Skip to content

--experimental-permission breaks REPL #48884

Description

@tniessen

Version

20.5.0

Platform

any

Subsystem

permission model

What steps will reproduce the bug?

Open a REPL and start typing:

$ node --experimental-permission --allow-fs-read=/
> f

How often does it reproduce? Is there a required condition?

Always.

What is the expected behavior? Why is that the expected behavior?

No error.

What do you see instead?

Fatal error:

node:internal/readline/emitKeypressEvents:74
            throw err;
            ^

Error: Access to this API has been restricted
    at Session.connect (node:inspector:68:7)
    at sendInspectorCommand (node:internal/util/inspector:52:11)
    at getGlobalLexicalScopeNames (node:repl:1262:10)
    at REPLServer.complete (node:repl:1493:26)
    at REPLServer.completer (node:repl:783:5)
    at showCompletionPreview (node:internal/repl/utils:230:10)
    at showPreview (node:internal/repl/utils:384:7)
    at REPLServer.self._ttyWrite (node:repl:1020:9)
    at ReadStream.onkeypress (node:internal/readline/interface:264:20)
    at ReadStream.emit (node:events:514:28) {
  code: 'ERR_ACCESS_DENIED',
  permission: 'Inspector',
  resource: 'Connect'
}

Node.js v20.5.0

Additional information

Likely side effect of 34d92ed.

Activity

  1. added
    replIssues and PRs related to the REPL subsystem.
    on Jul 22, 2023
  2. RafaelGSS commented on Jul 24, 2023

    @RafaelGSS
    Member

    Hi, thanks for reporting it. I'm aware of this behaviour.

  3. targos commented on Jul 24, 2023

    @targos
    Member

    Question is: should we make the internal calls to the inspector possible/privileged, or do like when the inspector is unavailable (this would just be a new condition in

    const { hasInspector } = internalBinding('config');
    if (!hasInspector) return onError();
    )

  4. RafaelGSS commented on Jul 24, 2023

    @RafaelGSS
    Member

    I believe REPL shouldn't be available when the permission model is enabled. Please let me know if I'm wrong, but the REPL can create a new V8 isolate and bypass any permission in several ways. If we start supporting REPL, it would mean that we need to cover all those cases.

  5. targos commented on Jul 25, 2023

    @targos
    Member

    the REPL can create a new V8 isolate and bypass any permission in several ways

    Can you elaborate?

  6. RafaelGSS commented on Jul 25, 2023

    @RafaelGSS
    Member

    the REPL can create a new V8 isolate and bypass any permission in several ways

    Can you elaborate?

    Basically, the same as 34d92ed fixes. I don't have a reproducible example because I'm not sure if that's possible. I'm just wondering if REPL can create a new V8 isolate, it means it could create without the experimental permission rules, right?

    Anyway, I created the #48920.

  7. added
    permissionIssues and PRs related to the Permission Model.
    on Aug 10, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    confirmed-bugIssues and PRs for confirmed bugs.permissionIssues and PRs related to the Permission Model.replIssues and PRs related to the REPL subsystem.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions