Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: add permission name when accessing a special file errors #25085

Merged
merged 13 commits into from
Aug 19, 2024
6 changes: 3 additions & 3 deletions ext/fs/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -89,9 +89,9 @@ impl FsPermissions for deno_permissions::PermissionsContainer {
api_name: &str,
) -> Result<Cow<'a, Path>, FsError> {
if resolved {
self.check_special_file(path, api_name).map_err(|_| {
std::io::Error::from(std::io::ErrorKind::PermissionDenied)
})?;
self
.check_special_file(path, api_name)
.map_err(FsError::PermissionDenied)?;
return Ok(Cow::Borrowed(path));
}

Expand Down
32 changes: 32 additions & 0 deletions tests/unit/os_test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@ import {
assert,
assertEquals,
assertNotEquals,
assertStringIncludes,
assertThrows,
} from "./test_util.ts";

Expand Down Expand Up @@ -196,6 +197,37 @@ Deno.test({ permissions: { read: false } }, function execPathPerm() {
);
});

Deno.test(async function execPathPerm() {
if (Deno.build.os !== "linux") return;
// This is hack to bypass a bug in deno test runner,
// Currently if you specify {read: true} permission, it will stil pass --allow-all (tests are run with deno test --allow-all) implicitly, so this test won't work
// The workaround is to spawn a deno executable with the needed permissions
// TODO(#25085): remove this hack when the bug is fixed
dsherret marked this conversation as resolved.
Show resolved Hide resolved
const cmd = new Deno.Command(Deno.execPath(), {
args: ["run", "--allow-read", "-"],
stdin: "piped",
stderr: "piped",
}).spawn();
const stdinWriter = cmd.stdin.getWriter();
await stdinWriter
.write(
new TextEncoder().encode('Deno.readTextFileSync("/proc/net/dev")'),
);
await stdinWriter.close();
await cmd.status;

const stderrReder = cmd.stderr.getReader();
const error = await stderrReder
.read()
.then((r) => new TextDecoder().decode(r.value));
await stderrReder.cancel();

assertStringIncludes(
error,
`PermissionDenied: Requires all access to "/proc/net/dev", run again with the --allow-all flag`,
);
});

Deno.test(
{ permissions: { sys: ["loadavg"] } },
function loadavgSuccess() {
Expand Down