Commit ff31c97032c for nodejs
commit ff31c97032c56f23e881185e2236836645d257ef
Author: Rafael Gonzaga <rafael.nunu@hotmail.com>
Date: Sat Oct 10 05:29:51 2026 -0300
lib: add --allow-fs-vfs to permission available flags
Without it, --allow-fs-vfs was accepted without --permission and was not
propagated to child processes like the other --allow-* flags.
Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com>
PR-URL: https://github.com/nodejs/node/pull/66554
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Ulises Gascón <ulisesgascongonzalez@gmail.com>
diff --git a/lib/internal/process/permission.js b/lib/internal/process/permission.js
index d2921694b99..92e54fbab49 100644
--- a/lib/internal/process/permission.js
+++ b/lib/internal/process/permission.js
@@ -74,6 +74,7 @@ module.exports = ObjectFreeze({
const flags = [
'--allow-fs-read',
'--allow-fs-write',
+ '--allow-fs-vfs',
'--allow-addons',
'--allow-child-process',
'--allow-env',
diff --git a/test/parallel/test-permission-allow-fs-vfs-flags.js b/test/parallel/test-permission-allow-fs-vfs-flags.js
new file mode 100644
index 00000000000..68fcac76bd7
--- /dev/null
+++ b/test/parallel/test-permission-allow-fs-vfs-flags.js
@@ -0,0 +1,42 @@
+'use strict';
+
+const common = require('../common');
+const { isMainThread } = require('worker_threads');
+
+if (!isMainThread) {
+ common.skip('This test only works on a main thread');
+}
+
+const { spawnSyncAndAssert, spawnSyncAndExit } = require('../common/child_process');
+
+// --allow-fs-vfs requires the permission model.
+spawnSyncAndExit(
+ process.execPath,
+ ['--allow-fs-vfs', '-e', ''],
+ {
+ status: 1,
+ signal: null,
+ stderr: /--permission is required/,
+ },
+);
+
+if (process.config.variables.node_without_node_options) {
+ common.skip('missing NODE_OPTIONS support');
+}
+
+// A child process inherits --allow-fs-vfs along with --permission.
+const child = `
+ const { spawnSync } = require('child_process');
+ const { stdout } = spawnSync(process.execPath, [
+ '-p', 'process.env.NODE_OPTIONS',
+ ], { encoding: 'utf8' });
+ process.stdout.write(stdout);
+`;
+
+spawnSyncAndAssert(
+ process.execPath,
+ ['--permission', '--allow-fs-vfs', '--allow-child-process', '-e', child],
+ {
+ stdout: /(^|\s)--allow-fs-vfs(\s|$)/,
+ },
+);