Repository navigation
[Bug]: When using --allow-fs-write to execute a non-existent folder, creating subdirectories of that folder will fail #53621
Description
Activity
- addedfsIssues and PRs related to file-system APIs and the fs module.Issues and PRs related to file-system APIs and the fs module.securityIssues and PRs related to security.Issues and PRs related to security.experimentalIssues and PRs related to experimental features.Issues and PRs related to experimental features.permissionIssues and PRs related to the Permission Model.Issues and PRs related to the Permission Model.
on Jun 28, 2024 You have set allow-write to
/Users/skypesky/workSpaces/javascript/github/tempand trying to write on
/Users/skypesky/workSpaces/javascript/github/tmp/it's working as supposed, you need set write-permission to/Users/skypesky/workSpaces/javascript/github/tmp@marco-ippolito
please ignore my spelling mistakes, this is indeed a bug, here is a screenshot.


does the folder
tempexists?- The temp folder does not exist! Specifically, I can actually create temp successfully, but I cannot create subfolders of temp.
const { mkdir } = require('node:fs/promises'); (async () => { await mkdir('/Users/skypesky/workSpaces/javascript/github/temp', { recursive: true }); // exec ok! await mkdir('/Users/skypesky/workSpaces/javascript/github/temp/a/b/c/d', { recursive: true }); // exec failed!!! })();does the folder
tempexists? if not it wont work To create the foldertempyou need to have write access in the parent directory for example:/Users/skypesky/workSpaces/javascript/github/I do not want it to have the permission to write data in this folder on github, this is not what we intended.
I can reproduce, I confirm its a bug @RafaelGSS
node --experimental-permission --allow-fs-write=$PWD/foo --allow-fs-read=$PWD/test.js test.js
const { mkdir } = require('node:fs/promises'); (async () => { await mkdir('./foo/', { recursive: true }); await mkdir('./foo/tmp/a/b/c/d', { recursive: true }); })();
- addedconfirmed-bugIssues and PRs for confirmed bugs.Issues and PRs for confirmed bugs.
on Jun 28, 2024 Meanwhile, can you try adding a
*aftertemp?--allow-fs-write=/Users/skypesky/workSpaces/javascript/github/temp/*Anyway, I'll fix it.
Just tested it this as well, if adding
*aftertempit will sayno matches found: --allow-fs-write=/file path/1 remaining item
Thanks, it was my terminal (zsh), after adding
*it works, it can create the folders recursively.Actually, thinking more about it... It's not a bug,
tempnever existed, so the system cannot identify iftempis supposed to be a folder or just a filetemp.I'm pretty sure if you try to create a file
/Users/skypesky/workSpaces/javascript/github/tempit will work with success.Hence, for non-existent folders you must add the wildcard: *.
- removedconfirmed-bugIssues and PRs for confirmed bugs.Issues and PRs for confirmed bugs.
on Jun 28, 2024 Actually, thinking more about it... It's not a bug,
tempnever existed, so the system cannot identify iftempis supposed to be a folder or just a filetemp.I'm pretty sure if you try to create a file
/Users/skypesky/workSpaces/javascript/github/tempit will work with success.Hence, for non-existent folders you must add the wildcard: *.
But give then case:
node --experimental-permission --allow-fs-write=$PWD/foo --allow-fs-read=$PWD/test.js test.jsconst { mkdir } = require('node:fs/promises'); (async () => { await mkdir('./foo/', { recursive: true }); await mkdir('./foo/tmp/a/b/c/d', { recursive: true }); })();The folder is created succesfully so it should word
PS: Accidentally closedReacted by jakecastelliIIRC, when the permission model is being initialized, it implicitly adds wildcards to the end of paths that are (existing) directories. If
$PWD/foodoes not exist, no wildcard is implicitly added, so the permission model only allows access to the exact path$PWD/foo.Reacted by jakecastelliIIRC, when the permission model is being initialized, it implicitly adds wildcards to the end of paths that are (existing) directories. If
$PWD/foodoes not exist, no wildcard is implicitly added, so the permission model only allows access to the exact path$PWD/foo.That's correct. If you created
$PWD/foofolder during runtime, the permission model won't be able to identify if that's a folder and add the wildcard.I'm going to close it as this is expected behaviour. Feel free to re-open if something is misleading.
Reacted by JianChao YeThanks for the explanation @tniessen @RafaelGSS I traced to
is_grantedmethod infs_permission.ccand found out it was cached. I am thinking this probably should be documented in the Limitations and Known Issues section of theapi/permissionsdoc? (👍 or 👎)Reacted by JianChao YeIt's not a limitation as it's designed to work in that way. We could mention it on https://nodejs.org/api/permissions.html#file-system-permissions specifically on wildcard mention.
Reacted by jakecastelli
Version
v22.3.0
Platform
Subsystem
No response
What steps will reproduce the bug?
test.jsHow often does it reproduce? Is there a required condition?
No response
What is the expected behavior? Why is that the expected behavior?
What do you see instead?
Additional information
const { mkdir } = require('node:fs/promises'); (async () => { await mkdir('/Users/skypesky/workSpaces/javascript/github/temp', { recursive: true }); // exec ok! await mkdir('/Users/skypesky/workSpaces/javascript/github/temp/a/b/c/d', { recursive: true }); // failed })();