From b83b2af2c0f881e54e900bbc768fb79cf392a530 Mon Sep 17 00:00:00 2001 From: Trivikram Kamat <16024985+trivikr@users.noreply.github.com> Date: Wed, 30 Sep 2026 22:22:35 -0700 Subject: [PATCH] ffi: remove permission checks from dlclose and dlsym The docs describe `ffi.dlclose(handle)` and `ffi.dlsym(handle, symbol)` as equivalent to `handle.close()` and `handle.getSymbol(symbol)`, but only the functions called `checkFFIPermission()`. After `process.permission.drop('ffi')`, `ffi.dlclose(lib)` threw `ERR_ACCESS_DENIED` while `lib.close()` succeeded. Remove the checks so the functions defer to the handle. Permission is already checked when the `DynamicLibrary` is constructed, and dropping a permission does not revoke resources that are already open. Signed-off-by: Trivikram Kamat <16024985+trivikr@users.noreply.github.com> Assisted-by: claude:opus-5.5 --- lib/ffi.js | 2 -- test/ffi/test-ffi-permissions.js | 6 +++--- 2 files changed, 3 insertions(+), 5 deletions(-) diff --git a/lib/ffi.js b/lib/ffi.js index 5cd7c4b354ab..2a9db50fa51c 100644 --- a/lib/ffi.js +++ b/lib/ffi.js @@ -252,12 +252,10 @@ function dlopen(path, definitions) { } function dlclose(handle) { - checkFFIPermission(); handle.close(); } function dlsym(handle, symbol) { - checkFFIPermission(); return handle.getSymbol(symbol); } diff --git a/test/ffi/test-ffi-permissions.js b/test/ffi/test-ffi-permissions.js index e441d88efac2..ff4a4ef3a67b 100644 --- a/test/ffi/test-ffi-permissions.js +++ b/test/ffi/test-ffi-permissions.js @@ -74,7 +74,7 @@ test('permission model blocks ffi memory and helper APIs', () => { ffi.getCurrentEventLoop(); }, denied); - assert.throws(() => { - ffi.dlclose({ close() {} }); - }, denied); + // Like handle.close() and handle.getSymbol(), these do not check permissions. + ffi.dlclose({ close() {} }); + assert.strictEqual(ffi.dlsym({ getSymbol: () => 1n }, 'x'), 1n); });