Repository navigation
[Bug]: use pm2 and --experimental-permission, throw Error: Access to this API has been restricted #53447
Description
Activity
With the permissions you have set, that API isn't accessible. Try giving your script more permissions if possible.
@nodejs/security-wg
- addedpermissionIssues and PRs related to the Permission Model.Issues and PRs related to the Permission Model.inspectorIssues and PRs related to the V8 inspector protocol.Issues and PRs related to the V8 inspector protocol.
on Jun 14, 2024 @redyetidev
hello,I don't know what option or parameter can be used to grant permission, it seems that this parameter is not supported? Can you give me an example?Hi! The security working group is in the CC, they know more about this and they'll respond soon!
As the error trace suggests:
(/Users/skypesky/Library/pnpm/global/5/.pnpm/@pm2+io@6.0.0/node_modules/@pm2/io/build/main/services/inspector.js:14:22PM2 attempts to use the inspector protocol and this is disabled by default when using the Permission Model. It's not a bug, t
there's nothing we can do on the Node.js side.As the error trace suggests:
(/Users/skypesky/Library/pnpm/global/5/.pnpm/@pm2+io@6.0.0/node_modules/@pm2/io/build/main/services/inspector.js:14:22PM2 attempts to use the inspector protocol and this is disabled by default when using the Permission Model. It's not a bug, t there's nothing we can do on the Node.js side.
@RafaelGSS
So how can I use --experimental-permission and give @pm2/io permission as well? What parameters should I add?So how can I use --experimental-permission and give @pm2/io permission as well? What parameters should I add?
You can't. As long as the
@pm2/iouses the inspector protocol, you can't use this module with the Permission Model.@RafaelGSS
I don't understand why there is this restriction and why we can't enable permissions.
Can we support an --allow-inspect parameter when using --experimental-permission?@RafaelGSS I don't understand why there is this restriction and why we can't enable permissions. Can we support an --allow-inspect parameter when using --experimental-permission?
The use of the inspector protocol can basically bypass any restriction imposed by the Permission Model. Technically, we can add an
--allow-inspectCLI, but it might cause an impression of a safe environment where it's not.let {result:{ objectId }} = await session.post('Runtime.evaluate', { expression: 'Worker' });
The usage of
sessioncan intercept internals and bypass the Worker and Child Process for example. We can for sure discuss a better implementation of this restriction, but a simple--allow-inspectormight not be accurate.Can you open an issue on nodejs/security-wg? Meanwhile, I'm closing this issue.
Version
v22.3.0
Platform
Darwin mac-studio.local 23.4.0 Darwin Kernel Version 23.4.0: Fri Mar 15 00:10:42 PDT 2024; root:xnu-10063.101.17~1/RELEASE_ARM64_T6000 arm64
Subsystem
No response
What steps will reproduce the bug?
pm2.io.js, install@pm2/iodepspm2 start pm2.io.js --node-args="--experimental-permission --allow-fs-read=*" -fpm2 logscommandHow often does it reproduce? Is there a required condition?
No response
What is the expected behavior? Why is that the expected behavior?
It should start and run normally without throwing any errors
What do you see instead?
Additional information
related: #53385 (comment)