Skip to content

Bug: Fail to disable eval() #44516

Description

@caoccao

Version

v16.17.0

Platform

Microsoft Windows NT 10.0.19044.0 x64

Subsystem

No response

What steps will reproduce the bug?

Background

I'm embedding Node.js in a C++ application and want to disable eval() for security concern.

Reproduce

  • Build command: vcbuild.bat static without-intl
  • C++ code: v8Context->AllowCodeGenerationFromStrings(false);

How often does it reproduce? Is there a required condition?

This is a consistent behavior malfunction. It doesn't require any conditions.

What is the expected behavior?

The expected result is calling eval() returns an error EvalError: Code generation from strings disallowed for this context. However, in v16.17.0 the eval() still works. It used to be working well in v16.16.0.

What do you see instead?

The eval() is not disabled.

Additional information

No response

Activity

  1. added
    v8 engineIssues and PRs related to the V8 dependency.
    on Sep 5, 2022
  2. legendecas commented on Sep 5, 2022

    @legendecas
    Member

    ModifyCodeGenerationFromStringsCallback is invoked when AllowCodeGenerationFromStrings is false. Node.js has set its ModifyCodeGenerationFromStringsCallback to check an internal allow code generation from strings flag.

    In order to propagate the AllowCodeGenerationFromStrings to Node.js internal flag slot, context->AllowCodeGenerationFromStrings should be set before node::InitializeContext, or start node with --disallow-code-generation-from-strings (#44324).

    Alternatively, the embedder can set its own callback of ModifyCodeGenerationFromStringsCallback.

  3. caoccao commented on Sep 5, 2022

    @caoccao
    Author

    Thank you for the detailed explanation.

    In my use case, the application may allow-disallow-allow-disallow... the code generation from strings in one context. It seems setting ModifyCodeGenerationFromStringsCallback is the only option. The question now is: will that break anything?

  4. caoccao commented on Sep 14, 2022

    @caoccao
    Author

    Update

    I added the following line and it works.

    // After V8 isolate is initialized.
    v8Isolate->SetModifyCodeGenerationFromStringsCallback(nullptr);
  5. FoxNick commented on Dec 18, 2024

    @FoxNick

    VM里 通过 配置实现了 开启和禁用 这样操作 就把vm 的EVAL 彻底禁掉了 VM里是通过代码关闭的

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    v8 engineIssues and PRs related to the V8 dependency.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions