Skip to content

Commit 6409145

Browse files
committed
permission: clamp Worker grants to parent for explicit execArgv
SEMVER-MAJOR: when the parent has the Permission Model enabled, a Worker with explicit execArgv (including []) cannot obtain wider permission-related grants than the parent. Clamp EnvironmentOptions, then rebuild exec_argv_out so CreateEnvironment enables Permission with the clamped allow lists (fixes empty execArgv). Documented in permissions and worker_threads APIs. Signed-off-by: yunshingng <yunshingng25@gmail.com>
1 parent 76bb3f7 commit 6409145

444 files changed

Lines changed: 4834 additions & 25541 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.github/workflows/auto-start-ci.yml‎

Lines changed: 5 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,3 @@
1-
# This action uses the following secrets:
2-
# JENKINS_USER: GitHub user whose Jenkins token is defined below
3-
# JENKINS_TOKEN: Jenkins token, to be used to start CI
41
name: Auto Start CI
52

63
on:
@@ -39,13 +36,11 @@ jobs:
3936
-t '{{ range . }}{{ .number }} {{ end }}' \
4037
--limit 5)" >> "$GITHUB_OUTPUT"
4138
env:
42-
GH_TOKEN: ${{ github.token }}
39+
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
4340
start-ci:
4441
permissions:
45-
checks: read
4642
contents: read
4743
pull-requests: write
48-
statuses: read
4944
needs: get-prs-for-ci
5045
if: needs.get-prs-for-ci.outputs.numbers != ''
5146
runs-on: ubuntu-slim
@@ -64,15 +59,16 @@ jobs:
6459
ncu-config set token "$GH_TOKEN"
6560
ncu-config set jenkins_token "$JENKINS_TOKEN"
6661
ncu-config set owner "$GITHUB_REPOSITORY_OWNER"
67-
ncu-config set repo "${GITHUB_REPOSITORY#*/}"
62+
ncu-config set repo "$(echo "$GITHUB_REPOSITORY" | cut -d/ -f2)"
6863
env:
6964
USERNAME: ${{ secrets.JENKINS_USER }}
70-
GH_TOKEN: ${{ github.token }}
65+
GH_TOKEN: ${{ secrets.GH_USER_TOKEN }}
7166
JENKINS_TOKEN: ${{ secrets.JENKINS_TOKEN }}
7267

7368
- name: Start the CI
7469
run: |
7570
curl -fsSL "https://github.com/${GITHUB_REPOSITORY}/raw/${GITHUB_SHA}/tools/actions/start-ci.sh" \
7671
| sh -s -- ${{ needs.get-prs-for-ci.outputs.numbers }}
7772
env:
78-
GH_TOKEN: ${{ github.token }}
73+
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
74+
GH_REPO: ${{ github.repository }}

‎.github/workflows/benchmark.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -141,7 +141,7 @@ jobs:
141141
--arg devTools '[]' \
142142
--arg benchmarkTools '[]' \
143143
--run '
144-
make build-ci -j4 V=1
144+
make -j4 V=1
145145
'
146146
147147
- name: Run benchmark

‎.github/workflows/build-tarball.yml‎

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,6 @@ on:
2323
- tools/eslint-rules/**
2424
- tools/eslint/**
2525
- tools/lint-md/**
26-
- tools/nix/**
2726
- typings/**
2827
- vcbuild.bat
2928
- .**
@@ -53,7 +52,6 @@ on:
5352
- tools/eslint-rules/**
5453
- tools/eslint/**
5554
- tools/lint-md/**
56-
- tools/nix/**
5755
- typings/**
5856
- vcbuild.bat
5957
- .**

‎.github/workflows/commit-queue.yml‎

Lines changed: 10 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -52,7 +52,7 @@ jobs:
5252
jq -r -s 'reduce .[] as $pr ([]; if index($pr) then . else . + [$pr] end) | join(" ")')
5353
echo "candidates=$candidates" >> "$GITHUB_OUTPUT"
5454
env:
55-
GH_TOKEN: ${{ github.token }}
55+
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
5656
commitQueue:
5757
needs: get_candidate_prs
5858
if: needs.get_candidate_prs.outputs.candidates != ''
@@ -63,14 +63,18 @@ jobs:
6363
statuses: read
6464
runs-on: ubuntu-slim
6565
steps:
66+
# Install dependencies
6667
- name: Install Node.js
6768
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
6869
with:
6970
node-version: ${{ env.NODE_VERSION }}
70-
7171
- name: Install @node-core/utils
7272
run: npm install -g @node-core/utils
7373

74+
- name: Set variables
75+
run: |
76+
echo "REPOSITORY=$(echo "$GITHUB_REPOSITORY" | cut -d/ -f2)" >> "$GITHUB_ENV"
77+
7478
- name: Configure @node-core/utils
7579
run: |
7680
# Keep the config outside the workspace so checkout does not remove it.
@@ -79,7 +83,7 @@ jobs:
7983
ncu-config --global set username "$USERNAME"
8084
ncu-config --global set token "$GH_TOKEN"
8185
ncu-config --global set jenkins_token "$JENKINS_TOKEN"
82-
ncu-config --global set repo "${GITHUB_REPOSITORY#*/}"
86+
ncu-config --global set repo "${REPOSITORY}"
8387
ncu-config --global set owner "${GITHUB_REPOSITORY_OWNER}"
8488
env:
8589
USERNAME: ${{ secrets.JENKINS_USER }}
@@ -98,6 +102,8 @@ jobs:
98102
metadata="${RUNNER_TEMP}/metadata-${pr}.json"
99103
output="${RUNNER_TEMP}/metadata-${pr}.txt"
100104
if git node metadata "$pr" \
105+
--owner "$GITHUB_REPOSITORY_OWNER" \
106+
--repo "$REPOSITORY" \
101107
--readme "$readme" \
102108
--json > "$metadata" 2> "$output"; then
103109
metadata_status=0
@@ -165,9 +171,7 @@ jobs:
165171
- name: Start the Commit Queue
166172
if: steps.get_mergeable_prs.outputs.numbers != ''
167173
run: |
168-
git config --local user.email "github-bot@iojs.org"
169-
git config --local user.name "Node.js GitHub Bot"
170174
ncu-config set token "$GH_TOKEN"
171-
./tools/actions/commit-queue.sh ${{ steps.get_mergeable_prs.outputs.numbers }}
175+
./tools/actions/commit-queue.sh "${GITHUB_REPOSITORY_OWNER}" "${REPOSITORY}" ${{ steps.get_mergeable_prs.outputs.numbers }}
172176
env:
173177
GH_TOKEN: ${{ secrets.GH_USER_TOKEN }}

‎.github/workflows/coverage-windows.yml‎

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,6 @@ on:
2323
- tools/eslint-rules/**
2424
- tools/eslint/**
2525
- tools/lint-md/**
26-
- tools/nix/**
2726
- typings/**
2827
- .**
2928
- '!.github/workflows/coverage-windows.yml'
@@ -50,7 +49,6 @@ on:
5049
- tools/eslint-rules/**
5150
- tools/eslint/**
5251
- tools/lint-md/**
53-
- tools/nix/**
5452
- typings/**
5553
- .**
5654
- '!.github/workflows/coverage-windows.yml'

‎.github/workflows/nix-changes.yml‎

Lines changed: 30 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -11,12 +11,10 @@ on:
1111
- v[0-9]+.x
1212
paths:
1313
- '**.nix'
14-
- tools/nix/**
1514
- .github/workflows/nix-changes.yml
1615
pull_request:
1716
paths:
1817
- '**.nix'
19-
- tools/nix/**
2018
- .github/workflows/nix-changes.yml
2119
types: [opened, synchronize, reopened, ready_for_review]
2220

@@ -49,9 +47,7 @@ jobs:
4947
with:
5048
fetch-depth: 2
5149
persist-credentials: false
52-
sparse-checkout: |
53-
shell.nix
54-
tools/nix/
50+
sparse-checkout: '*.nix'
5551
sparse-checkout-cone-mode: false
5652

5753
- uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0
@@ -64,14 +60,39 @@ jobs:
6460
name: nodejs
6561

6662
- name: Compute requisites after change
67-
run: ./tools/nix/list-requisites.sh > requisites-${{ matrix.system }}-after.list
63+
shell: bash # See https://docs.github.com/en/actions/writing-workflows/workflow-syntax-for-github-actions#exit-codes-and-error-action-preference, we want the pipefail option.
64+
run: |
65+
nix-store --query --references "$(
66+
nix-instantiate -I "nixpkgs=./tools/nix/pkgs.nix" shell.nix \
67+
--arg devTools "
68+
(import ./tools/nix/devTools.nix {})
69+
++ builtins.attrValues (
70+
{ inherit (import <nixpkgs> {}) nixfmt-tree sccache; }
71+
// import ./tools/nix/openssl-matrix.nix {}
72+
// import ./tools/nix/pkcs11.nix {}
73+
)")" \
74+
| xargs nix-store --realise \
75+
| xargs nix-store --query --requisites \
76+
| sort -k1.45 \
77+
> requisites-${{ matrix.system }}-after.list
6878
6979
- name: Compute requisites before change
80+
shell: bash # See https://docs.github.com/en/actions/writing-workflows/workflow-syntax-for-github-actions#exit-codes-and-error-action-preference, we want the pipefail option.
7081
run: |
7182
git reset HEAD^ --hard
72-
# TODO(aduh95): remove this once list-requisites.sh has reached `main`
73-
[ -f tools/nix/list-requisites.sh ] || git checkout FETCH_HEAD -- tools/nix/list-requisites.sh
74-
./tools/nix/list-requisites.sh > requisites-${{ matrix.system }}-before.list
83+
nix-store --query --references "$(
84+
nix-instantiate -I "nixpkgs=./tools/nix/pkgs.nix" shell.nix \
85+
--arg devTools "
86+
(import ./tools/nix/devTools.nix {})
87+
++ builtins.attrValues (
88+
{ inherit (import <nixpkgs> {}) nixfmt-tree sccache; }
89+
// import ./tools/nix/openssl-matrix.nix {}
90+
// import ./tools/nix/pkcs11.nix {}
91+
)")" \
92+
| xargs nix-store --realise \
93+
| xargs nix-store --query --requisites \
94+
| sort -k1.45 \
95+
> requisites-${{ matrix.system }}-before.list
7596
7697
- name: Output diff
7798
run: |

‎.github/workflows/test-linux.yml‎

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,6 @@ on:
99
- tools/actions/**
1010
- tools/clang-format/**
1111
- tools/dep_updaters/**
12-
- tools/nix/**
1312
- test/internet/**
1413
- '**.nix'
1514
- .github/**
@@ -28,7 +27,6 @@ on:
2827
- tools/actions/**
2928
- tools/clang-format/**
3029
- tools/dep_updaters/**
31-
- tools/nix/**
3230
- test/internet/**
3331
- '**.nix'
3432
- .github/**

‎.github/workflows/test-macos.yml‎

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,6 @@ on:
2323
- tools/eslint-rules/**
2424
- tools/eslint/**
2525
- tools/lint-md/**
26-
- tools/nix/**
2726
- typings/**
2827
- vcbuild.bat
2928
- .**
@@ -54,7 +53,6 @@ on:
5453
- tools/eslint-rules/**
5554
- tools/eslint/**
5655
- tools/lint-md/**
57-
- tools/nix/**
5856
- typings/**
5957
- vcbuild.bat
6058
- .**

‎.github/workflows/test-shared.yml‎

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -44,7 +44,6 @@ on:
4444
- '!tools/nix/**'
4545
- '!tools/v8/**'
4646
- '!tools/v8_gypfiles/**'
47-
- tools/nix/list-requisites.sh
4847
- typings/**
4948
- vcbuild.bat
5049
- .**
@@ -97,7 +96,6 @@ on:
9796
- '!tools/nix/**'
9897
- '!tools/v8/**'
9998
- '!tools/v8_gypfiles/**'
100-
- tools/nix/list-requisites.sh
10199
- typings/**
102100
- vcbuild.bat
103101
- .**

‎.gitignore‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -163,6 +163,7 @@ install_manifest.txt
163163

164164
# === Rules for AI assistants ===
165165
CLAUDE.md
166+
AGENTS.md
166167

167168
# === Global Rules ===
168169
# Keep last to avoid being excluded

0 commit comments

Comments
 (0)