From 77f73312f05f5084a7f0a9240cc39ea7a618742c Mon Sep 17 00:00:00 2001 From: RafaelGSS Date: Tue, 6 Oct 2026 06:33:09 -0300 Subject: [PATCH] lib: add --allow-fs-vfs to permission available flags Without it, --allow-fs-vfs was accepted without --permission and was not propagated to child processes like the other --allow-* flags. Signed-off-by: RafaelGSS --- lib/internal/process/permission.js | 1 + .../test-permission-allow-fs-vfs-flags.js | 42 +++++++++++++++++++ 2 files changed, 43 insertions(+) create mode 100644 test/parallel/test-permission-allow-fs-vfs-flags.js diff --git a/lib/internal/process/permission.js b/lib/internal/process/permission.js index d2921694b99a..92e54fbab493 100644 --- a/lib/internal/process/permission.js +++ b/lib/internal/process/permission.js @@ -74,6 +74,7 @@ module.exports = ObjectFreeze({ const flags = [ '--allow-fs-read', '--allow-fs-write', + '--allow-fs-vfs', '--allow-addons', '--allow-child-process', '--allow-env', diff --git a/test/parallel/test-permission-allow-fs-vfs-flags.js b/test/parallel/test-permission-allow-fs-vfs-flags.js new file mode 100644 index 000000000000..68fcac76bd73 --- /dev/null +++ b/test/parallel/test-permission-allow-fs-vfs-flags.js @@ -0,0 +1,42 @@ +'use strict'; + +const common = require('../common'); +const { isMainThread } = require('worker_threads'); + +if (!isMainThread) { + common.skip('This test only works on a main thread'); +} + +const { spawnSyncAndAssert, spawnSyncAndExit } = require('../common/child_process'); + +// --allow-fs-vfs requires the permission model. +spawnSyncAndExit( + process.execPath, + ['--allow-fs-vfs', '-e', ''], + { + status: 1, + signal: null, + stderr: /--permission is required/, + }, +); + +if (process.config.variables.node_without_node_options) { + common.skip('missing NODE_OPTIONS support'); +} + +// A child process inherits --allow-fs-vfs along with --permission. +const child = ` + const { spawnSync } = require('child_process'); + const { stdout } = spawnSync(process.execPath, [ + '-p', 'process.env.NODE_OPTIONS', + ], { encoding: 'utf8' }); + process.stdout.write(stdout); +`; + +spawnSyncAndAssert( + process.execPath, + ['--permission', '--allow-fs-vfs', '--allow-child-process', '-e', child], + { + stdout: /(^|\s)--allow-fs-vfs(\s|$)/, + }, +);