From 77600e4a6d5aabd88da24739b643a3318553881b Mon Sep 17 00:00:00 2001 From: RafaelGSS Date: Fri, 9 Oct 2026 08:25:24 -0300 Subject: [PATCH 1/2] src,permission: do not grant cwd read access without entrypoint Signed-off-by: RafaelGSS --- src/env.cc | 3 ++- .../test-permission-fs-read-entrypoint.js | 17 +++++++++++++++++ 2 files changed, 19 insertions(+), 1 deletion(-) diff --git a/src/env.cc b/src/env.cc index 2da45b82f1a2..045a61bb4d7d 100644 --- a/src/env.cc +++ b/src/env.cc @@ -1169,7 +1169,8 @@ Environment::Environment(IsolateData* isolate_data, } } - if (first_argv != "inspect") { + if (!first_argv.empty() && first_argv != "-" && + first_argv != "inspect") { options_->allow_fs_read.push_back(first_argv); } } diff --git a/test/parallel/test-permission-fs-read-entrypoint.js b/test/parallel/test-permission-fs-read-entrypoint.js index 631c793e1357..f0182dce6454 100644 --- a/test/parallel/test-permission-fs-read-entrypoint.js +++ b/test/parallel/test-permission-fs-read-entrypoint.js @@ -14,6 +14,7 @@ if (!common.hasCrypto) { const assert = require('assert'); const fixtures = require('../common/fixtures'); +const tmpdir = require('../common/tmpdir'); const { spawnSync } = require('child_process'); const file = fixtures.path('permission', 'hello-world.js'); @@ -36,3 +37,19 @@ const fsReadLoader = fixtures.path('permission', 'fs-read-loader.js'); ); assert.strictEqual(status, 0, `${arg0} Error: ${stderr.toString()}`); }); + +// When the code is read from stdin there is no entrypoint, so no implicit +// read access should be granted (in particular, not to the cwd). +tmpdir.refresh(); +[ + ['--permission'], + ['--permission', '-'], +].forEach((args) => { + const { status, stdout, stderr } = spawnSync(process.execPath, args, { + cwd: tmpdir.path, + input: 'console.log(process.permission.has("fs.read", ' + + 'require("path").join(process.cwd(), "x")))', + }); + assert.strictEqual(status, 0, `${args} Error: ${stderr.toString()}`); + assert.strictEqual(stdout.toString().trim(), 'false'); +}); From f18fd0aeb7eeb7aae55c46d4a8d2882c07eb3eaa Mon Sep 17 00:00:00 2001 From: RafaelGSS Date: Sat, 10 Oct 2026 18:23:11 -0300 Subject: [PATCH 2/2] src: format permission entrypoint check Signed-off-by: RafaelGSS --- src/env.cc | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/src/env.cc b/src/env.cc index 045a61bb4d7d..12a78a8dc3ac 100644 --- a/src/env.cc +++ b/src/env.cc @@ -1169,8 +1169,7 @@ Environment::Environment(IsolateData* isolate_data, } } - if (!first_argv.empty() && first_argv != "-" && - first_argv != "inspect") { + if (!first_argv.empty() && first_argv != "-" && first_argv != "inspect") { options_->allow_fs_read.push_back(first_argv); } }