ffi: `dlclose()`/`dlsym()` check permissions that `handle.close()`/`handle.getSymbol()` don't

#66425 · open · 0 comments

View on GitHub ↗

trivikr

### Version main ### Platform ```text macOS 26.7.0 ``` ### Subsystem ffi ### What steps will reproduce the bug? ```js import ffi from 'node:ffi'; const a = ffi.dlopen(null); const b = ffi.dlopen(null); process.permission.drop('ffi'); b.lib.getSymbol('qsort'); console.log('lib.getSymbol(): ok'); b.lib.close(); console.log('lib.close(): ok'); try { ffi.dlsym(a.lib, 'qsort'); } catch (err) { console.log('ffi.dlsym():', err.code); } try { ffi.dlclose(a.lib); } catch (err) { console.log('ffi.dlclose():', err.code); } ``` Run with ```console node --no-warnings --permission --allow-ffi repro.js ``` ### How often does it reproduce? Is there a required condition? Always ### What is the expected behavior? Why is that the expected behavior? The functions and the methods behave the same. [ffi.dlclose(handle)](https://github.com/nodejs/node/blob/main/doc/api/ffi.md#ffidlclosehandle) says > This is equivalent to calling `handle.close()`. [ffi.dlsym(handle, symbol)](https://github.com/nodejs/node/blob/main/doc/api/ffi.md#ffidlsymhandle-symbol) says > This is equivalent to calling `handle.getSymbol(symbol)`. ### What do you see instead? ```console lib.getSymbol(): ok lib.close(): ok ffi.dlsym(): ERR_ACCESS_DENIED ffi.dlclose(): ERR_ACCESS_DENIED ``` ### Additional information _No response_

Comments