Commit 2bcc5dd2eec for nodejs

commit 2bcc5dd2eec2ed895212a81679242eef14be3e4a
Author: Trivikram Kamat <trivikr.dev@gmail.com>
Date:   Fri Oct 2 22:29:33 2026 -0700

    ffi: remove permission checks from dlclose and dlsym

    The docs describe `ffi.dlclose(handle)` and `ffi.dlsym(handle, symbol)`
    as equivalent to `handle.close()` and `handle.getSymbol(symbol)`, but
    only the functions called `checkFFIPermission()`. After
    `process.permission.drop('ffi')`, `ffi.dlclose(lib)` threw
    `ERR_ACCESS_DENIED` while `lib.close()` succeeded.

    Remove the checks so the functions defer to the handle. Permission is
    already checked when the `DynamicLibrary` is constructed, and dropping
    a permission does not revoke resources that are already open.

    Signed-off-by: Trivikram Kamat <16024985+trivikr@users.noreply.github.com>
    Assisted-by: claude:opus-5.5
    PR-URL: https://github.com/nodejs/node/pull/66426
    Fixes: https://github.com/nodejs/node/issues/66425
    Reviewed-By: Paolo Insogna <paolo@cowtech.it>
    Reviewed-By: Anna Henningsen <anna@addaleax.net>

diff --git a/lib/ffi.js b/lib/ffi.js
index 5cd7c4b354a..2a9db50fa51 100644
--- a/lib/ffi.js
+++ b/lib/ffi.js
@@ -252,12 +252,10 @@ function dlopen(path, definitions) {
 }

 function dlclose(handle) {
-  checkFFIPermission();
   handle.close();
 }

 function dlsym(handle, symbol) {
-  checkFFIPermission();
   return handle.getSymbol(symbol);
 }

diff --git a/test/ffi/test-ffi-permissions.js b/test/ffi/test-ffi-permissions.js
index e441d88efac..ff4a4ef3a67 100644
--- a/test/ffi/test-ffi-permissions.js
+++ b/test/ffi/test-ffi-permissions.js
@@ -74,7 +74,7 @@ test('permission model blocks ffi memory and helper APIs', () => {
     ffi.getCurrentEventLoop();
   }, denied);

-  assert.throws(() => {
-    ffi.dlclose({ close() {} });
-  }, denied);
+  // Like handle.close() and handle.getSymbol(), these do not check permissions.
+  ffi.dlclose({ close() {} });
+  assert.strictEqual(ffi.dlsym({ getSymbol: () => 1n }, 'x'), 1n);
 });