src: apply multiple permissions improvements - #65158

Closed
jasnell wants to merge 11 commits into
nodejs:mainfrom
jasnell:jasnell/multiple-permission-improvements
Closed

src: apply multiple permissions improvements#65158
jasnell wants to merge 11 commits into
nodejs:mainfrom
jasnell:jasnell/multiple-permission-improvements

Conversation

@jasnell

Copy link
Copy Markdown
Member

Apply a range of improvements to src/permissions/*

  • Avoid recreating common strings
  • Use a DictionaryTemplate for permissions-related Diagnostics Channel messages
  • Simplify a C++ Diagnostics Channel API used in permissions
  • Make permissions storage more efficient (avoiding unsorted map)
  • Use a v8 fast api and radix tree improvement to make permissions checks ~2.5% faster
  • Simplify the permissions structure to eliminate duplication

Signed-off-by: James M Snell jasnell@gmail.com

Use env_property strings for permissions since those
are fixed. Avoid creating new string instances each
time.
Also use ToV8Value for a couple since we're in here.
Signed-off-by: James M Snell <jasnell@gmail.com>
Since DiagnosticChannel permission messages always have the
same shape and should be as low cost as possible, use a
cached DictionaryTemplate for creating them
Signed-off-by: James M Snell <jasnell@gmail.com>
Getting the name of the channel is unnecessary.
Signed-off-by: James M Snell <jasnell@gmail.com>
Signed-off-by: James M Snell <jasnell@gmail.com>
Signed-off-by: James M Snell <jasnell@gmail.com>
Use a fixed array rather than an unordered list
Signed-off-by: James M Snell <jasnell@gmail.com>
Improve the way the RadixTree works and apply a
fast api call.
Signed-off-by: James M Snell <jasnell@gmail.com>
Signed-off-by: James M Snell <jasnell@gmail.com>
Most of the PermissionBase subclasses used the identical
simple pattern. Rather than define a bunch of individual
identical permissions, use a single utility definition.
Special cases like FsPermission are still possible but
the simple case is kept... well, simple.
Signed-off-by: James M Snell <jasnell@gmail.com>
@jasnell
jasnell requested review from Qard and RafaelGSSAugust 9, 2026 02:28
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/gyp
  • @nodejs/security-wg

@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. lib / src Issues and PRs involving general changes in the lib/ or src/ directories. needs-ci PRs that need a full CI run. labels Aug 9, 2026
@jasnelljasnell changed the title src: cache permission stringssrc: apply multiple permissions improvementsAug 9, 2026
@nodejs-github-bot

This comment was marked as outdated.

@codecov

codecovBot commented Aug 9, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 78.12500% with 42 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.30%. Comparing base (c32ea43) to head (d110091).
⚠️ Report is 84 commits behind head on main.

Files with missing linesPatch %Lines
src/permission/permission.cc67.34%19 Missing and 13 partials ⚠️
src/permission/fs_permission.h88.88%2 Missing and 2 partials ⚠️
src/permission/fs_permission.cc70.00%3 Missing ⚠️
src/node_diagnostics_channel.cc71.42%2 Missing ⚠️
src/env.cc91.66%0 Missing and 1 partial ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #65158 +/- ##
==========================================
- Coverage 90.32% 90.30% -0.02% 
==========================================
Files 759 750 -9 Lines 248326 248314 -12 Branches 46859 46862 +3 ==========================================
- Hits 224293 224245 -48 + Misses 15481 15478 -3 - Partials 8552 8591 +39 
Files with missing linesCoverage Δ
src/env-inl.h95.01% <100.00%> (+0.02%)⬆️
src/env.h98.21% <ø> (ø)
src/node_diagnostics_channel.h57.14% <ø> (ø)
src/permission/boolean_permission.h100.00% <100.00%> (ø)
src/permission/permission.h100.00% <ø> (ø)
src/permission/permission_base.h100.00% <100.00%> (ø)
src/util.cc87.38% <100.00%> (+0.43%)⬆️
src/util.h90.98% <ø> (ø)
src/env.cc85.08% <91.66%> (-0.42%)⬇️
src/node_diagnostics_channel.cc83.60% <71.42%> (+0.09%)⬆️
... and 3 more

... and 51 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Signed-off-by: James M Snell <jasnell@gmail.com>
@jasnell
jasnellforce-pushed the jasnell/multiple-permission-improvements branch from a6b8717 to 7dd8d04CompareAugust 9, 2026 05:12
@nodejs-github-bot

This comment was marked as outdated.

@nodejs-github-bot

This comment was marked as outdated.

@nodejs-github-bot

This comment was marked as outdated.

Qard
Qard approved these changes Aug 9, 2026
@jasnell
jasnellforce-pushed the jasnell/multiple-permission-improvements branch from 8e7292b to 4c995fcCompareAugust 9, 2026 16:54
Signed-off-by: James M Snell <jasnell@gmail.com>
@jasnell
jasnellforce-pushed the jasnell/multiple-permission-improvements branch from 4c995fc to d110091CompareAugust 9, 2026 17:02
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@jasnelljasnell added the author ready PRs with CI started, the required approvals, and no outstanding review comments. label Aug 10, 2026
jasnell added a commit that referenced this pull request Aug 12, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
@jasnell

Copy link
Copy Markdown
MemberAuthor

Landed in 075d748...d996610

@jasnelljasnell closed this Aug 12, 2026
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Use env_property strings for permissions since those
are fixed. Avoid creating new string instances each
time.
Also use ToV8Value for a couple since we're in here.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Since DiagnosticChannel permission messages always have the
same shape and should be as low cost as possible, use a
cached DictionaryTemplate for creating them
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Getting the name of the channel is unnecessary.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Use a fixed array rather than an unordered list
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Improve the way the RadixTree works and apply a
fast api call.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Most of the PermissionBase subclasses used the identical
simple pattern. Rather than define a bunch of individual
identical permissions, use a single utility definition.
Special cases like FsPermission are still possible but
the simple case is kept... well, simple.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Use env_property strings for permissions since those
are fixed. Avoid creating new string instances each
time.
Also use ToV8Value for a couple since we're in here.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Since DiagnosticChannel permission messages always have the
same shape and should be as low cost as possible, use a
cached DictionaryTemplate for creating them
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Getting the name of the channel is unnecessary.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Use a fixed array rather than an unordered list
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Improve the way the RadixTree works and apply a
fast api call.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Most of the PermissionBase subclasses used the identical
simple pattern. Rather than define a bunch of individual
identical permissions, use a single utility definition.
Special cases like FsPermission are still possible but
the simple case is kept... well, simple.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Use env_property strings for permissions since those
are fixed. Avoid creating new string instances each
time.
Also use ToV8Value for a couple since we're in here.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Since DiagnosticChannel permission messages always have the
same shape and should be as low cost as possible, use a
cached DictionaryTemplate for creating them
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Getting the name of the channel is unnecessary.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author readyPRs with CI started, the required approvals, and no outstanding review comments.c++Issues and PRs that require attention from people who are familiar with C++.lib / srcIssues and PRs involving general changes in the lib/ or src/ directories.needs-ciPRs that need a full CI run.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@jasnell@nodejs-github-bot@Qard@meixg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

src: apply multiple permissions improvements - #65158

Closed
jasnell wants to merge 11 commits into
nodejs:mainfrom
jasnell:jasnell/multiple-permission-improvements
Closed

src: apply multiple permissions improvements#65158
jasnell wants to merge 11 commits into
nodejs:mainfrom
jasnell:jasnell/multiple-permission-improvements

Conversation

@jasnell

Copy link
Copy Markdown
Member

Apply a range of improvements to src/permissions/*

  • Avoid recreating common strings
  • Use a DictionaryTemplate for permissions-related Diagnostics Channel messages
  • Simplify a C++ Diagnostics Channel API used in permissions
  • Make permissions storage more efficient (avoiding unsorted map)
  • Use a v8 fast api and radix tree improvement to make permissions checks ~2.5% faster
  • Simplify the permissions structure to eliminate duplication

Signed-off-by: James M Snell jasnell@gmail.com

Use env_property strings for permissions since those
are fixed. Avoid creating new string instances each
time.
Also use ToV8Value for a couple since we're in here.
Signed-off-by: James M Snell <jasnell@gmail.com>
Since DiagnosticChannel permission messages always have the
same shape and should be as low cost as possible, use a
cached DictionaryTemplate for creating them
Signed-off-by: James M Snell <jasnell@gmail.com>
Getting the name of the channel is unnecessary.
Signed-off-by: James M Snell <jasnell@gmail.com>
Signed-off-by: James M Snell <jasnell@gmail.com>
Signed-off-by: James M Snell <jasnell@gmail.com>
Use a fixed array rather than an unordered list
Signed-off-by: James M Snell <jasnell@gmail.com>
Improve the way the RadixTree works and apply a
fast api call.
Signed-off-by: James M Snell <jasnell@gmail.com>
Signed-off-by: James M Snell <jasnell@gmail.com>
Most of the PermissionBase subclasses used the identical
simple pattern. Rather than define a bunch of individual
identical permissions, use a single utility definition.
Special cases like FsPermission are still possible but
the simple case is kept... well, simple.
Signed-off-by: James M Snell <jasnell@gmail.com>
@jasnell
jasnell requested review from Qard and RafaelGSSAugust 9, 2026 02:28
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/gyp
  • @nodejs/security-wg

@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. lib / src Issues and PRs involving general changes in the lib/ or src/ directories. needs-ci PRs that need a full CI run. labels Aug 9, 2026
@jasnelljasnell changed the title src: cache permission stringssrc: apply multiple permissions improvementsAug 9, 2026
@nodejs-github-bot

This comment was marked as outdated.

@codecov

codecovBot commented Aug 9, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 78.12500% with 42 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.30%. Comparing base (c32ea43) to head (d110091).
⚠️ Report is 84 commits behind head on main.

Files with missing linesPatch %Lines
src/permission/permission.cc67.34%19 Missing and 13 partials ⚠️
src/permission/fs_permission.h88.88%2 Missing and 2 partials ⚠️
src/permission/fs_permission.cc70.00%3 Missing ⚠️
src/node_diagnostics_channel.cc71.42%2 Missing ⚠️
src/env.cc91.66%0 Missing and 1 partial ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #65158 +/- ##
==========================================
- Coverage 90.32% 90.30% -0.02% 
==========================================
Files 759 750 -9 Lines 248326 248314 -12 Branches 46859 46862 +3 ==========================================
- Hits 224293 224245 -48 + Misses 15481 15478 -3 - Partials 8552 8591 +39 
Files with missing linesCoverage Δ
src/env-inl.h95.01% <100.00%> (+0.02%)⬆️
src/env.h98.21% <ø> (ø)
src/node_diagnostics_channel.h57.14% <ø> (ø)
src/permission/boolean_permission.h100.00% <100.00%> (ø)
src/permission/permission.h100.00% <ø> (ø)
src/permission/permission_base.h100.00% <100.00%> (ø)
src/util.cc87.38% <100.00%> (+0.43%)⬆️
src/util.h90.98% <ø> (ø)
src/env.cc85.08% <91.66%> (-0.42%)⬇️
src/node_diagnostics_channel.cc83.60% <71.42%> (+0.09%)⬆️
... and 3 more

... and 51 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Signed-off-by: James M Snell <jasnell@gmail.com>
@jasnell
jasnellforce-pushed the jasnell/multiple-permission-improvements branch from a6b8717 to 7dd8d04CompareAugust 9, 2026 05:12
@nodejs-github-bot

This comment was marked as outdated.

@nodejs-github-bot

This comment was marked as outdated.

@nodejs-github-bot

This comment was marked as outdated.

Qard
Qard approved these changes Aug 9, 2026
@jasnell
jasnellforce-pushed the jasnell/multiple-permission-improvements branch from 8e7292b to 4c995fcCompareAugust 9, 2026 16:54
Signed-off-by: James M Snell <jasnell@gmail.com>
@jasnell
jasnellforce-pushed the jasnell/multiple-permission-improvements branch from 4c995fc to d110091CompareAugust 9, 2026 17:02
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@jasnelljasnell added the author ready PRs with CI started, the required approvals, and no outstanding review comments. label Aug 10, 2026
jasnell added a commit that referenced this pull request Aug 12, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
@jasnell

Copy link
Copy Markdown
MemberAuthor

Landed in 075d748...d996610

@jasnelljasnell closed this Aug 12, 2026
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Use env_property strings for permissions since those
are fixed. Avoid creating new string instances each
time.
Also use ToV8Value for a couple since we're in here.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Since DiagnosticChannel permission messages always have the
same shape and should be as low cost as possible, use a
cached DictionaryTemplate for creating them
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Getting the name of the channel is unnecessary.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Use a fixed array rather than an unordered list
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Improve the way the RadixTree works and apply a
fast api call.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Most of the PermissionBase subclasses used the identical
simple pattern. Rather than define a bunch of individual
identical permissions, use a single utility definition.
Special cases like FsPermission are still possible but
the simple case is kept... well, simple.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Use env_property strings for permissions since those
are fixed. Avoid creating new string instances each
time.
Also use ToV8Value for a couple since we're in here.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Since DiagnosticChannel permission messages always have the
same shape and should be as low cost as possible, use a
cached DictionaryTemplate for creating them
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Getting the name of the channel is unnecessary.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Use a fixed array rather than an unordered list
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Improve the way the RadixTree works and apply a
fast api call.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Most of the PermissionBase subclasses used the identical
simple pattern. Rather than define a bunch of individual
identical permissions, use a single utility definition.
Special cases like FsPermission are still possible but
the simple case is kept... well, simple.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Use env_property strings for permissions since those
are fixed. Avoid creating new string instances each
time.
Also use ToV8Value for a couple since we're in here.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Since DiagnosticChannel permission messages always have the
same shape and should be as low cost as possible, use a
cached DictionaryTemplate for creating them
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Getting the name of the channel is unnecessary.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author readyPRs with CI started, the required approvals, and no outstanding review comments.c++Issues and PRs that require attention from people who are familiar with C++.lib / srcIssues and PRs involving general changes in the lib/ or src/ directories.needs-ciPRs that need a full CI run.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@jasnell@nodejs-github-bot@Qard@meixg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

src: apply multiple permissions improvements - #65158

Closed
jasnell wants to merge 11 commits into
nodejs:mainfrom
jasnell:jasnell/multiple-permission-improvements
Closed

src: apply multiple permissions improvements#65158
jasnell wants to merge 11 commits into
nodejs:mainfrom
jasnell:jasnell/multiple-permission-improvements

Conversation

@jasnell

Copy link
Copy Markdown
Member

Apply a range of improvements to src/permissions/*

  • Avoid recreating common strings
  • Use a DictionaryTemplate for permissions-related Diagnostics Channel messages
  • Simplify a C++ Diagnostics Channel API used in permissions
  • Make permissions storage more efficient (avoiding unsorted map)
  • Use a v8 fast api and radix tree improvement to make permissions checks ~2.5% faster
  • Simplify the permissions structure to eliminate duplication

Signed-off-by: James M Snell jasnell@gmail.com

Use env_property strings for permissions since those
are fixed. Avoid creating new string instances each
time.
Also use ToV8Value for a couple since we're in here.
Signed-off-by: James M Snell <jasnell@gmail.com>
Since DiagnosticChannel permission messages always have the
same shape and should be as low cost as possible, use a
cached DictionaryTemplate for creating them
Signed-off-by: James M Snell <jasnell@gmail.com>
Getting the name of the channel is unnecessary.
Signed-off-by: James M Snell <jasnell@gmail.com>
Signed-off-by: James M Snell <jasnell@gmail.com>
Signed-off-by: James M Snell <jasnell@gmail.com>
Use a fixed array rather than an unordered list
Signed-off-by: James M Snell <jasnell@gmail.com>
Improve the way the RadixTree works and apply a
fast api call.
Signed-off-by: James M Snell <jasnell@gmail.com>
Signed-off-by: James M Snell <jasnell@gmail.com>
Most of the PermissionBase subclasses used the identical
simple pattern. Rather than define a bunch of individual
identical permissions, use a single utility definition.
Special cases like FsPermission are still possible but
the simple case is kept... well, simple.
Signed-off-by: James M Snell <jasnell@gmail.com>
@jasnell
jasnell requested review from Qard and RafaelGSSAugust 9, 2026 02:28
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/gyp
  • @nodejs/security-wg

@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. lib / src Issues and PRs involving general changes in the lib/ or src/ directories. needs-ci PRs that need a full CI run. labels Aug 9, 2026
@jasnelljasnell changed the title src: cache permission stringssrc: apply multiple permissions improvementsAug 9, 2026
@nodejs-github-bot

This comment was marked as outdated.

@codecov

codecovBot commented Aug 9, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 78.12500% with 42 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.30%. Comparing base (c32ea43) to head (d110091).
⚠️ Report is 84 commits behind head on main.

Files with missing linesPatch %Lines
src/permission/permission.cc67.34%19 Missing and 13 partials ⚠️
src/permission/fs_permission.h88.88%2 Missing and 2 partials ⚠️
src/permission/fs_permission.cc70.00%3 Missing ⚠️
src/node_diagnostics_channel.cc71.42%2 Missing ⚠️
src/env.cc91.66%0 Missing and 1 partial ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #65158 +/- ##
==========================================
- Coverage 90.32% 90.30% -0.02% 
==========================================
Files 759 750 -9 Lines 248326 248314 -12 Branches 46859 46862 +3 ==========================================
- Hits 224293 224245 -48 + Misses 15481 15478 -3 - Partials 8552 8591 +39 
Files with missing linesCoverage Δ
src/env-inl.h95.01% <100.00%> (+0.02%)⬆️
src/env.h98.21% <ø> (ø)
src/node_diagnostics_channel.h57.14% <ø> (ø)
src/permission/boolean_permission.h100.00% <100.00%> (ø)
src/permission/permission.h100.00% <ø> (ø)
src/permission/permission_base.h100.00% <100.00%> (ø)
src/util.cc87.38% <100.00%> (+0.43%)⬆️
src/util.h90.98% <ø> (ø)
src/env.cc85.08% <91.66%> (-0.42%)⬇️
src/node_diagnostics_channel.cc83.60% <71.42%> (+0.09%)⬆️
... and 3 more

... and 51 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Signed-off-by: James M Snell <jasnell@gmail.com>
@jasnell
jasnellforce-pushed the jasnell/multiple-permission-improvements branch from a6b8717 to 7dd8d04CompareAugust 9, 2026 05:12
@nodejs-github-bot

This comment was marked as outdated.

@nodejs-github-bot

This comment was marked as outdated.

@nodejs-github-bot

This comment was marked as outdated.

Qard
Qard approved these changes Aug 9, 2026
@jasnell
jasnellforce-pushed the jasnell/multiple-permission-improvements branch from 8e7292b to 4c995fcCompareAugust 9, 2026 16:54
Signed-off-by: James M Snell <jasnell@gmail.com>
@jasnell
jasnellforce-pushed the jasnell/multiple-permission-improvements branch from 4c995fc to d110091CompareAugust 9, 2026 17:02
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@jasnelljasnell added the author ready PRs with CI started, the required approvals, and no outstanding review comments. label Aug 10, 2026
jasnell added a commit that referenced this pull request Aug 12, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
@jasnell

Copy link
Copy Markdown
MemberAuthor

Landed in 075d748...d996610

@jasnelljasnell closed this Aug 12, 2026
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Use env_property strings for permissions since those
are fixed. Avoid creating new string instances each
time.
Also use ToV8Value for a couple since we're in here.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Since DiagnosticChannel permission messages always have the
same shape and should be as low cost as possible, use a
cached DictionaryTemplate for creating them
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Getting the name of the channel is unnecessary.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Use a fixed array rather than an unordered list
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Improve the way the RadixTree works and apply a
fast api call.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Most of the PermissionBase subclasses used the identical
simple pattern. Rather than define a bunch of individual
identical permissions, use a single utility definition.
Special cases like FsPermission are still possible but
the simple case is kept... well, simple.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Use env_property strings for permissions since those
are fixed. Avoid creating new string instances each
time.
Also use ToV8Value for a couple since we're in here.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Since DiagnosticChannel permission messages always have the
same shape and should be as low cost as possible, use a
cached DictionaryTemplate for creating them
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Getting the name of the channel is unnecessary.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Use a fixed array rather than an unordered list
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Improve the way the RadixTree works and apply a
fast api call.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Most of the PermissionBase subclasses used the identical
simple pattern. Rather than define a bunch of individual
identical permissions, use a single utility definition.
Special cases like FsPermission are still possible but
the simple case is kept... well, simple.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Use env_property strings for permissions since those
are fixed. Avoid creating new string instances each
time.
Also use ToV8Value for a couple since we're in here.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Since DiagnosticChannel permission messages always have the
same shape and should be as low cost as possible, use a
cached DictionaryTemplate for creating them
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Getting the name of the channel is unnecessary.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author readyPRs with CI started, the required approvals, and no outstanding review comments.c++Issues and PRs that require attention from people who are familiar with C++.lib / srcIssues and PRs involving general changes in the lib/ or src/ directories.needs-ciPRs that need a full CI run.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@jasnell@nodejs-github-bot@Qard@meixg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

src: apply multiple permissions improvements - #65158

Closed
jasnell wants to merge 11 commits into
nodejs:mainfrom
jasnell:jasnell/multiple-permission-improvements
Closed

src: apply multiple permissions improvements#65158
jasnell wants to merge 11 commits into
nodejs:mainfrom
jasnell:jasnell/multiple-permission-improvements

Conversation

@jasnell

Copy link
Copy Markdown
Member

Apply a range of improvements to src/permissions/*

  • Avoid recreating common strings
  • Use a DictionaryTemplate for permissions-related Diagnostics Channel messages
  • Simplify a C++ Diagnostics Channel API used in permissions
  • Make permissions storage more efficient (avoiding unsorted map)
  • Use a v8 fast api and radix tree improvement to make permissions checks ~2.5% faster
  • Simplify the permissions structure to eliminate duplication

Signed-off-by: James M Snell jasnell@gmail.com

Use env_property strings for permissions since those
are fixed. Avoid creating new string instances each
time.
Also use ToV8Value for a couple since we're in here.
Signed-off-by: James M Snell <jasnell@gmail.com>
Since DiagnosticChannel permission messages always have the
same shape and should be as low cost as possible, use a
cached DictionaryTemplate for creating them
Signed-off-by: James M Snell <jasnell@gmail.com>
Getting the name of the channel is unnecessary.
Signed-off-by: James M Snell <jasnell@gmail.com>
Signed-off-by: James M Snell <jasnell@gmail.com>
Signed-off-by: James M Snell <jasnell@gmail.com>
Use a fixed array rather than an unordered list
Signed-off-by: James M Snell <jasnell@gmail.com>
Improve the way the RadixTree works and apply a
fast api call.
Signed-off-by: James M Snell <jasnell@gmail.com>
Signed-off-by: James M Snell <jasnell@gmail.com>
Most of the PermissionBase subclasses used the identical
simple pattern. Rather than define a bunch of individual
identical permissions, use a single utility definition.
Special cases like FsPermission are still possible but
the simple case is kept... well, simple.
Signed-off-by: James M Snell <jasnell@gmail.com>
@jasnell
jasnell requested review from Qard and RafaelGSSAugust 9, 2026 02:28
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/gyp
  • @nodejs/security-wg

@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. lib / src Issues and PRs involving general changes in the lib/ or src/ directories. needs-ci PRs that need a full CI run. labels Aug 9, 2026
@jasnelljasnell changed the title src: cache permission stringssrc: apply multiple permissions improvementsAug 9, 2026
@nodejs-github-bot

This comment was marked as outdated.

@codecov

codecovBot commented Aug 9, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 78.12500% with 42 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.30%. Comparing base (c32ea43) to head (d110091).
⚠️ Report is 84 commits behind head on main.

Files with missing linesPatch %Lines
src/permission/permission.cc67.34%19 Missing and 13 partials ⚠️
src/permission/fs_permission.h88.88%2 Missing and 2 partials ⚠️
src/permission/fs_permission.cc70.00%3 Missing ⚠️
src/node_diagnostics_channel.cc71.42%2 Missing ⚠️
src/env.cc91.66%0 Missing and 1 partial ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #65158 +/- ##
==========================================
- Coverage 90.32% 90.30% -0.02% 
==========================================
Files 759 750 -9 Lines 248326 248314 -12 Branches 46859 46862 +3 ==========================================
- Hits 224293 224245 -48 + Misses 15481 15478 -3 - Partials 8552 8591 +39 
Files with missing linesCoverage Δ
src/env-inl.h95.01% <100.00%> (+0.02%)⬆️
src/env.h98.21% <ø> (ø)
src/node_diagnostics_channel.h57.14% <ø> (ø)
src/permission/boolean_permission.h100.00% <100.00%> (ø)
src/permission/permission.h100.00% <ø> (ø)
src/permission/permission_base.h100.00% <100.00%> (ø)
src/util.cc87.38% <100.00%> (+0.43%)⬆️
src/util.h90.98% <ø> (ø)
src/env.cc85.08% <91.66%> (-0.42%)⬇️
src/node_diagnostics_channel.cc83.60% <71.42%> (+0.09%)⬆️
... and 3 more

... and 51 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Signed-off-by: James M Snell <jasnell@gmail.com>
@jasnell
jasnellforce-pushed the jasnell/multiple-permission-improvements branch from a6b8717 to 7dd8d04CompareAugust 9, 2026 05:12
@nodejs-github-bot

This comment was marked as outdated.

@nodejs-github-bot

This comment was marked as outdated.

@nodejs-github-bot

This comment was marked as outdated.

Qard
Qard approved these changes Aug 9, 2026
@jasnell
jasnellforce-pushed the jasnell/multiple-permission-improvements branch from 8e7292b to 4c995fcCompareAugust 9, 2026 16:54
Signed-off-by: James M Snell <jasnell@gmail.com>
@jasnell
jasnellforce-pushed the jasnell/multiple-permission-improvements branch from 4c995fc to d110091CompareAugust 9, 2026 17:02
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@jasnelljasnell added the author ready PRs with CI started, the required approvals, and no outstanding review comments. label Aug 10, 2026
jasnell added a commit that referenced this pull request Aug 12, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
@jasnell

Copy link
Copy Markdown
MemberAuthor

Landed in 075d748...d996610

@jasnelljasnell closed this Aug 12, 2026
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Use env_property strings for permissions since those
are fixed. Avoid creating new string instances each
time.
Also use ToV8Value for a couple since we're in here.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Since DiagnosticChannel permission messages always have the
same shape and should be as low cost as possible, use a
cached DictionaryTemplate for creating them
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Getting the name of the channel is unnecessary.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Use a fixed array rather than an unordered list
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Improve the way the RadixTree works and apply a
fast api call.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Most of the PermissionBase subclasses used the identical
simple pattern. Rather than define a bunch of individual
identical permissions, use a single utility definition.
Special cases like FsPermission are still possible but
the simple case is kept... well, simple.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Use env_property strings for permissions since those
are fixed. Avoid creating new string instances each
time.
Also use ToV8Value for a couple since we're in here.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Since DiagnosticChannel permission messages always have the
same shape and should be as low cost as possible, use a
cached DictionaryTemplate for creating them
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Getting the name of the channel is unnecessary.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Use a fixed array rather than an unordered list
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Improve the way the RadixTree works and apply a
fast api call.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Most of the PermissionBase subclasses used the identical
simple pattern. Rather than define a bunch of individual
identical permissions, use a single utility definition.
Special cases like FsPermission are still possible but
the simple case is kept... well, simple.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Use env_property strings for permissions since those
are fixed. Avoid creating new string instances each
time.
Also use ToV8Value for a couple since we're in here.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Since DiagnosticChannel permission messages always have the
same shape and should be as low cost as possible, use a
cached DictionaryTemplate for creating them
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Getting the name of the channel is unnecessary.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author readyPRs with CI started, the required approvals, and no outstanding review comments.c++Issues and PRs that require attention from people who are familiar with C++.lib / srcIssues and PRs involving general changes in the lib/ or src/ directories.needs-ciPRs that need a full CI run.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@jasnell@nodejs-github-bot@Qard@meixg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

src: apply multiple permissions improvements - #65158

Closed
jasnell wants to merge 11 commits into
nodejs:mainfrom
jasnell:jasnell/multiple-permission-improvements
Closed

src: apply multiple permissions improvements#65158
jasnell wants to merge 11 commits into
nodejs:mainfrom
jasnell:jasnell/multiple-permission-improvements

Conversation

@jasnell

Copy link
Copy Markdown
Member

Apply a range of improvements to src/permissions/*

  • Avoid recreating common strings
  • Use a DictionaryTemplate for permissions-related Diagnostics Channel messages
  • Simplify a C++ Diagnostics Channel API used in permissions
  • Make permissions storage more efficient (avoiding unsorted map)
  • Use a v8 fast api and radix tree improvement to make permissions checks ~2.5% faster
  • Simplify the permissions structure to eliminate duplication

Signed-off-by: James M Snell jasnell@gmail.com

Use env_property strings for permissions since those
are fixed. Avoid creating new string instances each
time.
Also use ToV8Value for a couple since we're in here.
Signed-off-by: James M Snell <jasnell@gmail.com>
Since DiagnosticChannel permission messages always have the
same shape and should be as low cost as possible, use a
cached DictionaryTemplate for creating them
Signed-off-by: James M Snell <jasnell@gmail.com>
Getting the name of the channel is unnecessary.
Signed-off-by: James M Snell <jasnell@gmail.com>
Signed-off-by: James M Snell <jasnell@gmail.com>
Signed-off-by: James M Snell <jasnell@gmail.com>
Use a fixed array rather than an unordered list
Signed-off-by: James M Snell <jasnell@gmail.com>
Improve the way the RadixTree works and apply a
fast api call.
Signed-off-by: James M Snell <jasnell@gmail.com>
Signed-off-by: James M Snell <jasnell@gmail.com>
Most of the PermissionBase subclasses used the identical
simple pattern. Rather than define a bunch of individual
identical permissions, use a single utility definition.
Special cases like FsPermission are still possible but
the simple case is kept... well, simple.
Signed-off-by: James M Snell <jasnell@gmail.com>
@jasnell
jasnell requested review from Qard and RafaelGSSAugust 9, 2026 02:28
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/gyp
  • @nodejs/security-wg

@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. lib / src Issues and PRs involving general changes in the lib/ or src/ directories. needs-ci PRs that need a full CI run. labels Aug 9, 2026
@jasnelljasnell changed the title src: cache permission stringssrc: apply multiple permissions improvementsAug 9, 2026
@nodejs-github-bot

This comment was marked as outdated.

@codecov

codecovBot commented Aug 9, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 78.12500% with 42 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.30%. Comparing base (c32ea43) to head (d110091).
⚠️ Report is 84 commits behind head on main.

Files with missing linesPatch %Lines
src/permission/permission.cc67.34%19 Missing and 13 partials ⚠️
src/permission/fs_permission.h88.88%2 Missing and 2 partials ⚠️
src/permission/fs_permission.cc70.00%3 Missing ⚠️
src/node_diagnostics_channel.cc71.42%2 Missing ⚠️
src/env.cc91.66%0 Missing and 1 partial ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #65158 +/- ##
==========================================
- Coverage 90.32% 90.30% -0.02% 
==========================================
Files 759 750 -9 Lines 248326 248314 -12 Branches 46859 46862 +3 ==========================================
- Hits 224293 224245 -48 + Misses 15481 15478 -3 - Partials 8552 8591 +39 
Files with missing linesCoverage Δ
src/env-inl.h95.01% <100.00%> (+0.02%)⬆️
src/env.h98.21% <ø> (ø)
src/node_diagnostics_channel.h57.14% <ø> (ø)
src/permission/boolean_permission.h100.00% <100.00%> (ø)
src/permission/permission.h100.00% <ø> (ø)
src/permission/permission_base.h100.00% <100.00%> (ø)
src/util.cc87.38% <100.00%> (+0.43%)⬆️
src/util.h90.98% <ø> (ø)
src/env.cc85.08% <91.66%> (-0.42%)⬇️
src/node_diagnostics_channel.cc83.60% <71.42%> (+0.09%)⬆️
... and 3 more

... and 51 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Signed-off-by: James M Snell <jasnell@gmail.com>
@jasnell
jasnellforce-pushed the jasnell/multiple-permission-improvements branch from a6b8717 to 7dd8d04CompareAugust 9, 2026 05:12
@nodejs-github-bot

This comment was marked as outdated.

@nodejs-github-bot

This comment was marked as outdated.

@nodejs-github-bot

This comment was marked as outdated.

Qard
Qard approved these changes Aug 9, 2026
@jasnell
jasnellforce-pushed the jasnell/multiple-permission-improvements branch from 8e7292b to 4c995fcCompareAugust 9, 2026 16:54
Signed-off-by: James M Snell <jasnell@gmail.com>
@jasnell
jasnellforce-pushed the jasnell/multiple-permission-improvements branch from 4c995fc to d110091CompareAugust 9, 2026 17:02
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@jasnelljasnell added the author ready PRs with CI started, the required approvals, and no outstanding review comments. label Aug 10, 2026
jasnell added a commit that referenced this pull request Aug 12, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
@jasnell

Copy link
Copy Markdown
MemberAuthor

Landed in 075d748...d996610

@jasnelljasnell closed this Aug 12, 2026
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Use env_property strings for permissions since those
are fixed. Avoid creating new string instances each
time.
Also use ToV8Value for a couple since we're in here.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Since DiagnosticChannel permission messages always have the
same shape and should be as low cost as possible, use a
cached DictionaryTemplate for creating them
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Getting the name of the channel is unnecessary.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Use a fixed array rather than an unordered list
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Improve the way the RadixTree works and apply a
fast api call.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Most of the PermissionBase subclasses used the identical
simple pattern. Rather than define a bunch of individual
identical permissions, use a single utility definition.
Special cases like FsPermission are still possible but
the simple case is kept... well, simple.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Use env_property strings for permissions since those
are fixed. Avoid creating new string instances each
time.
Also use ToV8Value for a couple since we're in here.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Since DiagnosticChannel permission messages always have the
same shape and should be as low cost as possible, use a
cached DictionaryTemplate for creating them
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Getting the name of the channel is unnecessary.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Use a fixed array rather than an unordered list
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Improve the way the RadixTree works and apply a
fast api call.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Most of the PermissionBase subclasses used the identical
simple pattern. Rather than define a bunch of individual
identical permissions, use a single utility definition.
Special cases like FsPermission are still possible but
the simple case is kept... well, simple.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Use env_property strings for permissions since those
are fixed. Avoid creating new string instances each
time.
Also use ToV8Value for a couple since we're in here.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Since DiagnosticChannel permission messages always have the
same shape and should be as low cost as possible, use a
cached DictionaryTemplate for creating them
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Getting the name of the channel is unnecessary.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author readyPRs with CI started, the required approvals, and no outstanding review comments.c++Issues and PRs that require attention from people who are familiar with C++.lib / srcIssues and PRs involving general changes in the lib/ or src/ directories.needs-ciPRs that need a full CI run.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@jasnell@nodejs-github-bot@Qard@meixg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

src: apply multiple permissions improvements - #65158

Closed
jasnell wants to merge 11 commits into
nodejs:mainfrom
jasnell:jasnell/multiple-permission-improvements
Closed

src: apply multiple permissions improvements#65158
jasnell wants to merge 11 commits into
nodejs:mainfrom
jasnell:jasnell/multiple-permission-improvements

Conversation

@jasnell

Copy link
Copy Markdown
Member

Apply a range of improvements to src/permissions/*

  • Avoid recreating common strings
  • Use a DictionaryTemplate for permissions-related Diagnostics Channel messages
  • Simplify a C++ Diagnostics Channel API used in permissions
  • Make permissions storage more efficient (avoiding unsorted map)
  • Use a v8 fast api and radix tree improvement to make permissions checks ~2.5% faster
  • Simplify the permissions structure to eliminate duplication

Signed-off-by: James M Snell jasnell@gmail.com

Use env_property strings for permissions since those
are fixed. Avoid creating new string instances each
time.
Also use ToV8Value for a couple since we're in here.
Signed-off-by: James M Snell <jasnell@gmail.com>
Since DiagnosticChannel permission messages always have the
same shape and should be as low cost as possible, use a
cached DictionaryTemplate for creating them
Signed-off-by: James M Snell <jasnell@gmail.com>
Getting the name of the channel is unnecessary.
Signed-off-by: James M Snell <jasnell@gmail.com>
Signed-off-by: James M Snell <jasnell@gmail.com>
Signed-off-by: James M Snell <jasnell@gmail.com>
Use a fixed array rather than an unordered list
Signed-off-by: James M Snell <jasnell@gmail.com>
Improve the way the RadixTree works and apply a
fast api call.
Signed-off-by: James M Snell <jasnell@gmail.com>
Signed-off-by: James M Snell <jasnell@gmail.com>
Most of the PermissionBase subclasses used the identical
simple pattern. Rather than define a bunch of individual
identical permissions, use a single utility definition.
Special cases like FsPermission are still possible but
the simple case is kept... well, simple.
Signed-off-by: James M Snell <jasnell@gmail.com>
@jasnell
jasnell requested review from Qard and RafaelGSSAugust 9, 2026 02:28
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/gyp
  • @nodejs/security-wg

@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. lib / src Issues and PRs involving general changes in the lib/ or src/ directories. needs-ci PRs that need a full CI run. labels Aug 9, 2026
@jasnelljasnell changed the title src: cache permission stringssrc: apply multiple permissions improvementsAug 9, 2026
@nodejs-github-bot

This comment was marked as outdated.

@codecov

codecovBot commented Aug 9, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 78.12500% with 42 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.30%. Comparing base (c32ea43) to head (d110091).
⚠️ Report is 84 commits behind head on main.

Files with missing linesPatch %Lines
src/permission/permission.cc67.34%19 Missing and 13 partials ⚠️
src/permission/fs_permission.h88.88%2 Missing and 2 partials ⚠️
src/permission/fs_permission.cc70.00%3 Missing ⚠️
src/node_diagnostics_channel.cc71.42%2 Missing ⚠️
src/env.cc91.66%0 Missing and 1 partial ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #65158 +/- ##
==========================================
- Coverage 90.32% 90.30% -0.02% 
==========================================
Files 759 750 -9 Lines 248326 248314 -12 Branches 46859 46862 +3 ==========================================
- Hits 224293 224245 -48 + Misses 15481 15478 -3 - Partials 8552 8591 +39 
Files with missing linesCoverage Δ
src/env-inl.h95.01% <100.00%> (+0.02%)⬆️
src/env.h98.21% <ø> (ø)
src/node_diagnostics_channel.h57.14% <ø> (ø)
src/permission/boolean_permission.h100.00% <100.00%> (ø)
src/permission/permission.h100.00% <ø> (ø)
src/permission/permission_base.h100.00% <100.00%> (ø)
src/util.cc87.38% <100.00%> (+0.43%)⬆️
src/util.h90.98% <ø> (ø)
src/env.cc85.08% <91.66%> (-0.42%)⬇️
src/node_diagnostics_channel.cc83.60% <71.42%> (+0.09%)⬆️
... and 3 more

... and 51 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Signed-off-by: James M Snell <jasnell@gmail.com>
@jasnell
jasnellforce-pushed the jasnell/multiple-permission-improvements branch from a6b8717 to 7dd8d04CompareAugust 9, 2026 05:12
@nodejs-github-bot

This comment was marked as outdated.

@nodejs-github-bot

This comment was marked as outdated.

@nodejs-github-bot

This comment was marked as outdated.

Qard
Qard approved these changes Aug 9, 2026
@jasnell
jasnellforce-pushed the jasnell/multiple-permission-improvements branch from 8e7292b to 4c995fcCompareAugust 9, 2026 16:54
Signed-off-by: James M Snell <jasnell@gmail.com>
@jasnell
jasnellforce-pushed the jasnell/multiple-permission-improvements branch from 4c995fc to d110091CompareAugust 9, 2026 17:02
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@jasnelljasnell added the author ready PRs with CI started, the required approvals, and no outstanding review comments. label Aug 10, 2026
jasnell added a commit that referenced this pull request Aug 12, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
@jasnell

Copy link
Copy Markdown
MemberAuthor

Landed in 075d748...d996610

@jasnelljasnell closed this Aug 12, 2026
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Use env_property strings for permissions since those
are fixed. Avoid creating new string instances each
time.
Also use ToV8Value for a couple since we're in here.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Since DiagnosticChannel permission messages always have the
same shape and should be as low cost as possible, use a
cached DictionaryTemplate for creating them
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Getting the name of the channel is unnecessary.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Use a fixed array rather than an unordered list
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Improve the way the RadixTree works and apply a
fast api call.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Most of the PermissionBase subclasses used the identical
simple pattern. Rather than define a bunch of individual
identical permissions, use a single utility definition.
Special cases like FsPermission are still possible but
the simple case is kept... well, simple.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Use env_property strings for permissions since those
are fixed. Avoid creating new string instances each
time.
Also use ToV8Value for a couple since we're in here.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Since DiagnosticChannel permission messages always have the
same shape and should be as low cost as possible, use a
cached DictionaryTemplate for creating them
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Getting the name of the channel is unnecessary.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Use a fixed array rather than an unordered list
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Improve the way the RadixTree works and apply a
fast api call.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Most of the PermissionBase subclasses used the identical
simple pattern. Rather than define a bunch of individual
identical permissions, use a single utility definition.
Special cases like FsPermission are still possible but
the simple case is kept... well, simple.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Use env_property strings for permissions since those
are fixed. Avoid creating new string instances each
time.
Also use ToV8Value for a couple since we're in here.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Since DiagnosticChannel permission messages always have the
same shape and should be as low cost as possible, use a
cached DictionaryTemplate for creating them
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Getting the name of the channel is unnecessary.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author readyPRs with CI started, the required approvals, and no outstanding review comments.c++Issues and PRs that require attention from people who are familiar with C++.lib / srcIssues and PRs involving general changes in the lib/ or src/ directories.needs-ciPRs that need a full CI run.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@jasnell@nodejs-github-bot@Qard@meixg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

src: apply multiple permissions improvements - #65158

Closed
jasnell wants to merge 11 commits into
nodejs:mainfrom
jasnell:jasnell/multiple-permission-improvements
Closed

src: apply multiple permissions improvements#65158
jasnell wants to merge 11 commits into
nodejs:mainfrom
jasnell:jasnell/multiple-permission-improvements

Conversation

@jasnell

Copy link
Copy Markdown
Member

Apply a range of improvements to src/permissions/*

  • Avoid recreating common strings
  • Use a DictionaryTemplate for permissions-related Diagnostics Channel messages
  • Simplify a C++ Diagnostics Channel API used in permissions
  • Make permissions storage more efficient (avoiding unsorted map)
  • Use a v8 fast api and radix tree improvement to make permissions checks ~2.5% faster
  • Simplify the permissions structure to eliminate duplication

Signed-off-by: James M Snell jasnell@gmail.com

Use env_property strings for permissions since those
are fixed. Avoid creating new string instances each
time.
Also use ToV8Value for a couple since we're in here.
Signed-off-by: James M Snell <jasnell@gmail.com>
Since DiagnosticChannel permission messages always have the
same shape and should be as low cost as possible, use a
cached DictionaryTemplate for creating them
Signed-off-by: James M Snell <jasnell@gmail.com>
Getting the name of the channel is unnecessary.
Signed-off-by: James M Snell <jasnell@gmail.com>
Signed-off-by: James M Snell <jasnell@gmail.com>
Signed-off-by: James M Snell <jasnell@gmail.com>
Use a fixed array rather than an unordered list
Signed-off-by: James M Snell <jasnell@gmail.com>
Improve the way the RadixTree works and apply a
fast api call.
Signed-off-by: James M Snell <jasnell@gmail.com>
Signed-off-by: James M Snell <jasnell@gmail.com>
Most of the PermissionBase subclasses used the identical
simple pattern. Rather than define a bunch of individual
identical permissions, use a single utility definition.
Special cases like FsPermission are still possible but
the simple case is kept... well, simple.
Signed-off-by: James M Snell <jasnell@gmail.com>
@jasnell
jasnell requested review from Qard and RafaelGSSAugust 9, 2026 02:28
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/gyp
  • @nodejs/security-wg

@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. lib / src Issues and PRs involving general changes in the lib/ or src/ directories. needs-ci PRs that need a full CI run. labels Aug 9, 2026
@jasnelljasnell changed the title src: cache permission stringssrc: apply multiple permissions improvementsAug 9, 2026
@nodejs-github-bot

This comment was marked as outdated.

@codecov

codecovBot commented Aug 9, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 78.12500% with 42 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.30%. Comparing base (c32ea43) to head (d110091).
⚠️ Report is 84 commits behind head on main.

Files with missing linesPatch %Lines
src/permission/permission.cc67.34%19 Missing and 13 partials ⚠️
src/permission/fs_permission.h88.88%2 Missing and 2 partials ⚠️
src/permission/fs_permission.cc70.00%3 Missing ⚠️
src/node_diagnostics_channel.cc71.42%2 Missing ⚠️
src/env.cc91.66%0 Missing and 1 partial ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #65158 +/- ##
==========================================
- Coverage 90.32% 90.30% -0.02% 
==========================================
Files 759 750 -9 Lines 248326 248314 -12 Branches 46859 46862 +3 ==========================================
- Hits 224293 224245 -48 + Misses 15481 15478 -3 - Partials 8552 8591 +39 
Files with missing linesCoverage Δ
src/env-inl.h95.01% <100.00%> (+0.02%)⬆️
src/env.h98.21% <ø> (ø)
src/node_diagnostics_channel.h57.14% <ø> (ø)
src/permission/boolean_permission.h100.00% <100.00%> (ø)
src/permission/permission.h100.00% <ø> (ø)
src/permission/permission_base.h100.00% <100.00%> (ø)
src/util.cc87.38% <100.00%> (+0.43%)⬆️
src/util.h90.98% <ø> (ø)
src/env.cc85.08% <91.66%> (-0.42%)⬇️
src/node_diagnostics_channel.cc83.60% <71.42%> (+0.09%)⬆️
... and 3 more

... and 51 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Signed-off-by: James M Snell <jasnell@gmail.com>
@jasnell
jasnellforce-pushed the jasnell/multiple-permission-improvements branch from a6b8717 to 7dd8d04CompareAugust 9, 2026 05:12
@nodejs-github-bot

This comment was marked as outdated.

@nodejs-github-bot

This comment was marked as outdated.

@nodejs-github-bot

This comment was marked as outdated.

Qard
Qard approved these changes Aug 9, 2026
@jasnell
jasnellforce-pushed the jasnell/multiple-permission-improvements branch from 8e7292b to 4c995fcCompareAugust 9, 2026 16:54
Signed-off-by: James M Snell <jasnell@gmail.com>
@jasnell
jasnellforce-pushed the jasnell/multiple-permission-improvements branch from 4c995fc to d110091CompareAugust 9, 2026 17:02
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@jasnelljasnell added the author ready PRs with CI started, the required approvals, and no outstanding review comments. label Aug 10, 2026
jasnell added a commit that referenced this pull request Aug 12, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
@jasnell

Copy link
Copy Markdown
MemberAuthor

Landed in 075d748...d996610

@jasnelljasnell closed this Aug 12, 2026
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Use env_property strings for permissions since those
are fixed. Avoid creating new string instances each
time.
Also use ToV8Value for a couple since we're in here.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Since DiagnosticChannel permission messages always have the
same shape and should be as low cost as possible, use a
cached DictionaryTemplate for creating them
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Getting the name of the channel is unnecessary.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Use a fixed array rather than an unordered list
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Improve the way the RadixTree works and apply a
fast api call.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Most of the PermissionBase subclasses used the identical
simple pattern. Rather than define a bunch of individual
identical permissions, use a single utility definition.
Special cases like FsPermission are still possible but
the simple case is kept... well, simple.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Use env_property strings for permissions since those
are fixed. Avoid creating new string instances each
time.
Also use ToV8Value for a couple since we're in here.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Since DiagnosticChannel permission messages always have the
same shape and should be as low cost as possible, use a
cached DictionaryTemplate for creating them
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Getting the name of the channel is unnecessary.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Use a fixed array rather than an unordered list
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Improve the way the RadixTree works and apply a
fast api call.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Most of the PermissionBase subclasses used the identical
simple pattern. Rather than define a bunch of individual
identical permissions, use a single utility definition.
Special cases like FsPermission are still possible but
the simple case is kept... well, simple.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Use env_property strings for permissions since those
are fixed. Avoid creating new string instances each
time.
Also use ToV8Value for a couple since we're in here.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Since DiagnosticChannel permission messages always have the
same shape and should be as low cost as possible, use a
cached DictionaryTemplate for creating them
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Getting the name of the channel is unnecessary.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author readyPRs with CI started, the required approvals, and no outstanding review comments.c++Issues and PRs that require attention from people who are familiar with C++.lib / srcIssues and PRs involving general changes in the lib/ or src/ directories.needs-ciPRs that need a full CI run.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@jasnell@nodejs-github-bot@Qard@meixg
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

src: apply multiple permissions improvements - #65158

Closed
jasnell wants to merge 11 commits into
nodejs:mainfrom
jasnell:jasnell/multiple-permission-improvements
Closed

src: apply multiple permissions improvements#65158
jasnell wants to merge 11 commits into
nodejs:mainfrom
jasnell:jasnell/multiple-permission-improvements

Conversation

@jasnell

Copy link
Copy Markdown
Member

Apply a range of improvements to src/permissions/*

  • Avoid recreating common strings
  • Use a DictionaryTemplate for permissions-related Diagnostics Channel messages
  • Simplify a C++ Diagnostics Channel API used in permissions
  • Make permissions storage more efficient (avoiding unsorted map)
  • Use a v8 fast api and radix tree improvement to make permissions checks ~2.5% faster
  • Simplify the permissions structure to eliminate duplication

Signed-off-by: James M Snell jasnell@gmail.com

Use env_property strings for permissions since those
are fixed. Avoid creating new string instances each
time.
Also use ToV8Value for a couple since we're in here.
Signed-off-by: James M Snell <jasnell@gmail.com>
Since DiagnosticChannel permission messages always have the
same shape and should be as low cost as possible, use a
cached DictionaryTemplate for creating them
Signed-off-by: James M Snell <jasnell@gmail.com>
Getting the name of the channel is unnecessary.
Signed-off-by: James M Snell <jasnell@gmail.com>
Signed-off-by: James M Snell <jasnell@gmail.com>
Signed-off-by: James M Snell <jasnell@gmail.com>
Use a fixed array rather than an unordered list
Signed-off-by: James M Snell <jasnell@gmail.com>
Improve the way the RadixTree works and apply a
fast api call.
Signed-off-by: James M Snell <jasnell@gmail.com>
Signed-off-by: James M Snell <jasnell@gmail.com>
Most of the PermissionBase subclasses used the identical
simple pattern. Rather than define a bunch of individual
identical permissions, use a single utility definition.
Special cases like FsPermission are still possible but
the simple case is kept... well, simple.
Signed-off-by: James M Snell <jasnell@gmail.com>
@jasnell
jasnell requested review from Qard and RafaelGSSAugust 9, 2026 02:28
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/gyp
  • @nodejs/security-wg

@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. lib / src Issues and PRs involving general changes in the lib/ or src/ directories. needs-ci PRs that need a full CI run. labels Aug 9, 2026
@jasnelljasnell changed the title src: cache permission stringssrc: apply multiple permissions improvementsAug 9, 2026
@nodejs-github-bot

This comment was marked as outdated.

@codecov

codecovBot commented Aug 9, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 78.12500% with 42 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.30%. Comparing base (c32ea43) to head (d110091).
⚠️ Report is 84 commits behind head on main.

Files with missing linesPatch %Lines
src/permission/permission.cc67.34%19 Missing and 13 partials ⚠️
src/permission/fs_permission.h88.88%2 Missing and 2 partials ⚠️
src/permission/fs_permission.cc70.00%3 Missing ⚠️
src/node_diagnostics_channel.cc71.42%2 Missing ⚠️
src/env.cc91.66%0 Missing and 1 partial ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #65158 +/- ##
==========================================
- Coverage 90.32% 90.30% -0.02% 
==========================================
Files 759 750 -9 Lines 248326 248314 -12 Branches 46859 46862 +3 ==========================================
- Hits 224293 224245 -48 + Misses 15481 15478 -3 - Partials 8552 8591 +39 
Files with missing linesCoverage Δ
src/env-inl.h95.01% <100.00%> (+0.02%)⬆️
src/env.h98.21% <ø> (ø)
src/node_diagnostics_channel.h57.14% <ø> (ø)
src/permission/boolean_permission.h100.00% <100.00%> (ø)
src/permission/permission.h100.00% <ø> (ø)
src/permission/permission_base.h100.00% <100.00%> (ø)
src/util.cc87.38% <100.00%> (+0.43%)⬆️
src/util.h90.98% <ø> (ø)
src/env.cc85.08% <91.66%> (-0.42%)⬇️
src/node_diagnostics_channel.cc83.60% <71.42%> (+0.09%)⬆️
... and 3 more

... and 51 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Signed-off-by: James M Snell <jasnell@gmail.com>
@jasnell
jasnellforce-pushed the jasnell/multiple-permission-improvements branch from a6b8717 to 7dd8d04CompareAugust 9, 2026 05:12
@nodejs-github-bot

This comment was marked as outdated.

@nodejs-github-bot

This comment was marked as outdated.

@nodejs-github-bot

This comment was marked as outdated.

Qard
Qard approved these changes Aug 9, 2026
@jasnell
jasnellforce-pushed the jasnell/multiple-permission-improvements branch from 8e7292b to 4c995fcCompareAugust 9, 2026 16:54
Signed-off-by: James M Snell <jasnell@gmail.com>
@jasnell
jasnellforce-pushed the jasnell/multiple-permission-improvements branch from 4c995fc to d110091CompareAugust 9, 2026 17:02
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@jasnelljasnell added the author ready PRs with CI started, the required approvals, and no outstanding review comments. label Aug 10, 2026
jasnell added a commit that referenced this pull request Aug 12, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
@jasnell

Copy link
Copy Markdown
MemberAuthor

Landed in 075d748...d996610

@jasnelljasnell closed this Aug 12, 2026
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Use env_property strings for permissions since those
are fixed. Avoid creating new string instances each
time.
Also use ToV8Value for a couple since we're in here.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Since DiagnosticChannel permission messages always have the
same shape and should be as low cost as possible, use a
cached DictionaryTemplate for creating them
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Getting the name of the channel is unnecessary.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Use a fixed array rather than an unordered list
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Improve the way the RadixTree works and apply a
fast api call.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Most of the PermissionBase subclasses used the identical
simple pattern. Rather than define a bunch of individual
identical permissions, use a single utility definition.
Special cases like FsPermission are still possible but
the simple case is kept... well, simple.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 13, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Use env_property strings for permissions since those
are fixed. Avoid creating new string instances each
time.
Also use ToV8Value for a couple since we're in here.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Since DiagnosticChannel permission messages always have the
same shape and should be as low cost as possible, use a
cached DictionaryTemplate for creating them
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Getting the name of the channel is unnecessary.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Use a fixed array rather than an unordered list
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Improve the way the RadixTree works and apply a
fast api call.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Most of the PermissionBase subclasses used the identical
simple pattern. Rather than define a bunch of individual
identical permissions, use a single utility definition.
Special cases like FsPermission are still possible but
the simple case is kept... well, simple.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Use env_property strings for permissions since those
are fixed. Avoid creating new string instances each
time.
Also use ToV8Value for a couple since we're in here.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Since DiagnosticChannel permission messages always have the
same shape and should be as low cost as possible, use a
cached DictionaryTemplate for creating them
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Getting the name of the channel is unnecessary.
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
aduh95 pushed a commit that referenced this pull request Aug 27, 2026
Signed-off-by: James M Snell <jasnell@gmail.com>
PR-URL: #65158
Reviewed-By: Xuguang Mei <meixuguang@gmail.com>
Reviewed-By: Stephen Belanger <admin@stephenbelanger.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author readyPRs with CI started, the required approvals, and no outstanding review comments.c++Issues and PRs that require attention from people who are familiar with C++.lib / srcIssues and PRs involving general changes in the lib/ or src/ directories.needs-ciPRs that need a full CI run.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@jasnell@nodejs-github-bot@Qard@meixg