[v24.x] Backport permission updates to v24 - #65354

Closed
RafaelGSS wants to merge 8 commits into
nodejs:v24.x-stagingfrom
RafaelGSS:backport-permission-updates-to-v24
Closed

[v24.x] Backport permission updates to v24#65354
RafaelGSS wants to merge 8 commits into
nodejs:v24.x-stagingfrom
RafaelGSS:backport-permission-updates-to-v24

Conversation

@RafaelGSSRafaelGSS added the semver-minor PRs that contain new features and should be released in the next minor version. label Aug 17, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/config
  • @nodejs/security-wg

@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. lib / src Issues and PRs involving general changes in the lib/ or src/ directories. needs-ci PRs that need a full CI run. v24.x Issues that can be reproduced on v24.x or PRs targeting the v24.x-staging branch. labels Aug 17, 2026
@codecov

codecovBot commented Aug 17, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 77.73109% with 53 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.28%. Comparing base (9e39360) to head (499c38a).
⚠️ Report is 2 commits behind head on v24.x-staging.

Files with missing linesPatch %Lines
src/permission/fs_permission.cc71.62%17 Missing and 4 partials ⚠️
src/permission/permission.cc83.05%3 Missing and 17 partials ⚠️
lib/internal/process/permission.js58.33%5 Missing ⚠️
src/permission/inspector_permission.cc0.00%3 Missing ⚠️
src/permission/wasi_permission.cc0.00%3 Missing ⚠️
src/node_binding.cc0.00%0 Missing and 1 partial ⚠️
Additional details and impacted files
@@ Coverage Diff @@## v24.x-staging #65354 +/- ##
=================================================
- Coverage 90.31% 90.28% -0.03% 
=================================================
Files 711 711 Lines 228425 228644 +219 Branches 43160 43200 +40 =================================================
+ Hits 206293 206425 +132 - Misses 14090 14100 +10 - Partials 8042 8119 +77 
Files with missing linesCoverage Δ
lib/internal/process/pre_execution.js98.18% <100.00%> (+0.52%)⬆️
src/env.cc80.72% <100.00%> (-0.12%)⬇️
src/node_options.cc76.58% <100.00%> (+0.02%)⬆️
src/node_options.h97.42% <100.00%> (-0.51%)⬇️
src/permission/addon_permission.cc100.00% <100.00%> (ø)
src/permission/child_process_permission.cc100.00% <100.00%> (ø)
src/permission/fs_permission.h91.78% <ø> (ø)
src/permission/permission.h100.00% <100.00%> (+16.66%)⬆️
src/permission/worker_permission.cc100.00% <100.00%> (ø)
src/node_binding.cc82.42% <0.00%> (-0.33%)⬇️
... and 5 more

... and 43 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@RafaelGSS
RafaelGSSforce-pushed the backport-permission-updates-to-v24 branch from 3b93be2 to 01e422dCompareAugust 17, 2026 19:57
@aduh95aduh95 added author ready PRs with CI started, the required approvals, and no outstanding review comments. request-ci Add this label to start a Jenkins CI on a PR. labels Aug 17, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 17, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

RafaelGSSand others added 8 commits August 17, 2026 19:21
Add --permission-audit flag that enables the permission model in
warning-only mode. Instead of throwing ERR_ACCESS_DENIED, it emits
a message via diagnostics channel and allows the operation to
continue.
Publish permission check results to per-scope diagnostics channels
(e.g., node:permission-model:fs) so users can observe permission
decisions at runtime via diagnostics_channel.
Refs: nodejs#59935
Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com>
PR-URL: nodejs#62672
Refs: nodejs#62223
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Signed-off-by: Martin <martin@asymmetric.re>
PR-URL: nodejs#64007
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Edy Silva <edigleyssonsilva@gmail.com>
The THROW_IF_INSUFFICIENT_PERMISSIONS and
ASYNC_THROW_IF_INSUFFICIENT_PERMISSIONS macros called
ThrowAccessDenied/AsyncThrowAccessDenied unconditionally and only
guarded the `return` with `warning_only()`.
ERR_ACCESS_DENIED_IF_INSUFFICIENT_PERMISSIONS had no `warning_only()`
guard at all — it always set the access-denied error and returned.
As a result, running with `--permission-audit` still produced
ERR_ACCESS_DENIED on any denied operation (fs, net, child_process,
worker, addon, ffi, inspector, wasi), defeating the audit-only purpose
of the flag.
Guard the denied-error path behind `!warning_only()` in all three
macros. In audit mode, the diagnostics-channel message is published
(already done in Permission::is_scope_granted) and execution continues;
in enforce mode (`--permission`), behavior is unchanged — the error is
raised and the call returns.
The tests cover both the direct (top-level) call and an `eval()`-wrapped
call: the direct call exercises the normal script path, and the
`eval()`-wrapped call exercises the V8 script-context boundary (the
diagnostics subscriber is registered in the outer module context while
the denied operation runs inside an eval'd string).
Refs: nodejs@9ddd1a9
Signed-off-by: Adrian Estrada <edsadr@gmail.com>
PR-URL: nodejs#64426
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Expand the documentation for the --permission-audit flag, which was
fixed in 51c09ea to no longer throw ERR_ACCESS_DENIED on denied
operations. The previous docs only had a two-sentence description in
cli.md and no mention in the permissions guide or process.permission
API docs.
- permissions.md: add enforce vs audit mode overview, a new
"Audit Mode" subsection listing the diagnostics channel names
(node:permission-model:*) and the { permission, resource } message
shape, and a usage example. Update the Runtime API section to
mention both --permission and --permission-audit.
- cli.md: expand the --permission-audit section to clarify that
--permission is not required, --allow-* flags are not needed,
errors are not thrown, and --permission takes precedence when both
are set. Add a cross-reference from --permission to
--permission-audit.
- process.md: note that process.permission is available under both
flags, and clarify permission.has() and permission.drop() behavior
in audit mode.
- node.1: regenerated via `make node.1`.
Refs: nodejs#64426
Signed-off-by: Adrian Estrada <edsadr@gmail.com>
PR-URL: nodejs#64791
Reviewed-By: Aviv Keller <me@aviv.sh>
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com>
Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
Adds unique warning codes of the form PERM0000 for all permissions
related SecurityWarnings, so that they can be individually silenced
if required.
Fixes: nodejs#59818
Signed-off-by: David Evans <davidje13@users.noreply.github.com>
PR-URL: nodejs#64414
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Ulises Gascón <ulisesgascongonzalez@gmail.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
@RafaelGSS
RafaelGSSforce-pushed the backport-permission-updates-to-v24 branch from 01e422d to 499c38aCompareAugust 17, 2026 22:56
@aduh95aduh95 added the request-ci Add this label to start a Jenkins CI on a PR. label Aug 19, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 19, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@aduh95

Copy link
Copy Markdown
Contributor

Landed in 82a0233...980c651

aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Add --permission-audit flag that enables the permission model in
warning-only mode. Instead of throwing ERR_ACCESS_DENIED, it emits
a message via diagnostics channel and allows the operation to
continue.
Publish permission check results to per-scope diagnostics channels
(e.g., node:permission-model:fs) so users can observe permission
decisions at runtime via diagnostics_channel.
Refs: #59935
PR-URL: #61869
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com>
PR-URL: #62672
Backport-PR-URL: #65354
Refs: #62223
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Signed-off-by: Martin <martin@asymmetric.re>
PR-URL: #64007
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
The THROW_IF_INSUFFICIENT_PERMISSIONS and
ASYNC_THROW_IF_INSUFFICIENT_PERMISSIONS macros called
ThrowAccessDenied/AsyncThrowAccessDenied unconditionally and only
guarded the `return` with `warning_only()`.
ERR_ACCESS_DENIED_IF_INSUFFICIENT_PERMISSIONS had no `warning_only()`
guard at all — it always set the access-denied error and returned.
As a result, running with `--permission-audit` still produced
ERR_ACCESS_DENIED on any denied operation (fs, net, child_process,
worker, addon, ffi, inspector, wasi), defeating the audit-only purpose
of the flag.
Guard the denied-error path behind `!warning_only()` in all three
macros. In audit mode, the diagnostics-channel message is published
(already done in Permission::is_scope_granted) and execution continues;
in enforce mode (`--permission`), behavior is unchanged — the error is
raised and the call returns.
The tests cover both the direct (top-level) call and an `eval()`-wrapped
call: the direct call exercises the normal script path, and the
`eval()`-wrapped call exercises the V8 script-context boundary (the
diagnostics subscriber is registered in the outer module context while
the denied operation runs inside an eval'd string).
Refs: 9ddd1a9
Signed-off-by: Adrian Estrada <edsadr@gmail.com>
PR-URL: #64426
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Expand the documentation for the --permission-audit flag, which was
fixed in 51c09ea to no longer throw ERR_ACCESS_DENIED on denied
operations. The previous docs only had a two-sentence description in
cli.md and no mention in the permissions guide or process.permission
API docs.
- permissions.md: add enforce vs audit mode overview, a new
"Audit Mode" subsection listing the diagnostics channel names
(node:permission-model:*) and the { permission, resource } message
shape, and a usage example. Update the Runtime API section to
mention both --permission and --permission-audit.
- cli.md: expand the --permission-audit section to clarify that
--permission is not required, --allow-* flags are not needed,
errors are not thrown, and --permission takes precedence when both
are set. Add a cross-reference from --permission to
--permission-audit.
- process.md: note that process.permission is available under both
flags, and clarify permission.has() and permission.drop() behavior
in audit mode.
- node.1: regenerated via `make node.1`.
Refs: #64426
Signed-off-by: Adrian Estrada <edsadr@gmail.com>
PR-URL: #64791
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Adds unique warning codes of the form PERM0000 for all permissions
related SecurityWarnings, so that they can be individually silenced
if required.
Fixes: #59818
Signed-off-by: David Evans <davidje13@users.noreply.github.com>
PR-URL: #64414
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
@aduh95aduh95 closed this Aug 20, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author readyPRs with CI started, the required approvals, and no outstanding review comments.c++Issues and PRs that require attention from people who are familiar with C++.lib / srcIssues and PRs involving general changes in the lib/ or src/ directories.needs-ciPRs that need a full CI run.semver-minorPRs that contain new features and should be released in the next minor version.v24.xIssues that can be reproduced on v24.x or PRs targeting the v24.x-staging branch.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@RafaelGSS@nodejs-github-bot@aduh95@mawalu@edsadr@davidje13
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

[v24.x] Backport permission updates to v24 - #65354

Closed
RafaelGSS wants to merge 8 commits into
nodejs:v24.x-stagingfrom
RafaelGSS:backport-permission-updates-to-v24
Closed

[v24.x] Backport permission updates to v24#65354
RafaelGSS wants to merge 8 commits into
nodejs:v24.x-stagingfrom
RafaelGSS:backport-permission-updates-to-v24

Conversation

@RafaelGSSRafaelGSS added the semver-minor PRs that contain new features and should be released in the next minor version. label Aug 17, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/config
  • @nodejs/security-wg

@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. lib / src Issues and PRs involving general changes in the lib/ or src/ directories. needs-ci PRs that need a full CI run. v24.x Issues that can be reproduced on v24.x or PRs targeting the v24.x-staging branch. labels Aug 17, 2026
@codecov

codecovBot commented Aug 17, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 77.73109% with 53 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.28%. Comparing base (9e39360) to head (499c38a).
⚠️ Report is 2 commits behind head on v24.x-staging.

Files with missing linesPatch %Lines
src/permission/fs_permission.cc71.62%17 Missing and 4 partials ⚠️
src/permission/permission.cc83.05%3 Missing and 17 partials ⚠️
lib/internal/process/permission.js58.33%5 Missing ⚠️
src/permission/inspector_permission.cc0.00%3 Missing ⚠️
src/permission/wasi_permission.cc0.00%3 Missing ⚠️
src/node_binding.cc0.00%0 Missing and 1 partial ⚠️
Additional details and impacted files
@@ Coverage Diff @@## v24.x-staging #65354 +/- ##
=================================================
- Coverage 90.31% 90.28% -0.03% 
=================================================
Files 711 711 Lines 228425 228644 +219 Branches 43160 43200 +40 =================================================
+ Hits 206293 206425 +132 - Misses 14090 14100 +10 - Partials 8042 8119 +77 
Files with missing linesCoverage Δ
lib/internal/process/pre_execution.js98.18% <100.00%> (+0.52%)⬆️
src/env.cc80.72% <100.00%> (-0.12%)⬇️
src/node_options.cc76.58% <100.00%> (+0.02%)⬆️
src/node_options.h97.42% <100.00%> (-0.51%)⬇️
src/permission/addon_permission.cc100.00% <100.00%> (ø)
src/permission/child_process_permission.cc100.00% <100.00%> (ø)
src/permission/fs_permission.h91.78% <ø> (ø)
src/permission/permission.h100.00% <100.00%> (+16.66%)⬆️
src/permission/worker_permission.cc100.00% <100.00%> (ø)
src/node_binding.cc82.42% <0.00%> (-0.33%)⬇️
... and 5 more

... and 43 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@RafaelGSS
RafaelGSSforce-pushed the backport-permission-updates-to-v24 branch from 3b93be2 to 01e422dCompareAugust 17, 2026 19:57
@aduh95aduh95 added author ready PRs with CI started, the required approvals, and no outstanding review comments. request-ci Add this label to start a Jenkins CI on a PR. labels Aug 17, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 17, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

RafaelGSSand others added 8 commits August 17, 2026 19:21
Add --permission-audit flag that enables the permission model in
warning-only mode. Instead of throwing ERR_ACCESS_DENIED, it emits
a message via diagnostics channel and allows the operation to
continue.
Publish permission check results to per-scope diagnostics channels
(e.g., node:permission-model:fs) so users can observe permission
decisions at runtime via diagnostics_channel.
Refs: nodejs#59935
Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com>
PR-URL: nodejs#62672
Refs: nodejs#62223
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Signed-off-by: Martin <martin@asymmetric.re>
PR-URL: nodejs#64007
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Edy Silva <edigleyssonsilva@gmail.com>
The THROW_IF_INSUFFICIENT_PERMISSIONS and
ASYNC_THROW_IF_INSUFFICIENT_PERMISSIONS macros called
ThrowAccessDenied/AsyncThrowAccessDenied unconditionally and only
guarded the `return` with `warning_only()`.
ERR_ACCESS_DENIED_IF_INSUFFICIENT_PERMISSIONS had no `warning_only()`
guard at all — it always set the access-denied error and returned.
As a result, running with `--permission-audit` still produced
ERR_ACCESS_DENIED on any denied operation (fs, net, child_process,
worker, addon, ffi, inspector, wasi), defeating the audit-only purpose
of the flag.
Guard the denied-error path behind `!warning_only()` in all three
macros. In audit mode, the diagnostics-channel message is published
(already done in Permission::is_scope_granted) and execution continues;
in enforce mode (`--permission`), behavior is unchanged — the error is
raised and the call returns.
The tests cover both the direct (top-level) call and an `eval()`-wrapped
call: the direct call exercises the normal script path, and the
`eval()`-wrapped call exercises the V8 script-context boundary (the
diagnostics subscriber is registered in the outer module context while
the denied operation runs inside an eval'd string).
Refs: nodejs@9ddd1a9
Signed-off-by: Adrian Estrada <edsadr@gmail.com>
PR-URL: nodejs#64426
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Expand the documentation for the --permission-audit flag, which was
fixed in 51c09ea to no longer throw ERR_ACCESS_DENIED on denied
operations. The previous docs only had a two-sentence description in
cli.md and no mention in the permissions guide or process.permission
API docs.
- permissions.md: add enforce vs audit mode overview, a new
"Audit Mode" subsection listing the diagnostics channel names
(node:permission-model:*) and the { permission, resource } message
shape, and a usage example. Update the Runtime API section to
mention both --permission and --permission-audit.
- cli.md: expand the --permission-audit section to clarify that
--permission is not required, --allow-* flags are not needed,
errors are not thrown, and --permission takes precedence when both
are set. Add a cross-reference from --permission to
--permission-audit.
- process.md: note that process.permission is available under both
flags, and clarify permission.has() and permission.drop() behavior
in audit mode.
- node.1: regenerated via `make node.1`.
Refs: nodejs#64426
Signed-off-by: Adrian Estrada <edsadr@gmail.com>
PR-URL: nodejs#64791
Reviewed-By: Aviv Keller <me@aviv.sh>
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com>
Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
Adds unique warning codes of the form PERM0000 for all permissions
related SecurityWarnings, so that they can be individually silenced
if required.
Fixes: nodejs#59818
Signed-off-by: David Evans <davidje13@users.noreply.github.com>
PR-URL: nodejs#64414
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Ulises Gascón <ulisesgascongonzalez@gmail.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
@RafaelGSS
RafaelGSSforce-pushed the backport-permission-updates-to-v24 branch from 01e422d to 499c38aCompareAugust 17, 2026 22:56
@aduh95aduh95 added the request-ci Add this label to start a Jenkins CI on a PR. label Aug 19, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 19, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@aduh95

Copy link
Copy Markdown
Contributor

Landed in 82a0233...980c651

aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Add --permission-audit flag that enables the permission model in
warning-only mode. Instead of throwing ERR_ACCESS_DENIED, it emits
a message via diagnostics channel and allows the operation to
continue.
Publish permission check results to per-scope diagnostics channels
(e.g., node:permission-model:fs) so users can observe permission
decisions at runtime via diagnostics_channel.
Refs: #59935
PR-URL: #61869
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com>
PR-URL: #62672
Backport-PR-URL: #65354
Refs: #62223
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Signed-off-by: Martin <martin@asymmetric.re>
PR-URL: #64007
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
The THROW_IF_INSUFFICIENT_PERMISSIONS and
ASYNC_THROW_IF_INSUFFICIENT_PERMISSIONS macros called
ThrowAccessDenied/AsyncThrowAccessDenied unconditionally and only
guarded the `return` with `warning_only()`.
ERR_ACCESS_DENIED_IF_INSUFFICIENT_PERMISSIONS had no `warning_only()`
guard at all — it always set the access-denied error and returned.
As a result, running with `--permission-audit` still produced
ERR_ACCESS_DENIED on any denied operation (fs, net, child_process,
worker, addon, ffi, inspector, wasi), defeating the audit-only purpose
of the flag.
Guard the denied-error path behind `!warning_only()` in all three
macros. In audit mode, the diagnostics-channel message is published
(already done in Permission::is_scope_granted) and execution continues;
in enforce mode (`--permission`), behavior is unchanged — the error is
raised and the call returns.
The tests cover both the direct (top-level) call and an `eval()`-wrapped
call: the direct call exercises the normal script path, and the
`eval()`-wrapped call exercises the V8 script-context boundary (the
diagnostics subscriber is registered in the outer module context while
the denied operation runs inside an eval'd string).
Refs: 9ddd1a9
Signed-off-by: Adrian Estrada <edsadr@gmail.com>
PR-URL: #64426
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Expand the documentation for the --permission-audit flag, which was
fixed in 51c09ea to no longer throw ERR_ACCESS_DENIED on denied
operations. The previous docs only had a two-sentence description in
cli.md and no mention in the permissions guide or process.permission
API docs.
- permissions.md: add enforce vs audit mode overview, a new
"Audit Mode" subsection listing the diagnostics channel names
(node:permission-model:*) and the { permission, resource } message
shape, and a usage example. Update the Runtime API section to
mention both --permission and --permission-audit.
- cli.md: expand the --permission-audit section to clarify that
--permission is not required, --allow-* flags are not needed,
errors are not thrown, and --permission takes precedence when both
are set. Add a cross-reference from --permission to
--permission-audit.
- process.md: note that process.permission is available under both
flags, and clarify permission.has() and permission.drop() behavior
in audit mode.
- node.1: regenerated via `make node.1`.
Refs: #64426
Signed-off-by: Adrian Estrada <edsadr@gmail.com>
PR-URL: #64791
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Adds unique warning codes of the form PERM0000 for all permissions
related SecurityWarnings, so that they can be individually silenced
if required.
Fixes: #59818
Signed-off-by: David Evans <davidje13@users.noreply.github.com>
PR-URL: #64414
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
@aduh95aduh95 closed this Aug 20, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author readyPRs with CI started, the required approvals, and no outstanding review comments.c++Issues and PRs that require attention from people who are familiar with C++.lib / srcIssues and PRs involving general changes in the lib/ or src/ directories.needs-ciPRs that need a full CI run.semver-minorPRs that contain new features and should be released in the next minor version.v24.xIssues that can be reproduced on v24.x or PRs targeting the v24.x-staging branch.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@RafaelGSS@nodejs-github-bot@aduh95@mawalu@edsadr@davidje13
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[v24.x] Backport permission updates to v24 - #65354

Closed
RafaelGSS wants to merge 8 commits into
nodejs:v24.x-stagingfrom
RafaelGSS:backport-permission-updates-to-v24
Closed

[v24.x] Backport permission updates to v24#65354
RafaelGSS wants to merge 8 commits into
nodejs:v24.x-stagingfrom
RafaelGSS:backport-permission-updates-to-v24

Conversation

@RafaelGSSRafaelGSS added the semver-minor PRs that contain new features and should be released in the next minor version. label Aug 17, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/config
  • @nodejs/security-wg

@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. lib / src Issues and PRs involving general changes in the lib/ or src/ directories. needs-ci PRs that need a full CI run. v24.x Issues that can be reproduced on v24.x or PRs targeting the v24.x-staging branch. labels Aug 17, 2026
@codecov

codecovBot commented Aug 17, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 77.73109% with 53 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.28%. Comparing base (9e39360) to head (499c38a).
⚠️ Report is 2 commits behind head on v24.x-staging.

Files with missing linesPatch %Lines
src/permission/fs_permission.cc71.62%17 Missing and 4 partials ⚠️
src/permission/permission.cc83.05%3 Missing and 17 partials ⚠️
lib/internal/process/permission.js58.33%5 Missing ⚠️
src/permission/inspector_permission.cc0.00%3 Missing ⚠️
src/permission/wasi_permission.cc0.00%3 Missing ⚠️
src/node_binding.cc0.00%0 Missing and 1 partial ⚠️
Additional details and impacted files
@@ Coverage Diff @@## v24.x-staging #65354 +/- ##
=================================================
- Coverage 90.31% 90.28% -0.03% 
=================================================
Files 711 711 Lines 228425 228644 +219 Branches 43160 43200 +40 =================================================
+ Hits 206293 206425 +132 - Misses 14090 14100 +10 - Partials 8042 8119 +77 
Files with missing linesCoverage Δ
lib/internal/process/pre_execution.js98.18% <100.00%> (+0.52%)⬆️
src/env.cc80.72% <100.00%> (-0.12%)⬇️
src/node_options.cc76.58% <100.00%> (+0.02%)⬆️
src/node_options.h97.42% <100.00%> (-0.51%)⬇️
src/permission/addon_permission.cc100.00% <100.00%> (ø)
src/permission/child_process_permission.cc100.00% <100.00%> (ø)
src/permission/fs_permission.h91.78% <ø> (ø)
src/permission/permission.h100.00% <100.00%> (+16.66%)⬆️
src/permission/worker_permission.cc100.00% <100.00%> (ø)
src/node_binding.cc82.42% <0.00%> (-0.33%)⬇️
... and 5 more

... and 43 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@RafaelGSS
RafaelGSSforce-pushed the backport-permission-updates-to-v24 branch from 3b93be2 to 01e422dCompareAugust 17, 2026 19:57
@aduh95aduh95 added author ready PRs with CI started, the required approvals, and no outstanding review comments. request-ci Add this label to start a Jenkins CI on a PR. labels Aug 17, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 17, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

RafaelGSSand others added 8 commits August 17, 2026 19:21
Add --permission-audit flag that enables the permission model in
warning-only mode. Instead of throwing ERR_ACCESS_DENIED, it emits
a message via diagnostics channel and allows the operation to
continue.
Publish permission check results to per-scope diagnostics channels
(e.g., node:permission-model:fs) so users can observe permission
decisions at runtime via diagnostics_channel.
Refs: nodejs#59935
Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com>
PR-URL: nodejs#62672
Refs: nodejs#62223
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Signed-off-by: Martin <martin@asymmetric.re>
PR-URL: nodejs#64007
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Edy Silva <edigleyssonsilva@gmail.com>
The THROW_IF_INSUFFICIENT_PERMISSIONS and
ASYNC_THROW_IF_INSUFFICIENT_PERMISSIONS macros called
ThrowAccessDenied/AsyncThrowAccessDenied unconditionally and only
guarded the `return` with `warning_only()`.
ERR_ACCESS_DENIED_IF_INSUFFICIENT_PERMISSIONS had no `warning_only()`
guard at all — it always set the access-denied error and returned.
As a result, running with `--permission-audit` still produced
ERR_ACCESS_DENIED on any denied operation (fs, net, child_process,
worker, addon, ffi, inspector, wasi), defeating the audit-only purpose
of the flag.
Guard the denied-error path behind `!warning_only()` in all three
macros. In audit mode, the diagnostics-channel message is published
(already done in Permission::is_scope_granted) and execution continues;
in enforce mode (`--permission`), behavior is unchanged — the error is
raised and the call returns.
The tests cover both the direct (top-level) call and an `eval()`-wrapped
call: the direct call exercises the normal script path, and the
`eval()`-wrapped call exercises the V8 script-context boundary (the
diagnostics subscriber is registered in the outer module context while
the denied operation runs inside an eval'd string).
Refs: nodejs@9ddd1a9
Signed-off-by: Adrian Estrada <edsadr@gmail.com>
PR-URL: nodejs#64426
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Expand the documentation for the --permission-audit flag, which was
fixed in 51c09ea to no longer throw ERR_ACCESS_DENIED on denied
operations. The previous docs only had a two-sentence description in
cli.md and no mention in the permissions guide or process.permission
API docs.
- permissions.md: add enforce vs audit mode overview, a new
"Audit Mode" subsection listing the diagnostics channel names
(node:permission-model:*) and the { permission, resource } message
shape, and a usage example. Update the Runtime API section to
mention both --permission and --permission-audit.
- cli.md: expand the --permission-audit section to clarify that
--permission is not required, --allow-* flags are not needed,
errors are not thrown, and --permission takes precedence when both
are set. Add a cross-reference from --permission to
--permission-audit.
- process.md: note that process.permission is available under both
flags, and clarify permission.has() and permission.drop() behavior
in audit mode.
- node.1: regenerated via `make node.1`.
Refs: nodejs#64426
Signed-off-by: Adrian Estrada <edsadr@gmail.com>
PR-URL: nodejs#64791
Reviewed-By: Aviv Keller <me@aviv.sh>
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com>
Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
Adds unique warning codes of the form PERM0000 for all permissions
related SecurityWarnings, so that they can be individually silenced
if required.
Fixes: nodejs#59818
Signed-off-by: David Evans <davidje13@users.noreply.github.com>
PR-URL: nodejs#64414
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Ulises Gascón <ulisesgascongonzalez@gmail.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
@RafaelGSS
RafaelGSSforce-pushed the backport-permission-updates-to-v24 branch from 01e422d to 499c38aCompareAugust 17, 2026 22:56
@aduh95aduh95 added the request-ci Add this label to start a Jenkins CI on a PR. label Aug 19, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 19, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@aduh95

Copy link
Copy Markdown
Contributor

Landed in 82a0233...980c651

aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Add --permission-audit flag that enables the permission model in
warning-only mode. Instead of throwing ERR_ACCESS_DENIED, it emits
a message via diagnostics channel and allows the operation to
continue.
Publish permission check results to per-scope diagnostics channels
(e.g., node:permission-model:fs) so users can observe permission
decisions at runtime via diagnostics_channel.
Refs: #59935
PR-URL: #61869
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com>
PR-URL: #62672
Backport-PR-URL: #65354
Refs: #62223
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Signed-off-by: Martin <martin@asymmetric.re>
PR-URL: #64007
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
The THROW_IF_INSUFFICIENT_PERMISSIONS and
ASYNC_THROW_IF_INSUFFICIENT_PERMISSIONS macros called
ThrowAccessDenied/AsyncThrowAccessDenied unconditionally and only
guarded the `return` with `warning_only()`.
ERR_ACCESS_DENIED_IF_INSUFFICIENT_PERMISSIONS had no `warning_only()`
guard at all — it always set the access-denied error and returned.
As a result, running with `--permission-audit` still produced
ERR_ACCESS_DENIED on any denied operation (fs, net, child_process,
worker, addon, ffi, inspector, wasi), defeating the audit-only purpose
of the flag.
Guard the denied-error path behind `!warning_only()` in all three
macros. In audit mode, the diagnostics-channel message is published
(already done in Permission::is_scope_granted) and execution continues;
in enforce mode (`--permission`), behavior is unchanged — the error is
raised and the call returns.
The tests cover both the direct (top-level) call and an `eval()`-wrapped
call: the direct call exercises the normal script path, and the
`eval()`-wrapped call exercises the V8 script-context boundary (the
diagnostics subscriber is registered in the outer module context while
the denied operation runs inside an eval'd string).
Refs: 9ddd1a9
Signed-off-by: Adrian Estrada <edsadr@gmail.com>
PR-URL: #64426
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Expand the documentation for the --permission-audit flag, which was
fixed in 51c09ea to no longer throw ERR_ACCESS_DENIED on denied
operations. The previous docs only had a two-sentence description in
cli.md and no mention in the permissions guide or process.permission
API docs.
- permissions.md: add enforce vs audit mode overview, a new
"Audit Mode" subsection listing the diagnostics channel names
(node:permission-model:*) and the { permission, resource } message
shape, and a usage example. Update the Runtime API section to
mention both --permission and --permission-audit.
- cli.md: expand the --permission-audit section to clarify that
--permission is not required, --allow-* flags are not needed,
errors are not thrown, and --permission takes precedence when both
are set. Add a cross-reference from --permission to
--permission-audit.
- process.md: note that process.permission is available under both
flags, and clarify permission.has() and permission.drop() behavior
in audit mode.
- node.1: regenerated via `make node.1`.
Refs: #64426
Signed-off-by: Adrian Estrada <edsadr@gmail.com>
PR-URL: #64791
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Adds unique warning codes of the form PERM0000 for all permissions
related SecurityWarnings, so that they can be individually silenced
if required.
Fixes: #59818
Signed-off-by: David Evans <davidje13@users.noreply.github.com>
PR-URL: #64414
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
@aduh95aduh95 closed this Aug 20, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author readyPRs with CI started, the required approvals, and no outstanding review comments.c++Issues and PRs that require attention from people who are familiar with C++.lib / srcIssues and PRs involving general changes in the lib/ or src/ directories.needs-ciPRs that need a full CI run.semver-minorPRs that contain new features and should be released in the next minor version.v24.xIssues that can be reproduced on v24.x or PRs targeting the v24.x-staging branch.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@RafaelGSS@nodejs-github-bot@aduh95@mawalu@edsadr@davidje13
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[v24.x] Backport permission updates to v24 - #65354

Closed
RafaelGSS wants to merge 8 commits into
nodejs:v24.x-stagingfrom
RafaelGSS:backport-permission-updates-to-v24
Closed

[v24.x] Backport permission updates to v24#65354
RafaelGSS wants to merge 8 commits into
nodejs:v24.x-stagingfrom
RafaelGSS:backport-permission-updates-to-v24

Conversation

@RafaelGSSRafaelGSS added the semver-minor PRs that contain new features and should be released in the next minor version. label Aug 17, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/config
  • @nodejs/security-wg

@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. lib / src Issues and PRs involving general changes in the lib/ or src/ directories. needs-ci PRs that need a full CI run. v24.x Issues that can be reproduced on v24.x or PRs targeting the v24.x-staging branch. labels Aug 17, 2026
@codecov

codecovBot commented Aug 17, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 77.73109% with 53 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.28%. Comparing base (9e39360) to head (499c38a).
⚠️ Report is 2 commits behind head on v24.x-staging.

Files with missing linesPatch %Lines
src/permission/fs_permission.cc71.62%17 Missing and 4 partials ⚠️
src/permission/permission.cc83.05%3 Missing and 17 partials ⚠️
lib/internal/process/permission.js58.33%5 Missing ⚠️
src/permission/inspector_permission.cc0.00%3 Missing ⚠️
src/permission/wasi_permission.cc0.00%3 Missing ⚠️
src/node_binding.cc0.00%0 Missing and 1 partial ⚠️
Additional details and impacted files
@@ Coverage Diff @@## v24.x-staging #65354 +/- ##
=================================================
- Coverage 90.31% 90.28% -0.03% 
=================================================
Files 711 711 Lines 228425 228644 +219 Branches 43160 43200 +40 =================================================
+ Hits 206293 206425 +132 - Misses 14090 14100 +10 - Partials 8042 8119 +77 
Files with missing linesCoverage Δ
lib/internal/process/pre_execution.js98.18% <100.00%> (+0.52%)⬆️
src/env.cc80.72% <100.00%> (-0.12%)⬇️
src/node_options.cc76.58% <100.00%> (+0.02%)⬆️
src/node_options.h97.42% <100.00%> (-0.51%)⬇️
src/permission/addon_permission.cc100.00% <100.00%> (ø)
src/permission/child_process_permission.cc100.00% <100.00%> (ø)
src/permission/fs_permission.h91.78% <ø> (ø)
src/permission/permission.h100.00% <100.00%> (+16.66%)⬆️
src/permission/worker_permission.cc100.00% <100.00%> (ø)
src/node_binding.cc82.42% <0.00%> (-0.33%)⬇️
... and 5 more

... and 43 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@RafaelGSS
RafaelGSSforce-pushed the backport-permission-updates-to-v24 branch from 3b93be2 to 01e422dCompareAugust 17, 2026 19:57
@aduh95aduh95 added author ready PRs with CI started, the required approvals, and no outstanding review comments. request-ci Add this label to start a Jenkins CI on a PR. labels Aug 17, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 17, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

RafaelGSSand others added 8 commits August 17, 2026 19:21
Add --permission-audit flag that enables the permission model in
warning-only mode. Instead of throwing ERR_ACCESS_DENIED, it emits
a message via diagnostics channel and allows the operation to
continue.
Publish permission check results to per-scope diagnostics channels
(e.g., node:permission-model:fs) so users can observe permission
decisions at runtime via diagnostics_channel.
Refs: nodejs#59935
Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com>
PR-URL: nodejs#62672
Refs: nodejs#62223
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Signed-off-by: Martin <martin@asymmetric.re>
PR-URL: nodejs#64007
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Edy Silva <edigleyssonsilva@gmail.com>
The THROW_IF_INSUFFICIENT_PERMISSIONS and
ASYNC_THROW_IF_INSUFFICIENT_PERMISSIONS macros called
ThrowAccessDenied/AsyncThrowAccessDenied unconditionally and only
guarded the `return` with `warning_only()`.
ERR_ACCESS_DENIED_IF_INSUFFICIENT_PERMISSIONS had no `warning_only()`
guard at all — it always set the access-denied error and returned.
As a result, running with `--permission-audit` still produced
ERR_ACCESS_DENIED on any denied operation (fs, net, child_process,
worker, addon, ffi, inspector, wasi), defeating the audit-only purpose
of the flag.
Guard the denied-error path behind `!warning_only()` in all three
macros. In audit mode, the diagnostics-channel message is published
(already done in Permission::is_scope_granted) and execution continues;
in enforce mode (`--permission`), behavior is unchanged — the error is
raised and the call returns.
The tests cover both the direct (top-level) call and an `eval()`-wrapped
call: the direct call exercises the normal script path, and the
`eval()`-wrapped call exercises the V8 script-context boundary (the
diagnostics subscriber is registered in the outer module context while
the denied operation runs inside an eval'd string).
Refs: nodejs@9ddd1a9
Signed-off-by: Adrian Estrada <edsadr@gmail.com>
PR-URL: nodejs#64426
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Expand the documentation for the --permission-audit flag, which was
fixed in 51c09ea to no longer throw ERR_ACCESS_DENIED on denied
operations. The previous docs only had a two-sentence description in
cli.md and no mention in the permissions guide or process.permission
API docs.
- permissions.md: add enforce vs audit mode overview, a new
"Audit Mode" subsection listing the diagnostics channel names
(node:permission-model:*) and the { permission, resource } message
shape, and a usage example. Update the Runtime API section to
mention both --permission and --permission-audit.
- cli.md: expand the --permission-audit section to clarify that
--permission is not required, --allow-* flags are not needed,
errors are not thrown, and --permission takes precedence when both
are set. Add a cross-reference from --permission to
--permission-audit.
- process.md: note that process.permission is available under both
flags, and clarify permission.has() and permission.drop() behavior
in audit mode.
- node.1: regenerated via `make node.1`.
Refs: nodejs#64426
Signed-off-by: Adrian Estrada <edsadr@gmail.com>
PR-URL: nodejs#64791
Reviewed-By: Aviv Keller <me@aviv.sh>
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com>
Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
Adds unique warning codes of the form PERM0000 for all permissions
related SecurityWarnings, so that they can be individually silenced
if required.
Fixes: nodejs#59818
Signed-off-by: David Evans <davidje13@users.noreply.github.com>
PR-URL: nodejs#64414
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Ulises Gascón <ulisesgascongonzalez@gmail.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
@RafaelGSS
RafaelGSSforce-pushed the backport-permission-updates-to-v24 branch from 01e422d to 499c38aCompareAugust 17, 2026 22:56
@aduh95aduh95 added the request-ci Add this label to start a Jenkins CI on a PR. label Aug 19, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 19, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@aduh95

Copy link
Copy Markdown
Contributor

Landed in 82a0233...980c651

aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Add --permission-audit flag that enables the permission model in
warning-only mode. Instead of throwing ERR_ACCESS_DENIED, it emits
a message via diagnostics channel and allows the operation to
continue.
Publish permission check results to per-scope diagnostics channels
(e.g., node:permission-model:fs) so users can observe permission
decisions at runtime via diagnostics_channel.
Refs: #59935
PR-URL: #61869
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com>
PR-URL: #62672
Backport-PR-URL: #65354
Refs: #62223
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Signed-off-by: Martin <martin@asymmetric.re>
PR-URL: #64007
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
The THROW_IF_INSUFFICIENT_PERMISSIONS and
ASYNC_THROW_IF_INSUFFICIENT_PERMISSIONS macros called
ThrowAccessDenied/AsyncThrowAccessDenied unconditionally and only
guarded the `return` with `warning_only()`.
ERR_ACCESS_DENIED_IF_INSUFFICIENT_PERMISSIONS had no `warning_only()`
guard at all — it always set the access-denied error and returned.
As a result, running with `--permission-audit` still produced
ERR_ACCESS_DENIED on any denied operation (fs, net, child_process,
worker, addon, ffi, inspector, wasi), defeating the audit-only purpose
of the flag.
Guard the denied-error path behind `!warning_only()` in all three
macros. In audit mode, the diagnostics-channel message is published
(already done in Permission::is_scope_granted) and execution continues;
in enforce mode (`--permission`), behavior is unchanged — the error is
raised and the call returns.
The tests cover both the direct (top-level) call and an `eval()`-wrapped
call: the direct call exercises the normal script path, and the
`eval()`-wrapped call exercises the V8 script-context boundary (the
diagnostics subscriber is registered in the outer module context while
the denied operation runs inside an eval'd string).
Refs: 9ddd1a9
Signed-off-by: Adrian Estrada <edsadr@gmail.com>
PR-URL: #64426
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Expand the documentation for the --permission-audit flag, which was
fixed in 51c09ea to no longer throw ERR_ACCESS_DENIED on denied
operations. The previous docs only had a two-sentence description in
cli.md and no mention in the permissions guide or process.permission
API docs.
- permissions.md: add enforce vs audit mode overview, a new
"Audit Mode" subsection listing the diagnostics channel names
(node:permission-model:*) and the { permission, resource } message
shape, and a usage example. Update the Runtime API section to
mention both --permission and --permission-audit.
- cli.md: expand the --permission-audit section to clarify that
--permission is not required, --allow-* flags are not needed,
errors are not thrown, and --permission takes precedence when both
are set. Add a cross-reference from --permission to
--permission-audit.
- process.md: note that process.permission is available under both
flags, and clarify permission.has() and permission.drop() behavior
in audit mode.
- node.1: regenerated via `make node.1`.
Refs: #64426
Signed-off-by: Adrian Estrada <edsadr@gmail.com>
PR-URL: #64791
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Adds unique warning codes of the form PERM0000 for all permissions
related SecurityWarnings, so that they can be individually silenced
if required.
Fixes: #59818
Signed-off-by: David Evans <davidje13@users.noreply.github.com>
PR-URL: #64414
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
@aduh95aduh95 closed this Aug 20, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author readyPRs with CI started, the required approvals, and no outstanding review comments.c++Issues and PRs that require attention from people who are familiar with C++.lib / srcIssues and PRs involving general changes in the lib/ or src/ directories.needs-ciPRs that need a full CI run.semver-minorPRs that contain new features and should be released in the next minor version.v24.xIssues that can be reproduced on v24.x or PRs targeting the v24.x-staging branch.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@RafaelGSS@nodejs-github-bot@aduh95@mawalu@edsadr@davidje13
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

[v24.x] Backport permission updates to v24 - #65354

Closed
RafaelGSS wants to merge 8 commits into
nodejs:v24.x-stagingfrom
RafaelGSS:backport-permission-updates-to-v24
Closed

[v24.x] Backport permission updates to v24#65354
RafaelGSS wants to merge 8 commits into
nodejs:v24.x-stagingfrom
RafaelGSS:backport-permission-updates-to-v24

Conversation

@RafaelGSSRafaelGSS added the semver-minor PRs that contain new features and should be released in the next minor version. label Aug 17, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/config
  • @nodejs/security-wg

@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. lib / src Issues and PRs involving general changes in the lib/ or src/ directories. needs-ci PRs that need a full CI run. v24.x Issues that can be reproduced on v24.x or PRs targeting the v24.x-staging branch. labels Aug 17, 2026
@codecov

codecovBot commented Aug 17, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 77.73109% with 53 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.28%. Comparing base (9e39360) to head (499c38a).
⚠️ Report is 2 commits behind head on v24.x-staging.

Files with missing linesPatch %Lines
src/permission/fs_permission.cc71.62%17 Missing and 4 partials ⚠️
src/permission/permission.cc83.05%3 Missing and 17 partials ⚠️
lib/internal/process/permission.js58.33%5 Missing ⚠️
src/permission/inspector_permission.cc0.00%3 Missing ⚠️
src/permission/wasi_permission.cc0.00%3 Missing ⚠️
src/node_binding.cc0.00%0 Missing and 1 partial ⚠️
Additional details and impacted files
@@ Coverage Diff @@## v24.x-staging #65354 +/- ##
=================================================
- Coverage 90.31% 90.28% -0.03% 
=================================================
Files 711 711 Lines 228425 228644 +219 Branches 43160 43200 +40 =================================================
+ Hits 206293 206425 +132 - Misses 14090 14100 +10 - Partials 8042 8119 +77 
Files with missing linesCoverage Δ
lib/internal/process/pre_execution.js98.18% <100.00%> (+0.52%)⬆️
src/env.cc80.72% <100.00%> (-0.12%)⬇️
src/node_options.cc76.58% <100.00%> (+0.02%)⬆️
src/node_options.h97.42% <100.00%> (-0.51%)⬇️
src/permission/addon_permission.cc100.00% <100.00%> (ø)
src/permission/child_process_permission.cc100.00% <100.00%> (ø)
src/permission/fs_permission.h91.78% <ø> (ø)
src/permission/permission.h100.00% <100.00%> (+16.66%)⬆️
src/permission/worker_permission.cc100.00% <100.00%> (ø)
src/node_binding.cc82.42% <0.00%> (-0.33%)⬇️
... and 5 more

... and 43 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@RafaelGSS
RafaelGSSforce-pushed the backport-permission-updates-to-v24 branch from 3b93be2 to 01e422dCompareAugust 17, 2026 19:57
@aduh95aduh95 added author ready PRs with CI started, the required approvals, and no outstanding review comments. request-ci Add this label to start a Jenkins CI on a PR. labels Aug 17, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 17, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

RafaelGSSand others added 8 commits August 17, 2026 19:21
Add --permission-audit flag that enables the permission model in
warning-only mode. Instead of throwing ERR_ACCESS_DENIED, it emits
a message via diagnostics channel and allows the operation to
continue.
Publish permission check results to per-scope diagnostics channels
(e.g., node:permission-model:fs) so users can observe permission
decisions at runtime via diagnostics_channel.
Refs: nodejs#59935
Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com>
PR-URL: nodejs#62672
Refs: nodejs#62223
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Signed-off-by: Martin <martin@asymmetric.re>
PR-URL: nodejs#64007
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Edy Silva <edigleyssonsilva@gmail.com>
The THROW_IF_INSUFFICIENT_PERMISSIONS and
ASYNC_THROW_IF_INSUFFICIENT_PERMISSIONS macros called
ThrowAccessDenied/AsyncThrowAccessDenied unconditionally and only
guarded the `return` with `warning_only()`.
ERR_ACCESS_DENIED_IF_INSUFFICIENT_PERMISSIONS had no `warning_only()`
guard at all — it always set the access-denied error and returned.
As a result, running with `--permission-audit` still produced
ERR_ACCESS_DENIED on any denied operation (fs, net, child_process,
worker, addon, ffi, inspector, wasi), defeating the audit-only purpose
of the flag.
Guard the denied-error path behind `!warning_only()` in all three
macros. In audit mode, the diagnostics-channel message is published
(already done in Permission::is_scope_granted) and execution continues;
in enforce mode (`--permission`), behavior is unchanged — the error is
raised and the call returns.
The tests cover both the direct (top-level) call and an `eval()`-wrapped
call: the direct call exercises the normal script path, and the
`eval()`-wrapped call exercises the V8 script-context boundary (the
diagnostics subscriber is registered in the outer module context while
the denied operation runs inside an eval'd string).
Refs: nodejs@9ddd1a9
Signed-off-by: Adrian Estrada <edsadr@gmail.com>
PR-URL: nodejs#64426
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Expand the documentation for the --permission-audit flag, which was
fixed in 51c09ea to no longer throw ERR_ACCESS_DENIED on denied
operations. The previous docs only had a two-sentence description in
cli.md and no mention in the permissions guide or process.permission
API docs.
- permissions.md: add enforce vs audit mode overview, a new
"Audit Mode" subsection listing the diagnostics channel names
(node:permission-model:*) and the { permission, resource } message
shape, and a usage example. Update the Runtime API section to
mention both --permission and --permission-audit.
- cli.md: expand the --permission-audit section to clarify that
--permission is not required, --allow-* flags are not needed,
errors are not thrown, and --permission takes precedence when both
are set. Add a cross-reference from --permission to
--permission-audit.
- process.md: note that process.permission is available under both
flags, and clarify permission.has() and permission.drop() behavior
in audit mode.
- node.1: regenerated via `make node.1`.
Refs: nodejs#64426
Signed-off-by: Adrian Estrada <edsadr@gmail.com>
PR-URL: nodejs#64791
Reviewed-By: Aviv Keller <me@aviv.sh>
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com>
Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
Adds unique warning codes of the form PERM0000 for all permissions
related SecurityWarnings, so that they can be individually silenced
if required.
Fixes: nodejs#59818
Signed-off-by: David Evans <davidje13@users.noreply.github.com>
PR-URL: nodejs#64414
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Ulises Gascón <ulisesgascongonzalez@gmail.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
@RafaelGSS
RafaelGSSforce-pushed the backport-permission-updates-to-v24 branch from 01e422d to 499c38aCompareAugust 17, 2026 22:56
@aduh95aduh95 added the request-ci Add this label to start a Jenkins CI on a PR. label Aug 19, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 19, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@aduh95

Copy link
Copy Markdown
Contributor

Landed in 82a0233...980c651

aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Add --permission-audit flag that enables the permission model in
warning-only mode. Instead of throwing ERR_ACCESS_DENIED, it emits
a message via diagnostics channel and allows the operation to
continue.
Publish permission check results to per-scope diagnostics channels
(e.g., node:permission-model:fs) so users can observe permission
decisions at runtime via diagnostics_channel.
Refs: #59935
PR-URL: #61869
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com>
PR-URL: #62672
Backport-PR-URL: #65354
Refs: #62223
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Signed-off-by: Martin <martin@asymmetric.re>
PR-URL: #64007
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
The THROW_IF_INSUFFICIENT_PERMISSIONS and
ASYNC_THROW_IF_INSUFFICIENT_PERMISSIONS macros called
ThrowAccessDenied/AsyncThrowAccessDenied unconditionally and only
guarded the `return` with `warning_only()`.
ERR_ACCESS_DENIED_IF_INSUFFICIENT_PERMISSIONS had no `warning_only()`
guard at all — it always set the access-denied error and returned.
As a result, running with `--permission-audit` still produced
ERR_ACCESS_DENIED on any denied operation (fs, net, child_process,
worker, addon, ffi, inspector, wasi), defeating the audit-only purpose
of the flag.
Guard the denied-error path behind `!warning_only()` in all three
macros. In audit mode, the diagnostics-channel message is published
(already done in Permission::is_scope_granted) and execution continues;
in enforce mode (`--permission`), behavior is unchanged — the error is
raised and the call returns.
The tests cover both the direct (top-level) call and an `eval()`-wrapped
call: the direct call exercises the normal script path, and the
`eval()`-wrapped call exercises the V8 script-context boundary (the
diagnostics subscriber is registered in the outer module context while
the denied operation runs inside an eval'd string).
Refs: 9ddd1a9
Signed-off-by: Adrian Estrada <edsadr@gmail.com>
PR-URL: #64426
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Expand the documentation for the --permission-audit flag, which was
fixed in 51c09ea to no longer throw ERR_ACCESS_DENIED on denied
operations. The previous docs only had a two-sentence description in
cli.md and no mention in the permissions guide or process.permission
API docs.
- permissions.md: add enforce vs audit mode overview, a new
"Audit Mode" subsection listing the diagnostics channel names
(node:permission-model:*) and the { permission, resource } message
shape, and a usage example. Update the Runtime API section to
mention both --permission and --permission-audit.
- cli.md: expand the --permission-audit section to clarify that
--permission is not required, --allow-* flags are not needed,
errors are not thrown, and --permission takes precedence when both
are set. Add a cross-reference from --permission to
--permission-audit.
- process.md: note that process.permission is available under both
flags, and clarify permission.has() and permission.drop() behavior
in audit mode.
- node.1: regenerated via `make node.1`.
Refs: #64426
Signed-off-by: Adrian Estrada <edsadr@gmail.com>
PR-URL: #64791
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Adds unique warning codes of the form PERM0000 for all permissions
related SecurityWarnings, so that they can be individually silenced
if required.
Fixes: #59818
Signed-off-by: David Evans <davidje13@users.noreply.github.com>
PR-URL: #64414
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
@aduh95aduh95 closed this Aug 20, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author readyPRs with CI started, the required approvals, and no outstanding review comments.c++Issues and PRs that require attention from people who are familiar with C++.lib / srcIssues and PRs involving general changes in the lib/ or src/ directories.needs-ciPRs that need a full CI run.semver-minorPRs that contain new features and should be released in the next minor version.v24.xIssues that can be reproduced on v24.x or PRs targeting the v24.x-staging branch.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@RafaelGSS@nodejs-github-bot@aduh95@mawalu@edsadr@davidje13
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[v24.x] Backport permission updates to v24 - #65354

Closed
RafaelGSS wants to merge 8 commits into
nodejs:v24.x-stagingfrom
RafaelGSS:backport-permission-updates-to-v24
Closed

[v24.x] Backport permission updates to v24#65354
RafaelGSS wants to merge 8 commits into
nodejs:v24.x-stagingfrom
RafaelGSS:backport-permission-updates-to-v24

Conversation

@RafaelGSSRafaelGSS added the semver-minor PRs that contain new features and should be released in the next minor version. label Aug 17, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/config
  • @nodejs/security-wg

@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. lib / src Issues and PRs involving general changes in the lib/ or src/ directories. needs-ci PRs that need a full CI run. v24.x Issues that can be reproduced on v24.x or PRs targeting the v24.x-staging branch. labels Aug 17, 2026
@codecov

codecovBot commented Aug 17, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 77.73109% with 53 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.28%. Comparing base (9e39360) to head (499c38a).
⚠️ Report is 2 commits behind head on v24.x-staging.

Files with missing linesPatch %Lines
src/permission/fs_permission.cc71.62%17 Missing and 4 partials ⚠️
src/permission/permission.cc83.05%3 Missing and 17 partials ⚠️
lib/internal/process/permission.js58.33%5 Missing ⚠️
src/permission/inspector_permission.cc0.00%3 Missing ⚠️
src/permission/wasi_permission.cc0.00%3 Missing ⚠️
src/node_binding.cc0.00%0 Missing and 1 partial ⚠️
Additional details and impacted files
@@ Coverage Diff @@## v24.x-staging #65354 +/- ##
=================================================
- Coverage 90.31% 90.28% -0.03% 
=================================================
Files 711 711 Lines 228425 228644 +219 Branches 43160 43200 +40 =================================================
+ Hits 206293 206425 +132 - Misses 14090 14100 +10 - Partials 8042 8119 +77 
Files with missing linesCoverage Δ
lib/internal/process/pre_execution.js98.18% <100.00%> (+0.52%)⬆️
src/env.cc80.72% <100.00%> (-0.12%)⬇️
src/node_options.cc76.58% <100.00%> (+0.02%)⬆️
src/node_options.h97.42% <100.00%> (-0.51%)⬇️
src/permission/addon_permission.cc100.00% <100.00%> (ø)
src/permission/child_process_permission.cc100.00% <100.00%> (ø)
src/permission/fs_permission.h91.78% <ø> (ø)
src/permission/permission.h100.00% <100.00%> (+16.66%)⬆️
src/permission/worker_permission.cc100.00% <100.00%> (ø)
src/node_binding.cc82.42% <0.00%> (-0.33%)⬇️
... and 5 more

... and 43 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@RafaelGSS
RafaelGSSforce-pushed the backport-permission-updates-to-v24 branch from 3b93be2 to 01e422dCompareAugust 17, 2026 19:57
@aduh95aduh95 added author ready PRs with CI started, the required approvals, and no outstanding review comments. request-ci Add this label to start a Jenkins CI on a PR. labels Aug 17, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 17, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

RafaelGSSand others added 8 commits August 17, 2026 19:21
Add --permission-audit flag that enables the permission model in
warning-only mode. Instead of throwing ERR_ACCESS_DENIED, it emits
a message via diagnostics channel and allows the operation to
continue.
Publish permission check results to per-scope diagnostics channels
(e.g., node:permission-model:fs) so users can observe permission
decisions at runtime via diagnostics_channel.
Refs: nodejs#59935
Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com>
PR-URL: nodejs#62672
Refs: nodejs#62223
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Signed-off-by: Martin <martin@asymmetric.re>
PR-URL: nodejs#64007
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Edy Silva <edigleyssonsilva@gmail.com>
The THROW_IF_INSUFFICIENT_PERMISSIONS and
ASYNC_THROW_IF_INSUFFICIENT_PERMISSIONS macros called
ThrowAccessDenied/AsyncThrowAccessDenied unconditionally and only
guarded the `return` with `warning_only()`.
ERR_ACCESS_DENIED_IF_INSUFFICIENT_PERMISSIONS had no `warning_only()`
guard at all — it always set the access-denied error and returned.
As a result, running with `--permission-audit` still produced
ERR_ACCESS_DENIED on any denied operation (fs, net, child_process,
worker, addon, ffi, inspector, wasi), defeating the audit-only purpose
of the flag.
Guard the denied-error path behind `!warning_only()` in all three
macros. In audit mode, the diagnostics-channel message is published
(already done in Permission::is_scope_granted) and execution continues;
in enforce mode (`--permission`), behavior is unchanged — the error is
raised and the call returns.
The tests cover both the direct (top-level) call and an `eval()`-wrapped
call: the direct call exercises the normal script path, and the
`eval()`-wrapped call exercises the V8 script-context boundary (the
diagnostics subscriber is registered in the outer module context while
the denied operation runs inside an eval'd string).
Refs: nodejs@9ddd1a9
Signed-off-by: Adrian Estrada <edsadr@gmail.com>
PR-URL: nodejs#64426
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Expand the documentation for the --permission-audit flag, which was
fixed in 51c09ea to no longer throw ERR_ACCESS_DENIED on denied
operations. The previous docs only had a two-sentence description in
cli.md and no mention in the permissions guide or process.permission
API docs.
- permissions.md: add enforce vs audit mode overview, a new
"Audit Mode" subsection listing the diagnostics channel names
(node:permission-model:*) and the { permission, resource } message
shape, and a usage example. Update the Runtime API section to
mention both --permission and --permission-audit.
- cli.md: expand the --permission-audit section to clarify that
--permission is not required, --allow-* flags are not needed,
errors are not thrown, and --permission takes precedence when both
are set. Add a cross-reference from --permission to
--permission-audit.
- process.md: note that process.permission is available under both
flags, and clarify permission.has() and permission.drop() behavior
in audit mode.
- node.1: regenerated via `make node.1`.
Refs: nodejs#64426
Signed-off-by: Adrian Estrada <edsadr@gmail.com>
PR-URL: nodejs#64791
Reviewed-By: Aviv Keller <me@aviv.sh>
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com>
Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
Adds unique warning codes of the form PERM0000 for all permissions
related SecurityWarnings, so that they can be individually silenced
if required.
Fixes: nodejs#59818
Signed-off-by: David Evans <davidje13@users.noreply.github.com>
PR-URL: nodejs#64414
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Ulises Gascón <ulisesgascongonzalez@gmail.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
@RafaelGSS
RafaelGSSforce-pushed the backport-permission-updates-to-v24 branch from 01e422d to 499c38aCompareAugust 17, 2026 22:56
@aduh95aduh95 added the request-ci Add this label to start a Jenkins CI on a PR. label Aug 19, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 19, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@aduh95

Copy link
Copy Markdown
Contributor

Landed in 82a0233...980c651

aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Add --permission-audit flag that enables the permission model in
warning-only mode. Instead of throwing ERR_ACCESS_DENIED, it emits
a message via diagnostics channel and allows the operation to
continue.
Publish permission check results to per-scope diagnostics channels
(e.g., node:permission-model:fs) so users can observe permission
decisions at runtime via diagnostics_channel.
Refs: #59935
PR-URL: #61869
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com>
PR-URL: #62672
Backport-PR-URL: #65354
Refs: #62223
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Signed-off-by: Martin <martin@asymmetric.re>
PR-URL: #64007
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
The THROW_IF_INSUFFICIENT_PERMISSIONS and
ASYNC_THROW_IF_INSUFFICIENT_PERMISSIONS macros called
ThrowAccessDenied/AsyncThrowAccessDenied unconditionally and only
guarded the `return` with `warning_only()`.
ERR_ACCESS_DENIED_IF_INSUFFICIENT_PERMISSIONS had no `warning_only()`
guard at all — it always set the access-denied error and returned.
As a result, running with `--permission-audit` still produced
ERR_ACCESS_DENIED on any denied operation (fs, net, child_process,
worker, addon, ffi, inspector, wasi), defeating the audit-only purpose
of the flag.
Guard the denied-error path behind `!warning_only()` in all three
macros. In audit mode, the diagnostics-channel message is published
(already done in Permission::is_scope_granted) and execution continues;
in enforce mode (`--permission`), behavior is unchanged — the error is
raised and the call returns.
The tests cover both the direct (top-level) call and an `eval()`-wrapped
call: the direct call exercises the normal script path, and the
`eval()`-wrapped call exercises the V8 script-context boundary (the
diagnostics subscriber is registered in the outer module context while
the denied operation runs inside an eval'd string).
Refs: 9ddd1a9
Signed-off-by: Adrian Estrada <edsadr@gmail.com>
PR-URL: #64426
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Expand the documentation for the --permission-audit flag, which was
fixed in 51c09ea to no longer throw ERR_ACCESS_DENIED on denied
operations. The previous docs only had a two-sentence description in
cli.md and no mention in the permissions guide or process.permission
API docs.
- permissions.md: add enforce vs audit mode overview, a new
"Audit Mode" subsection listing the diagnostics channel names
(node:permission-model:*) and the { permission, resource } message
shape, and a usage example. Update the Runtime API section to
mention both --permission and --permission-audit.
- cli.md: expand the --permission-audit section to clarify that
--permission is not required, --allow-* flags are not needed,
errors are not thrown, and --permission takes precedence when both
are set. Add a cross-reference from --permission to
--permission-audit.
- process.md: note that process.permission is available under both
flags, and clarify permission.has() and permission.drop() behavior
in audit mode.
- node.1: regenerated via `make node.1`.
Refs: #64426
Signed-off-by: Adrian Estrada <edsadr@gmail.com>
PR-URL: #64791
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Adds unique warning codes of the form PERM0000 for all permissions
related SecurityWarnings, so that they can be individually silenced
if required.
Fixes: #59818
Signed-off-by: David Evans <davidje13@users.noreply.github.com>
PR-URL: #64414
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
@aduh95aduh95 closed this Aug 20, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author readyPRs with CI started, the required approvals, and no outstanding review comments.c++Issues and PRs that require attention from people who are familiar with C++.lib / srcIssues and PRs involving general changes in the lib/ or src/ directories.needs-ciPRs that need a full CI run.semver-minorPRs that contain new features and should be released in the next minor version.v24.xIssues that can be reproduced on v24.x or PRs targeting the v24.x-staging branch.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@RafaelGSS@nodejs-github-bot@aduh95@mawalu@edsadr@davidje13
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[v24.x] Backport permission updates to v24 - #65354

Closed
RafaelGSS wants to merge 8 commits into
nodejs:v24.x-stagingfrom
RafaelGSS:backport-permission-updates-to-v24
Closed

[v24.x] Backport permission updates to v24#65354
RafaelGSS wants to merge 8 commits into
nodejs:v24.x-stagingfrom
RafaelGSS:backport-permission-updates-to-v24

Conversation

@RafaelGSSRafaelGSS added the semver-minor PRs that contain new features and should be released in the next minor version. label Aug 17, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/config
  • @nodejs/security-wg

@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. lib / src Issues and PRs involving general changes in the lib/ or src/ directories. needs-ci PRs that need a full CI run. v24.x Issues that can be reproduced on v24.x or PRs targeting the v24.x-staging branch. labels Aug 17, 2026
@codecov

codecovBot commented Aug 17, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 77.73109% with 53 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.28%. Comparing base (9e39360) to head (499c38a).
⚠️ Report is 2 commits behind head on v24.x-staging.

Files with missing linesPatch %Lines
src/permission/fs_permission.cc71.62%17 Missing and 4 partials ⚠️
src/permission/permission.cc83.05%3 Missing and 17 partials ⚠️
lib/internal/process/permission.js58.33%5 Missing ⚠️
src/permission/inspector_permission.cc0.00%3 Missing ⚠️
src/permission/wasi_permission.cc0.00%3 Missing ⚠️
src/node_binding.cc0.00%0 Missing and 1 partial ⚠️
Additional details and impacted files
@@ Coverage Diff @@## v24.x-staging #65354 +/- ##
=================================================
- Coverage 90.31% 90.28% -0.03% 
=================================================
Files 711 711 Lines 228425 228644 +219 Branches 43160 43200 +40 =================================================
+ Hits 206293 206425 +132 - Misses 14090 14100 +10 - Partials 8042 8119 +77 
Files with missing linesCoverage Δ
lib/internal/process/pre_execution.js98.18% <100.00%> (+0.52%)⬆️
src/env.cc80.72% <100.00%> (-0.12%)⬇️
src/node_options.cc76.58% <100.00%> (+0.02%)⬆️
src/node_options.h97.42% <100.00%> (-0.51%)⬇️
src/permission/addon_permission.cc100.00% <100.00%> (ø)
src/permission/child_process_permission.cc100.00% <100.00%> (ø)
src/permission/fs_permission.h91.78% <ø> (ø)
src/permission/permission.h100.00% <100.00%> (+16.66%)⬆️
src/permission/worker_permission.cc100.00% <100.00%> (ø)
src/node_binding.cc82.42% <0.00%> (-0.33%)⬇️
... and 5 more

... and 43 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@RafaelGSS
RafaelGSSforce-pushed the backport-permission-updates-to-v24 branch from 3b93be2 to 01e422dCompareAugust 17, 2026 19:57
@aduh95aduh95 added author ready PRs with CI started, the required approvals, and no outstanding review comments. request-ci Add this label to start a Jenkins CI on a PR. labels Aug 17, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 17, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

RafaelGSSand others added 8 commits August 17, 2026 19:21
Add --permission-audit flag that enables the permission model in
warning-only mode. Instead of throwing ERR_ACCESS_DENIED, it emits
a message via diagnostics channel and allows the operation to
continue.
Publish permission check results to per-scope diagnostics channels
(e.g., node:permission-model:fs) so users can observe permission
decisions at runtime via diagnostics_channel.
Refs: nodejs#59935
Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com>
PR-URL: nodejs#62672
Refs: nodejs#62223
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Signed-off-by: Martin <martin@asymmetric.re>
PR-URL: nodejs#64007
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Edy Silva <edigleyssonsilva@gmail.com>
The THROW_IF_INSUFFICIENT_PERMISSIONS and
ASYNC_THROW_IF_INSUFFICIENT_PERMISSIONS macros called
ThrowAccessDenied/AsyncThrowAccessDenied unconditionally and only
guarded the `return` with `warning_only()`.
ERR_ACCESS_DENIED_IF_INSUFFICIENT_PERMISSIONS had no `warning_only()`
guard at all — it always set the access-denied error and returned.
As a result, running with `--permission-audit` still produced
ERR_ACCESS_DENIED on any denied operation (fs, net, child_process,
worker, addon, ffi, inspector, wasi), defeating the audit-only purpose
of the flag.
Guard the denied-error path behind `!warning_only()` in all three
macros. In audit mode, the diagnostics-channel message is published
(already done in Permission::is_scope_granted) and execution continues;
in enforce mode (`--permission`), behavior is unchanged — the error is
raised and the call returns.
The tests cover both the direct (top-level) call and an `eval()`-wrapped
call: the direct call exercises the normal script path, and the
`eval()`-wrapped call exercises the V8 script-context boundary (the
diagnostics subscriber is registered in the outer module context while
the denied operation runs inside an eval'd string).
Refs: nodejs@9ddd1a9
Signed-off-by: Adrian Estrada <edsadr@gmail.com>
PR-URL: nodejs#64426
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Expand the documentation for the --permission-audit flag, which was
fixed in 51c09ea to no longer throw ERR_ACCESS_DENIED on denied
operations. The previous docs only had a two-sentence description in
cli.md and no mention in the permissions guide or process.permission
API docs.
- permissions.md: add enforce vs audit mode overview, a new
"Audit Mode" subsection listing the diagnostics channel names
(node:permission-model:*) and the { permission, resource } message
shape, and a usage example. Update the Runtime API section to
mention both --permission and --permission-audit.
- cli.md: expand the --permission-audit section to clarify that
--permission is not required, --allow-* flags are not needed,
errors are not thrown, and --permission takes precedence when both
are set. Add a cross-reference from --permission to
--permission-audit.
- process.md: note that process.permission is available under both
flags, and clarify permission.has() and permission.drop() behavior
in audit mode.
- node.1: regenerated via `make node.1`.
Refs: nodejs#64426
Signed-off-by: Adrian Estrada <edsadr@gmail.com>
PR-URL: nodejs#64791
Reviewed-By: Aviv Keller <me@aviv.sh>
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com>
Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
Adds unique warning codes of the form PERM0000 for all permissions
related SecurityWarnings, so that they can be individually silenced
if required.
Fixes: nodejs#59818
Signed-off-by: David Evans <davidje13@users.noreply.github.com>
PR-URL: nodejs#64414
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Ulises Gascón <ulisesgascongonzalez@gmail.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
@RafaelGSS
RafaelGSSforce-pushed the backport-permission-updates-to-v24 branch from 01e422d to 499c38aCompareAugust 17, 2026 22:56
@aduh95aduh95 added the request-ci Add this label to start a Jenkins CI on a PR. label Aug 19, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 19, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@aduh95

Copy link
Copy Markdown
Contributor

Landed in 82a0233...980c651

aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Add --permission-audit flag that enables the permission model in
warning-only mode. Instead of throwing ERR_ACCESS_DENIED, it emits
a message via diagnostics channel and allows the operation to
continue.
Publish permission check results to per-scope diagnostics channels
(e.g., node:permission-model:fs) so users can observe permission
decisions at runtime via diagnostics_channel.
Refs: #59935
PR-URL: #61869
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com>
PR-URL: #62672
Backport-PR-URL: #65354
Refs: #62223
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Signed-off-by: Martin <martin@asymmetric.re>
PR-URL: #64007
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
The THROW_IF_INSUFFICIENT_PERMISSIONS and
ASYNC_THROW_IF_INSUFFICIENT_PERMISSIONS macros called
ThrowAccessDenied/AsyncThrowAccessDenied unconditionally and only
guarded the `return` with `warning_only()`.
ERR_ACCESS_DENIED_IF_INSUFFICIENT_PERMISSIONS had no `warning_only()`
guard at all — it always set the access-denied error and returned.
As a result, running with `--permission-audit` still produced
ERR_ACCESS_DENIED on any denied operation (fs, net, child_process,
worker, addon, ffi, inspector, wasi), defeating the audit-only purpose
of the flag.
Guard the denied-error path behind `!warning_only()` in all three
macros. In audit mode, the diagnostics-channel message is published
(already done in Permission::is_scope_granted) and execution continues;
in enforce mode (`--permission`), behavior is unchanged — the error is
raised and the call returns.
The tests cover both the direct (top-level) call and an `eval()`-wrapped
call: the direct call exercises the normal script path, and the
`eval()`-wrapped call exercises the V8 script-context boundary (the
diagnostics subscriber is registered in the outer module context while
the denied operation runs inside an eval'd string).
Refs: 9ddd1a9
Signed-off-by: Adrian Estrada <edsadr@gmail.com>
PR-URL: #64426
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Expand the documentation for the --permission-audit flag, which was
fixed in 51c09ea to no longer throw ERR_ACCESS_DENIED on denied
operations. The previous docs only had a two-sentence description in
cli.md and no mention in the permissions guide or process.permission
API docs.
- permissions.md: add enforce vs audit mode overview, a new
"Audit Mode" subsection listing the diagnostics channel names
(node:permission-model:*) and the { permission, resource } message
shape, and a usage example. Update the Runtime API section to
mention both --permission and --permission-audit.
- cli.md: expand the --permission-audit section to clarify that
--permission is not required, --allow-* flags are not needed,
errors are not thrown, and --permission takes precedence when both
are set. Add a cross-reference from --permission to
--permission-audit.
- process.md: note that process.permission is available under both
flags, and clarify permission.has() and permission.drop() behavior
in audit mode.
- node.1: regenerated via `make node.1`.
Refs: #64426
Signed-off-by: Adrian Estrada <edsadr@gmail.com>
PR-URL: #64791
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Adds unique warning codes of the form PERM0000 for all permissions
related SecurityWarnings, so that they can be individually silenced
if required.
Fixes: #59818
Signed-off-by: David Evans <davidje13@users.noreply.github.com>
PR-URL: #64414
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
@aduh95aduh95 closed this Aug 20, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author readyPRs with CI started, the required approvals, and no outstanding review comments.c++Issues and PRs that require attention from people who are familiar with C++.lib / srcIssues and PRs involving general changes in the lib/ or src/ directories.needs-ciPRs that need a full CI run.semver-minorPRs that contain new features and should be released in the next minor version.v24.xIssues that can be reproduced on v24.x or PRs targeting the v24.x-staging branch.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@RafaelGSS@nodejs-github-bot@aduh95@mawalu@edsadr@davidje13
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

[v24.x] Backport permission updates to v24 - #65354

Closed
RafaelGSS wants to merge 8 commits into
nodejs:v24.x-stagingfrom
RafaelGSS:backport-permission-updates-to-v24
Closed

[v24.x] Backport permission updates to v24#65354
RafaelGSS wants to merge 8 commits into
nodejs:v24.x-stagingfrom
RafaelGSS:backport-permission-updates-to-v24

Conversation

@RafaelGSSRafaelGSS added the semver-minor PRs that contain new features and should be released in the next minor version. label Aug 17, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/config
  • @nodejs/security-wg

@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. lib / src Issues and PRs involving general changes in the lib/ or src/ directories. needs-ci PRs that need a full CI run. v24.x Issues that can be reproduced on v24.x or PRs targeting the v24.x-staging branch. labels Aug 17, 2026
@codecov

codecovBot commented Aug 17, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 77.73109% with 53 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.28%. Comparing base (9e39360) to head (499c38a).
⚠️ Report is 2 commits behind head on v24.x-staging.

Files with missing linesPatch %Lines
src/permission/fs_permission.cc71.62%17 Missing and 4 partials ⚠️
src/permission/permission.cc83.05%3 Missing and 17 partials ⚠️
lib/internal/process/permission.js58.33%5 Missing ⚠️
src/permission/inspector_permission.cc0.00%3 Missing ⚠️
src/permission/wasi_permission.cc0.00%3 Missing ⚠️
src/node_binding.cc0.00%0 Missing and 1 partial ⚠️
Additional details and impacted files
@@ Coverage Diff @@## v24.x-staging #65354 +/- ##
=================================================
- Coverage 90.31% 90.28% -0.03% 
=================================================
Files 711 711 Lines 228425 228644 +219 Branches 43160 43200 +40 =================================================
+ Hits 206293 206425 +132 - Misses 14090 14100 +10 - Partials 8042 8119 +77 
Files with missing linesCoverage Δ
lib/internal/process/pre_execution.js98.18% <100.00%> (+0.52%)⬆️
src/env.cc80.72% <100.00%> (-0.12%)⬇️
src/node_options.cc76.58% <100.00%> (+0.02%)⬆️
src/node_options.h97.42% <100.00%> (-0.51%)⬇️
src/permission/addon_permission.cc100.00% <100.00%> (ø)
src/permission/child_process_permission.cc100.00% <100.00%> (ø)
src/permission/fs_permission.h91.78% <ø> (ø)
src/permission/permission.h100.00% <100.00%> (+16.66%)⬆️
src/permission/worker_permission.cc100.00% <100.00%> (ø)
src/node_binding.cc82.42% <0.00%> (-0.33%)⬇️
... and 5 more

... and 43 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@RafaelGSS
RafaelGSSforce-pushed the backport-permission-updates-to-v24 branch from 3b93be2 to 01e422dCompareAugust 17, 2026 19:57
@aduh95aduh95 added author ready PRs with CI started, the required approvals, and no outstanding review comments. request-ci Add this label to start a Jenkins CI on a PR. labels Aug 17, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 17, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

RafaelGSSand others added 8 commits August 17, 2026 19:21
Add --permission-audit flag that enables the permission model in
warning-only mode. Instead of throwing ERR_ACCESS_DENIED, it emits
a message via diagnostics channel and allows the operation to
continue.
Publish permission check results to per-scope diagnostics channels
(e.g., node:permission-model:fs) so users can observe permission
decisions at runtime via diagnostics_channel.
Refs: nodejs#59935
Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com>
PR-URL: nodejs#62672
Refs: nodejs#62223
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Signed-off-by: Martin <martin@asymmetric.re>
PR-URL: nodejs#64007
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Edy Silva <edigleyssonsilva@gmail.com>
The THROW_IF_INSUFFICIENT_PERMISSIONS and
ASYNC_THROW_IF_INSUFFICIENT_PERMISSIONS macros called
ThrowAccessDenied/AsyncThrowAccessDenied unconditionally and only
guarded the `return` with `warning_only()`.
ERR_ACCESS_DENIED_IF_INSUFFICIENT_PERMISSIONS had no `warning_only()`
guard at all — it always set the access-denied error and returned.
As a result, running with `--permission-audit` still produced
ERR_ACCESS_DENIED on any denied operation (fs, net, child_process,
worker, addon, ffi, inspector, wasi), defeating the audit-only purpose
of the flag.
Guard the denied-error path behind `!warning_only()` in all three
macros. In audit mode, the diagnostics-channel message is published
(already done in Permission::is_scope_granted) and execution continues;
in enforce mode (`--permission`), behavior is unchanged — the error is
raised and the call returns.
The tests cover both the direct (top-level) call and an `eval()`-wrapped
call: the direct call exercises the normal script path, and the
`eval()`-wrapped call exercises the V8 script-context boundary (the
diagnostics subscriber is registered in the outer module context while
the denied operation runs inside an eval'd string).
Refs: nodejs@9ddd1a9
Signed-off-by: Adrian Estrada <edsadr@gmail.com>
PR-URL: nodejs#64426
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Expand the documentation for the --permission-audit flag, which was
fixed in 51c09ea to no longer throw ERR_ACCESS_DENIED on denied
operations. The previous docs only had a two-sentence description in
cli.md and no mention in the permissions guide or process.permission
API docs.
- permissions.md: add enforce vs audit mode overview, a new
"Audit Mode" subsection listing the diagnostics channel names
(node:permission-model:*) and the { permission, resource } message
shape, and a usage example. Update the Runtime API section to
mention both --permission and --permission-audit.
- cli.md: expand the --permission-audit section to clarify that
--permission is not required, --allow-* flags are not needed,
errors are not thrown, and --permission takes precedence when both
are set. Add a cross-reference from --permission to
--permission-audit.
- process.md: note that process.permission is available under both
flags, and clarify permission.has() and permission.drop() behavior
in audit mode.
- node.1: regenerated via `make node.1`.
Refs: nodejs#64426
Signed-off-by: Adrian Estrada <edsadr@gmail.com>
PR-URL: nodejs#64791
Reviewed-By: Aviv Keller <me@aviv.sh>
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com>
Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
Adds unique warning codes of the form PERM0000 for all permissions
related SecurityWarnings, so that they can be individually silenced
if required.
Fixes: nodejs#59818
Signed-off-by: David Evans <davidje13@users.noreply.github.com>
PR-URL: nodejs#64414
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Ulises Gascón <ulisesgascongonzalez@gmail.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
@RafaelGSS
RafaelGSSforce-pushed the backport-permission-updates-to-v24 branch from 01e422d to 499c38aCompareAugust 17, 2026 22:56
@aduh95aduh95 added the request-ci Add this label to start a Jenkins CI on a PR. label Aug 19, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 19, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@aduh95

Copy link
Copy Markdown
Contributor

Landed in 82a0233...980c651

aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Add --permission-audit flag that enables the permission model in
warning-only mode. Instead of throwing ERR_ACCESS_DENIED, it emits
a message via diagnostics channel and allows the operation to
continue.
Publish permission check results to per-scope diagnostics channels
(e.g., node:permission-model:fs) so users can observe permission
decisions at runtime via diagnostics_channel.
Refs: #59935
PR-URL: #61869
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com>
PR-URL: #62672
Backport-PR-URL: #65354
Refs: #62223
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Signed-off-by: Martin <martin@asymmetric.re>
PR-URL: #64007
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
The THROW_IF_INSUFFICIENT_PERMISSIONS and
ASYNC_THROW_IF_INSUFFICIENT_PERMISSIONS macros called
ThrowAccessDenied/AsyncThrowAccessDenied unconditionally and only
guarded the `return` with `warning_only()`.
ERR_ACCESS_DENIED_IF_INSUFFICIENT_PERMISSIONS had no `warning_only()`
guard at all — it always set the access-denied error and returned.
As a result, running with `--permission-audit` still produced
ERR_ACCESS_DENIED on any denied operation (fs, net, child_process,
worker, addon, ffi, inspector, wasi), defeating the audit-only purpose
of the flag.
Guard the denied-error path behind `!warning_only()` in all three
macros. In audit mode, the diagnostics-channel message is published
(already done in Permission::is_scope_granted) and execution continues;
in enforce mode (`--permission`), behavior is unchanged — the error is
raised and the call returns.
The tests cover both the direct (top-level) call and an `eval()`-wrapped
call: the direct call exercises the normal script path, and the
`eval()`-wrapped call exercises the V8 script-context boundary (the
diagnostics subscriber is registered in the outer module context while
the denied operation runs inside an eval'd string).
Refs: 9ddd1a9
Signed-off-by: Adrian Estrada <edsadr@gmail.com>
PR-URL: #64426
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Expand the documentation for the --permission-audit flag, which was
fixed in 51c09ea to no longer throw ERR_ACCESS_DENIED on denied
operations. The previous docs only had a two-sentence description in
cli.md and no mention in the permissions guide or process.permission
API docs.
- permissions.md: add enforce vs audit mode overview, a new
"Audit Mode" subsection listing the diagnostics channel names
(node:permission-model:*) and the { permission, resource } message
shape, and a usage example. Update the Runtime API section to
mention both --permission and --permission-audit.
- cli.md: expand the --permission-audit section to clarify that
--permission is not required, --allow-* flags are not needed,
errors are not thrown, and --permission takes precedence when both
are set. Add a cross-reference from --permission to
--permission-audit.
- process.md: note that process.permission is available under both
flags, and clarify permission.has() and permission.drop() behavior
in audit mode.
- node.1: regenerated via `make node.1`.
Refs: #64426
Signed-off-by: Adrian Estrada <edsadr@gmail.com>
PR-URL: #64791
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
aduh95 pushed a commit that referenced this pull request Aug 20, 2026
Adds unique warning codes of the form PERM0000 for all permissions
related SecurityWarnings, so that they can be individually silenced
if required.
Fixes: #59818
Signed-off-by: David Evans <davidje13@users.noreply.github.com>
PR-URL: #64414
Backport-PR-URL: #65354
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
@aduh95aduh95 closed this Aug 20, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author readyPRs with CI started, the required approvals, and no outstanding review comments.c++Issues and PRs that require attention from people who are familiar with C++.lib / srcIssues and PRs involving general changes in the lib/ or src/ directories.needs-ciPRs that need a full CI run.semver-minorPRs that contain new features and should be released in the next minor version.v24.xIssues that can be reproduced on v24.x or PRs targeting the v24.x-staging branch.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@RafaelGSS@nodejs-github-bot@aduh95@mawalu@edsadr@davidje13