Skip to content

Commit 7d4532e

Browse files
committed
permission: SEMVER-MAJOR ceiling for Worker explicit execArgv
Breaking change: when the parent has the Permission Model enabled, a Worker with explicit execArgv (including []) cannot obtain wider permission-related grants than the parent. - Unconfigured worker permission flags → parent grant ceiling - Configured flags → intersect booleans; fs lists subset of parent (empty worker fs list keeps parent list; prefix-aware path coverage) - Options only; runtime FSPermission unchanged - Document behavior in permissions and worker_threads APIs Signed-off-by: yunshingng <yunshingng25@gmail.com>
1 parent f89a4b9 commit 7d4532e

4 files changed

Lines changed: 243 additions & 249 deletions

File tree

‎doc/api/permissions.md‎

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -28,6 +28,15 @@ If you find a potential security vulnerability, please refer to our
2828

2929
### Permission Model
3030

31+
<!-- worker-execargv-permission-ceiling -->
32+
When the Permission Model is enabled in the parent process, creating a
33+
`worker_threads.Worker` with an explicit `execArgv` option (including an empty
34+
array) no longer allows the worker to obtain a wider permission-related grant
35+
set than the parent. Permission-related grants on the worker are limited to a
36+
subset of the parent's grants. Non-permission `execArgv` flags are unaffected.
37+
This is a breaking change relative to earlier releases where `execArgv: []`
38+
could drop the parent's Permission Model grants.
39+
3140
<!-- YAML
3241
added: v20.0.0
3342
changes:

‎doc/api/worker_threads.md‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1561,6 +1561,12 @@ if (isMainThread) {
15611561
15621562
### `new Worker(filename[, options])`
15631563
1564+
<!-- worker-execargv-permission-ceiling -->
1565+
**Permission Model (breaking):** If the parent process runs with the
1566+
Permission Model enabled, an explicit `execArgv` (including `[]`) does not
1567+
disable or exceed the parent's permission-related grants. See the Permission
1568+
Model documentation.
1569+
15641570
<!-- YAML
15651571
added: v10.5.0
15661572
changes:

0 commit comments

Comments
 (0)