Commit 2bcc5dd2eec for nodejs
commit 2bcc5dd2eec2ed895212a81679242eef14be3e4a
Author: Trivikram Kamat <trivikr.dev@gmail.com>
Date: Fri Oct 2 22:29:33 2026 -0700
ffi: remove permission checks from dlclose and dlsym
The docs describe `ffi.dlclose(handle)` and `ffi.dlsym(handle, symbol)`
as equivalent to `handle.close()` and `handle.getSymbol(symbol)`, but
only the functions called `checkFFIPermission()`. After
`process.permission.drop('ffi')`, `ffi.dlclose(lib)` threw
`ERR_ACCESS_DENIED` while `lib.close()` succeeded.
Remove the checks so the functions defer to the handle. Permission is
already checked when the `DynamicLibrary` is constructed, and dropping
a permission does not revoke resources that are already open.
Signed-off-by: Trivikram Kamat <16024985+trivikr@users.noreply.github.com>
Assisted-by: claude:opus-5.5
PR-URL: https://github.com/nodejs/node/pull/66426
Fixes: https://github.com/nodejs/node/issues/66425
Reviewed-By: Paolo Insogna <paolo@cowtech.it>
Reviewed-By: Anna Henningsen <anna@addaleax.net>
diff --git a/lib/ffi.js b/lib/ffi.js
index 5cd7c4b354a..2a9db50fa51 100644
--- a/lib/ffi.js
+++ b/lib/ffi.js
@@ -252,12 +252,10 @@ function dlopen(path, definitions) {
}
function dlclose(handle) {
- checkFFIPermission();
handle.close();
}
function dlsym(handle, symbol) {
- checkFFIPermission();
return handle.getSymbol(symbol);
}
diff --git a/test/ffi/test-ffi-permissions.js b/test/ffi/test-ffi-permissions.js
index e441d88efac..ff4a4ef3a67 100644
--- a/test/ffi/test-ffi-permissions.js
+++ b/test/ffi/test-ffi-permissions.js
@@ -74,7 +74,7 @@ test('permission model blocks ffi memory and helper APIs', () => {
ffi.getCurrentEventLoop();
}, denied);
- assert.throws(() => {
- ffi.dlclose({ close() {} });
- }, denied);
+ // Like handle.close() and handle.getSymbol(), these do not check permissions.
+ ffi.dlclose({ close() {} });
+ assert.strictEqual(ffi.dlsym({ getSymbol: () => 1n }, 'x'), 1n);
});