Skip to content

Many macOS popups asking for incoming connections appear when running test suite for the first time #37233

Description

@marsonya

I saw 10s of popups in MacOS asking "Do you want the application node to accept incoming network connections?" when I ran the test suite. They just keep coming, 1 every 5-10 seconds. The only way to stop is force close vscode. Happened when I ran ./configure && make -j4 test.

Screenshot 2021-02-04 at 18 30 25

  • Operating Sustem: MacOS
  • Version: Big Sur 11.0.1

What steps will reproduce the bug?

  • Cloned my Fork
  • Made a few changes to tests (var to let/const)
  • Ran the Test Suite ./configure && make -j4 test

How often does it reproduce? Is there a required condition?

This happened twice.
First time, I did not allow. Simply force closed vscode.
I wanted to try again to get a screenshot this time.
So I ran the test suite a second time, got the screenshot and allowed the application to get incoming calls.

What is the expected behavior?

One popup must be enough.

What do you see instead?

I see 10s of popups. They keep increasing. 1 every 5-10 seconds.

Additional information

The only way to make it stop is to force close vscode. The popups just keep coming.

Activity

  1. cjihrig commented on Feb 5, 2021

    @cjihrig
    Contributor

    If you run tools/macos-firewall.sh before the test suite it should help.

  2. added
    buildIssues and PRs related to Node.js builds or CI infrastructure.
    macosIssues and PRs related to the macOS platform.
    on Feb 9, 2021
  3. Trott commented on Feb 15, 2021

    @Trott
    Member

    This depends on your firewall settings. It doesn't seem to happen on a default macOS setup, but tends to happen if you have a managed macOS machine or if the firewall settings are otherwise adjusted to be sufficiently strict.

    I don't think there's much to do about this other than perhaps document the existence of tools/macos-firewall.sh a bit more prominently than it's currently documented?

    I'm going to close this but feel free to comment or re-open if you think there's more to discuss and/or more to do here.

  4. marsonya commented on Feb 15, 2021

    @marsonya
    MemberAuthor

    I realise that tools/macos-firewall.sh will solve this issue and I do have custom firewall config on my system.
    But my intention of creating this issue was to bring the infinite popups to your notice.
    In my opinion, even if I have not run the tools/macos-firewall.sh, I should see only one popup.

  5. Trott commented on Feb 17, 2021

    @Trott
    Member

    In my opinion, even if I have not run the tools/macos-firewall.sh, I should see only one popup.

    I'm not sure how we'd achieve that unless we run all the tests that require network access with a single invocation of node.

  6. marsonya commented on Mar 18, 2021

    @marsonya
    MemberAuthor

    I followed the BUILDING.md file along with the feedback in this discussion.

    I built node.js using make. It was successful, or at least I think so. This is how my build ended in terminal:-

    Screenshot 2021-03-19 at 00 13 23

    After that, I executed tools/macos-firewall.sh but this is what happens:-

    Screenshot 2021-03-19 at 00 09 09

    Regardless, I ran the tests. The popups showed. All of em.

    Am I missing something?

    More Information:-
    OS: macOS Big Sur

  7. Trott commented on Mar 20, 2021

    @Trott
    Member

    The output you show is expected. (I know it looks like a bunch of errors and brokenness, but I think what the script does is try everything possible, and only one or two of those are supposed to succeed.)

    I think the docs may incorrectly be specifying to run the script with sudo. I run it without sudo and it works. Any chance running it without sudo works for you?

  8. Trott commented on Mar 20, 2021

    @Trott
    Member
  9. marsonya commented on Mar 20, 2021

    @marsonya
    MemberAuthor

    The output you show is expected. (I know it looks like a bunch of errors and brokenness, but I think what the script does is try everything possible, and only one or two of those are supposed to succeed.)

    I think the docs may incorrectly be specifying to run the script with sudo. I run it without sudo and it works. Any chance running it without sudo works for you?

    It works without sudo for me. Getting the same output I shared above.

  10. danbev commented on Mar 20, 2021

    @danbev
    Contributor

    Perhaps there is some change required for macOS Big Sur though for this script to work with it. Unfortunately I'm no longer using a mac and don't really have a good way to test/fix this 😞

  11. Trott commented on Mar 20, 2021

    @Trott
    Member

    It works without sudo for me. Getting the same output I shared above.

    When you say it works without sudo, does that mean that running it without sudo means you no longer get all those dialogue boxes when running tests? If so, then the fix here I guess is to update the documentation. I'm not sure if the answer is to remove sudo or to suggest that it may require omitting sudo. (Like I said, I never run it with sudo.)

    As for the output, it has always been that way, so I'm not too concerned about that (although if someone wants to fix it without affecting the script working across various macOS versions, then great).

  12. marsonya commented on Mar 20, 2021

    @marsonya
    MemberAuthor

    It works without sudo for me. Getting the same output I shared above.

    When you say is works without sudo, does that mean that running it without sudo means you no longer get all those dialogue boxes when running tests? If so, then the fix here I guess is to update the documentation. I'm not sure if the answer is to remove sudo or to suggest that it may require omitting sudo. (Like I said, I never run it with sudo.)

    As for the output, it has always been that way, so I'm not too concerned about that (although if someone wants to fix it without affecting the script working across various macOS versions, then great).

    Unfortunately, running the script with or without sudo did not help. I am still seeing the popups.
    On a side note, the tests are running without any problems as the popups keep coming.

  13. 10 remaining items

  14. Trott commented on Mar 23, 2021

    @Trott
    Member

    I see at https://developer.apple.com/forums/thread/666222?answerId=646899022#646899022 that @Qard has run into this problem. Maybe he knows something more than what we've figured out so far.

    Based on that thread, it appears this may be a bug in Big Sur that may be fixed in an upcoming update.

  15. Trott commented on Mar 23, 2021

    @Trott
    Member

    Can confirm that now that I've updated to Big Sur, I'm seeing the same behavior. And it sure seems like a Big Sur bug.

  16. marsonya commented on Mar 23, 2021

    @marsonya
    MemberAuthor

    Can confirm that now that I've updated to Big Sur, I'm seeing the same behavior. And it sure seems like a Big Sur bug.

    Apple patching up Big Sur might take some time.
    Is there an alternative for the meantime? Something that can be done manually?

  17. added a commit that references this issue on Mar 23, 2021
  18. Trott commented on Mar 24, 2021

    @Trott
    Member

    Apple patching up Big Sur might take some time.
    Is there an alternative for the meantime? Something that can be done manually?

    I'm not sure if any or all of these will work, but you can try:

    1: You can go to System Preferences -> Security & Privacy -> Firewall -> Firewall Options and use the GUI to add your node binary and set it to "Allow incoming connections".

    2: I just tried this and it worked, surprisingly to me. tools/test.py test/parallel/test-http will run one test that results in the dialogue box. I clicked "Allow" after the test finished and subsequent test runs did not result in the dialogue box showing up. I won't be surprised if that doesn't work, but it sure seemed to work for me.
    ¯\(ツ)/¯

    3: Last resort, not recommended, but you can turn off the firewall entirely either from the command line or in the System Preferences -> Security & Privacy -> Firewall GUI.

  19. marsonya commented on Mar 24, 2021

    @marsonya
    MemberAuthor

    Apple patching up Big Sur might take some time.
    Is there an alternative for the meantime? Something that can be done manually?

    I'm not sure if any or all of these will work, but you can try:

    1: You can go to System Preferences -> Security & Privacy -> Firewall -> Firewall Options and use the GUI to add your node binary and set it to "Allow incoming connections".

    2: I just tried this and it worked, surprisingly to me. tools/test.py test/parallel/test-http will run one test that results in the dialogue box. I clicked "Allow" after the test finished and subsequent test runs did not result in the dialogue box showing up. I won't be surprised if that doesn't work, but it sure seemed to work for me.
    ¯_(ツ)_/¯

    3: Last resort, not recommended, but you can turn off the firewall entirely either from the command line or in the System Preferences -> Security & Privacy -> Firewall GUI.

    node is already set in Firewall Options. So 1 doesn't work for me.
    I tried 2. Did not work.
    I am uncomfortable with 3 :)

    So, for the time being, I will just let the popups appear when I am running the full test suite. Takes like 5 mins only anyways. The popups are not at all a big problem when running tests for a specific subsystem. So that's a relief.

    I really appreciate you looking into this and thanks for the options :)

  20. Trott commented on Mar 24, 2021

    @Trott
    Member

    node is already set in Firewall Options. So 1 doesn't work for me.

    I imagine it says "Allow incoming connections" rather than "Block incoming connections". If not, definitely change it to "Allow".

    If that doesn't work, one last thing to try might be to remove it and re-add it, just in case it's been added at a different path or something like that.

  21. marsonya commented on Mar 24, 2021

    @marsonya
    MemberAuthor

    I imagine it says "Allow incoming connections" rather than "Block incoming connections". If not, definitely change it to "Allow".

    It did say "Allow Incoming connections". But did not work earlier.

    If that doesn't work, one last thing to try might be to remove it and re-add it, just in case it's been added at a different path or something like that.

    Then, I took your suggestion. Removed node and cctest from firewall options and added them again.
    It worked like a Charm. Thanks.

  22. added a commit that references this issue on May 1, 2021
  23. anonrig commented on Jul 29, 2022

    @anonrig
    Member

    I'm having somehow a similar issue, where I believe running make -j8 test creates a new executable, and therefore dismisses the integrity check on the firewall and invalidates the tools/macos-firewall.sh changes on macOS Monterey 12.4 on M1. The only thing worked for me is to disable the firewall, but I'm interested in a better alternative. Anyone solved this?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    buildIssues and PRs related to Node.js builds or CI infrastructure.macosIssues and PRs related to the macOS platform.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions