Skip to content

Commit f89a4b9

Browse files
committed
permission: match permission CLI flags by exact name or =value
Avoid treating longer distinct options that share a prefix (e.g. --allow-fs-read-extra) as permission args when stripping/rewriting exec_argv. Signed-off-by: yunshingng <yunshingng25@gmail.com>
1 parent 445a62c commit f89a4b9

1 file changed

Lines changed: 28 additions & 12 deletions

File tree

‎src/node_worker.cc‎

Lines changed: 28 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -537,21 +537,36 @@ static bool WorkerConfiguredPermission(const EnvironmentOptions* w) {
537537
return false;
538538
}
539539

540+
// True only for exact flag names or "flag=value". Does not match a longer
541+
// distinct option that merely shares a prefix (e.g. --allow-fs-read-extra).
542+
static bool IsExactPermissionFlag(const std::string& arg, const char* name) {
543+
const size_t n = std::char_traits<char>::length(name);
544+
if (arg.size() < n) {
545+
return false;
546+
}
547+
if (arg.compare(0, n, name) != 0) {
548+
return false;
549+
}
550+
return arg.size() == n || arg[n] == '=';
551+
}
552+
540553
static bool IsPermissionArg(const std::string& arg) {
541-
return arg == "--permission" || arg == "--permission-audit" ||
542-
arg.rfind("--allow-fs-read", 0) == 0 ||
543-
arg.rfind("--allow-fs-write", 0) == 0 ||
544-
arg.rfind("--allow-addons", 0) == 0 ||
545-
arg.rfind("--allow-inspector", 0) == 0 ||
546-
arg.rfind("--allow-child-process", 0) == 0 ||
547-
arg.rfind("--allow-net", 0) == 0 ||
548-
arg.rfind("--allow-wasi", 0) == 0 ||
549-
arg.rfind("--allow-ffi", 0) == 0 ||
550-
arg.rfind("--allow-openssl-store", 0) == 0 ||
551-
arg.rfind("--allow-worker", 0) == 0;
554+
return IsExactPermissionFlag(arg, "--permission") ||
555+
IsExactPermissionFlag(arg, "--permission-audit") ||
556+
IsExactPermissionFlag(arg, "--allow-fs-read") ||
557+
IsExactPermissionFlag(arg, "--allow-fs-write") ||
558+
IsExactPermissionFlag(arg, "--allow-addons") ||
559+
IsExactPermissionFlag(arg, "--allow-inspector") ||
560+
IsExactPermissionFlag(arg, "--allow-child-process") ||
561+
IsExactPermissionFlag(arg, "--allow-net") ||
562+
IsExactPermissionFlag(arg, "--allow-wasi") ||
563+
IsExactPermissionFlag(arg, "--allow-ffi") ||
564+
IsExactPermissionFlag(arg, "--allow-openssl-store") ||
565+
IsExactPermissionFlag(arg, "--allow-worker");
552566
}
553567

554568
// Flags that may take a separate following argv token (space form).
569+
// Only the bare form (no =value) may be followed by a separate path token.
555570
static bool PermissionArgTakesNext(const std::string& arg) {
556571
return arg == "--allow-fs-read" || arg == "--allow-fs-write";
557572
}
@@ -567,7 +582,8 @@ static void StripPermissionArgs(std::vector<std::string>* argv) {
567582
if (IsPermissionArg(a)) {
568583
if (PermissionArgTakesNext(a) && i + 1 < argv->size()) {
569584
const std::string& next = (*argv)[i + 1];
570-
// Skip path token if it is not another flag.
585+
// Bare --allow-fs-read/--allow-fs-write may be followed by a path
586+
// token (space-separated CLI form). Only skip one non-flag token.
571587
if (!next.empty() && next[0] != '-') {
572588
i++;
573589
}

0 commit comments

Comments
 (0)