Repository navigation
src: let embedders exempt linked bindings from the addon permission - #66067
Merged
nodejs-github-bot merged 1 commit intoSep 20, 2026
Merged
Conversation
process._linkedBinding() is subject to the permission model's addon scope since the check was added to GetLinkedBinding(). For an embedder that implements part of its runtime as linked bindings this means its own bootstrap cannot reach them under --permission unless the user also passes --allow-addons, which allows loading addons from the file system as well. Add EnvironmentFlags::kNoAddonPermissionForLinkedBindings. When set, GetLinkedBinding() skips the addon permission check for that Environment and the worker threads it creates; process.dlopen() stays gated and the default behavior is unchanged. Refs: nodejs#65432 Signed-off-by: Shelley Vohr <shelley.vohr@gmail.com>
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## main #66067 +/- ##
==========================================
- Coverage 90.27% 90.26% -0.01%
==========================================
Files 789 789
Lines 271473 271480 +7
Branches 51808 51815 +7
==========================================
- Hits 245066 245064 -2
- Misses 16880 16885 +5
- Partials 9527 9531 +4
🚀 New features to boost your workflow:
|
legendecas
approved these changes
Sep 16, 2026
meixg
approved these changes
Sep 17, 2026
Collaborator
Collaborator
jasnell
approved these changes
Sep 18, 2026
Collaborator
Collaborator
|
Landed in 25e6c15 |
aduh95
pushed a commit
that referenced
this pull request
Sep 27, 2026
process._linkedBinding() is subject to the permission model's addon scope since the check was added to GetLinkedBinding(). For an embedder that implements part of its runtime as linked bindings this means its own bootstrap cannot reach them under --permission unless the user also passes --allow-addons, which allows loading addons from the file system as well. Add EnvironmentFlags::kNoAddonPermissionForLinkedBindings. When set, GetLinkedBinding() skips the addon permission check for that Environment and the worker threads it creates; process.dlopen() stays gated and the default behavior is unchanged. Refs: #65432 Signed-off-by: Shelley Vohr <shelley.vohr@gmail.com> PR-URL: #66067 Reviewed-By: Chengzhong Wu <legendecas@gmail.com> Reviewed-By: Xuguang Mei <meixuguang@gmail.com> Reviewed-By: James M Snell <jasnell@gmail.com>
nodejs-github-bot
added a commit
that referenced
this pull request
Oct 5, 2026
Notable changes: benchmark: * (SEMVER-MINOR) add http header validator benchmark (James M Snell) #66334 buffer: * (SEMVER-MINOR) add isLatin1 (James M Snell) #66298 * (SEMVER-MINOR) add isLatin1 (James M Snell) #66298 * (SEMVER-MINOR) add Buffer.stringLength() (Matteo Collina) #66064 build, doc: * move to redesign (Aviv Keller) #62045 http: * (SEMVER-MINOR) add isValidHeaderName() and isValidHeaderValue() (James M Snell) #66334 http2: * (SEMVER-MINOR) add new connectionWindowSize option (Tim Perry) #65619 lib: * (SEMVER-MINOR) fix stream loading bug in node:bench (James M Snell) #66114 perf_hooks: * (SEMVER-MINOR) fix truncation of monitorEventLoopDelay() resolution (James M Snell) #66115 * (SEMVER-MINOR) allow RecordableHistogram to record 0 (James M Snell) #66114 * (SEMVER-MINOR) add histogram.diff() (James M Snell) #66099 * (SEMVER-MINOR) report histogram memory to V8 (James M Snell) #66099 * (SEMVER-MINOR) add histogram.snapshot() (James M Snell) #66099 * (SEMVER-MINOR) add histogram export format version 2 (James M Snell) #66098 * (SEMVER-MINOR) harden histogram CBOR import validation (James M Snell) #66098 process: * (SEMVER-MINOR) graduate process.ref/unref from experimental (James M Snell) #66213 sqlite: * (SEMVER-MINOR) rename DatabaseSync and StatementSync (Guilherme Araújo) #65988 src: * (SEMVER-MINOR) add --process-timeout=N (James M Snell) #66138 * (SEMVER-MINOR) expose size and count in heap profile output (Ilyas Shabi) #65737 * (SEMVER-MINOR) let embedders exempt linked bindings from the addon permission (Shelley Vohr) #66067 test: * deflake sliding window histogram test (James M Snell) #66132 PR-URL: #66546
aduh95
pushed a commit
that referenced
this pull request
Oct 6, 2026
Notable changes: buffer: * (SEMVER-MINOR) add isLatin1 (James M Snell) #66298 * (SEMVER-MINOR) add Buffer.stringLength() (Matteo Collina) #66064 build, doc: * move to redesign (Aviv Keller) #62045 http: * (SEMVER-MINOR) add isValidHeaderName() and isValidHeaderValue() (James M Snell) #66334 http2: * (SEMVER-MINOR) add new connectionWindowSize option (Tim Perry) #65619 perf_hooks: * (SEMVER-MINOR) fix truncation of monitorEventLoopDelay() resolution (James M Snell) #66115 * (SEMVER-MINOR) allow RecordableHistogram to record 0 (James M Snell) #66114 * (SEMVER-MINOR) add histogram.diff() (James M Snell) #66099 * (SEMVER-MINOR) report histogram memory to V8 (James M Snell) #66099 * (SEMVER-MINOR) add histogram.snapshot() (James M Snell) #66099 * (SEMVER-MINOR) add histogram export format version 2 (James M Snell) #66098 * (SEMVER-MINOR) harden histogram CBOR import validation (James M Snell) #66098 process: * (SEMVER-MINOR) graduate process.ref/unref from experimental (James M Snell) #66213 sqlite: * (SEMVER-MINOR) rename DatabaseSync and StatementSync (Guilherme Araújo) #65988 src: * (SEMVER-MINOR) add --process-timeout=N (James M Snell) #66138 * (SEMVER-MINOR) expose size and count in heap profile output (Ilyas Shabi) #65737 * (SEMVER-MINOR) let embedders exempt linked bindings from the addon permission (Shelley Vohr) #66067 PR-URL: #66546
aduh95
pushed a commit
that referenced
this pull request
Oct 6, 2026
Notable changes: buffer: * (SEMVER-MINOR) add isLatin1 (James M Snell) #66298 * (SEMVER-MINOR) add Buffer.stringLength() (Matteo Collina) #66064 build, doc: * move to redesign (Aviv Keller) #62045 doc: * promote Alpine Linux to tier 2 support (Stewart X Addison) #63737 http: * (SEMVER-MINOR) add isValidHeaderName() and isValidHeaderValue() (James M Snell) #66334 http2: * (SEMVER-MINOR) add new connectionWindowSize option (Tim Perry) #65619 perf_hooks: * (SEMVER-MINOR) fix truncation of monitorEventLoopDelay() resolution (James M Snell) #66115 * (SEMVER-MINOR) allow RecordableHistogram to record 0 (James M Snell) #66114 * (SEMVER-MINOR) add histogram.diff() (James M Snell) #66099 * (SEMVER-MINOR) add histogram.snapshot() (James M Snell) #66099 * (SEMVER-MINOR) harden histogram CBOR import validation (James M Snell) #66098 process: * (SEMVER-MINOR) graduate process.ref/unref from experimental (James M Snell) #66213 sqlite: * (SEMVER-MINOR) rename DatabaseSync and StatementSync (Guilherme Araújo) #65988 src: * (SEMVER-MINOR) add --process-timeout=N (James M Snell) #66138 * (SEMVER-MINOR) expose size and count in heap profile output (Ilyas Shabi) #65737 * (SEMVER-MINOR) let embedders exempt linked bindings from the addon permission (Shelley Vohr) #66067 PR-URL: #66546
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Refs: #65432
Since #65432
process._linkedBinding()is subject to the permission model's addon scope, the same asprocess.dlopen(). A stocknodebinary has no linked bindings, so this only affects embedders, and for an embedder that implements part of its runtime as linked bindings (NODE_LINKED_MODULE/node::AddLinkedBinding()) it means its own bootstrap cannot reach them under--permissionunless the user also passes--allow-addons- which then allows loading addons from the file system as well.This adds
EnvironmentFlags::kNoAddonPermissionForLinkedBindings. When an embedder sets it,GetLinkedBinding()skips the addon permission check for that Environment and the worker threads it creates;process.dlopen()stays gated by--allow-addonsand the default behavior is unchanged. The reasoning is that--allow-addonsguards loading native code from disk at runtime, while linked bindings are compiled into the executable by the embedder and trusted the same way the built-in bindings are.Disclosure: the code, tests and this description were written by Claude Code, directed and reviewed by @codebytere.