Commit ff31c97032c for nodejs

commit ff31c97032c56f23e881185e2236836645d257ef
Author: Rafael Gonzaga <rafael.nunu@hotmail.com>
Date:   Sat Oct 10 05:29:51 2026 -0300

    lib: add --allow-fs-vfs to permission available flags

    Without it, --allow-fs-vfs was accepted without --permission and was not
    propagated to child processes like the other --allow-* flags.

    Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com>
    PR-URL: https://github.com/nodejs/node/pull/66554
    Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
    Reviewed-By: Ulises Gascón <ulisesgascongonzalez@gmail.com>

diff --git a/lib/internal/process/permission.js b/lib/internal/process/permission.js
index d2921694b99..92e54fbab49 100644
--- a/lib/internal/process/permission.js
+++ b/lib/internal/process/permission.js
@@ -74,6 +74,7 @@ module.exports = ObjectFreeze({
     const flags = [
       '--allow-fs-read',
       '--allow-fs-write',
+      '--allow-fs-vfs',
       '--allow-addons',
       '--allow-child-process',
       '--allow-env',
diff --git a/test/parallel/test-permission-allow-fs-vfs-flags.js b/test/parallel/test-permission-allow-fs-vfs-flags.js
new file mode 100644
index 00000000000..68fcac76bd7
--- /dev/null
+++ b/test/parallel/test-permission-allow-fs-vfs-flags.js
@@ -0,0 +1,42 @@
+'use strict';
+
+const common = require('../common');
+const { isMainThread } = require('worker_threads');
+
+if (!isMainThread) {
+  common.skip('This test only works on a main thread');
+}
+
+const { spawnSyncAndAssert, spawnSyncAndExit } = require('../common/child_process');
+
+// --allow-fs-vfs requires the permission model.
+spawnSyncAndExit(
+  process.execPath,
+  ['--allow-fs-vfs', '-e', ''],
+  {
+    status: 1,
+    signal: null,
+    stderr: /--permission is required/,
+  },
+);
+
+if (process.config.variables.node_without_node_options) {
+  common.skip('missing NODE_OPTIONS support');
+}
+
+// A child process inherits --allow-fs-vfs along with --permission.
+const child = `
+  const { spawnSync } = require('child_process');
+  const { stdout } = spawnSync(process.execPath, [
+    '-p', 'process.env.NODE_OPTIONS',
+  ], { encoding: 'utf8' });
+  process.stdout.write(stdout);
+`;
+
+spawnSyncAndAssert(
+  process.execPath,
+  ['--permission', '--allow-fs-vfs', '--allow-child-process', '-e', child],
+  {
+    stdout: /(^|\s)--allow-fs-vfs(\s|$)/,
+  },
+);