From a30e5329d2da3a4c2bcac0f3c4ee3b90347108d1 Mon Sep 17 00:00:00 2001 From: yunshingng Date: Tue, 22 Sep 2026 04:53:24 -0400 Subject: [PATCH] doc: clarify Worker execArgv vs Permission Model grants Omit execArgv: the worker keeps the parent's CLI flags, including --permission and --allow-*. Explicit execArgv (including []) replaces inheritance and can drop those grants. That is intended. Documented after nodejs/node#65359. No runtime change. Refs: https://github.com/nodejs/node/pull/65359 Signed-off-by: yunshingng --- doc/api/permissions.md | 8 +++++++- doc/api/worker_threads.md | 6 ++++++ 2 files changed, 13 insertions(+), 1 deletion(-) diff --git a/doc/api/permissions.md b/doc/api/permissions.md index 0b46f42d982a..d57b706dafc9 100644 --- a/doc/api/permissions.md +++ b/doc/api/permissions.md @@ -330,7 +330,13 @@ easy to configure permissions as needed when using `npx`. There are constraints you need to know before using this system: -* The model does not inherit to a worker thread. +* The model does not inherit to a worker thread. A default + `worker_threads.Worker` (no `execArgv` option) still receives the parent + process CLI flags, including `--permission` and `--allow-*` if those were + passed to the parent. Setting `execArgv` explicitly, including + `execArgv: []`, replaces the inherited flags. The worker then does not keep + the parent's Permission Model grants unless those flags are listed again in + `execArgv`. That difference is intended, not a bypass. * When using the Permission Model the following features will be restricted: * Native modules * Network diff --git a/doc/api/worker_threads.md b/doc/api/worker_threads.md index e7b6b19b355c..21b9ac663b32 100644 --- a/doc/api/worker_threads.md +++ b/doc/api/worker_threads.md @@ -1631,6 +1631,12 @@ changes: process (such as `--title`) are not supported. If set, this is provided as [`process.execArgv`][] inside the worker. By default, options are inherited from the parent thread. + Passing an explicit `execArgv` (including an empty array) replaces that + inheritance: the worker receives only the listed flags. Under the + [Permission Model](permissions.md#permission-model), that means an explicit + `execArgv` can drop the parent's `--permission` / `--allow-*` grants. + Omit `execArgv` to keep the parent's CLI flags. This is intended. See + [Permission Model limitations](permissions.md#limitations-and-known-issues). * `stdin` {boolean} If this is set to `true`, then `worker.stdin` provides a writable stream whose contents appear as `process.stdin` inside the Worker. By default, no data is provided.