Skip to content

Commit b83b2af

Browse files
committed
ffi: remove permission checks from dlclose and dlsym
The docs describe `ffi.dlclose(handle)` and `ffi.dlsym(handle, symbol)` as equivalent to `handle.close()` and `handle.getSymbol(symbol)`, but only the functions called `checkFFIPermission()`. After `process.permission.drop('ffi')`, `ffi.dlclose(lib)` threw `ERR_ACCESS_DENIED` while `lib.close()` succeeded. Remove the checks so the functions defer to the handle. Permission is already checked when the `DynamicLibrary` is constructed, and dropping a permission does not revoke resources that are already open. Signed-off-by: Trivikram Kamat <16024985+trivikr@users.noreply.github.com> Assisted-by: claude:opus-5.5
1 parent 5e3bbc4 commit b83b2af

2 files changed

Lines changed: 3 additions & 5 deletions

File tree

‎lib/ffi.js‎

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -252,12 +252,10 @@ function dlopen(path, definitions) {
252252
}
253253

254254
function dlclose(handle) {
255-
checkFFIPermission();
256255
handle.close();
257256
}
258257

259258
function dlsym(handle, symbol) {
260-
checkFFIPermission();
261259
return handle.getSymbol(symbol);
262260
}
263261

‎test/ffi/test-ffi-permissions.js‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -74,7 +74,7 @@ test('permission model blocks ffi memory and helper APIs', () => {
7474
ffi.getCurrentEventLoop();
7575
}, denied);
7676

77-
assert.throws(() => {
78-
ffi.dlclose({ close() {} });
79-
}, denied);
77+
// Like handle.close() and handle.getSymbol(), these do not check permissions.
78+
ffi.dlclose({ close() {} });
79+
assert.strictEqual(ffi.dlsym({ getSymbol: () => 1n }, 'x'), 1n);
8080
});

0 commit comments

Comments
 (0)