Skip to content

setcap on Node.js prevents processing of NODE_OPTIONS #37588

Description

@connor4312
  • Version: v15.11.0
  • Platform: Linux connor-Virtual-Machine 5.4.0-66-generic
  • Subsystem: unknown

What steps will reproduce the bug?

  1. sudo setcap cap_net_admin+iep $(which node)
  2. Attempt to use anything in the NODE_OPTIONS environment variable
  3. Nothing happens

How often does it reproduce? Is there a required condition?

100% of the time

What is the expected behavior?

I would expect NODE_OPTIONS to be processed regardless.

What do you see instead?

Additional information

Reported on microsoft/vscode-js-debug#852

Activity

  1. addaleax commented on Mar 23, 2021

    @addaleax
    Member

    I think @danbev's #37727 might address this.

  2. added
    linuxIssues and PRs related to the Linux platform.
    securityIssues and PRs related to security.
    on Aug 9, 2021
  3. drazisil commented on Sep 18, 2021

    @drazisil

    When did this behavior break? It doesn't look like the code changed. Is this a change in kernel security?

  4. Busyrev commented on Dec 26, 2021

    @Busyrev

    Reproduced on 17.3.0. Its very important for debugging sсripts that using Bluetooth and GPIO. Please fix it.

  5. lesmo commented on Apr 17, 2023

    @lesmo

    Just wanted to share this is also happening for node v14 under Linux. The annoying part is it took me hours to land at this conclusion.

    The only workaround seems to be NOT using setcap... some alternatives include just using any other port not requiring elevated privileges, some iptables stuff or running with authbind instead (but I havent tried it).

  6. hacki11 commented on Apr 9, 2025

    @hacki11

    So I had the use case to debug as non-root code using raw-socket for which the capability cap_net_raw is needed in a Dev Container using VS Code. My workaround to realize this is using a wrapper.

    VS Code starts the debugging like

    /usr/bin/env 'NODE_OPTIONS= --require ...' 'VSCODE_INSPECTOR_OPTIONS=...' /usr/bin/node ./main.js
    

    which is not working as NODE_OPTIONS is not evaluated as non-root with the enabled capability.

    So i created a wrapper, which extracts the value of NODE_OPTIONS and puts it as node argument, like:

    /usr/bin/node.real --require ... ./main.js
    

    This works because the arguments are evaluated correctly even as non-root having capabilities.

    The Wrapper node-wrapper.sh:

    #!/bin/bash
    NODE_ARGS=()
    
    if [[ -n "$NODE_OPTIONS" ]]; then
      eval "read -r -a NODE_ARGS <<< \"$NODE_OPTIONS\""
      unset NODE_OPTIONS
    fi
    
    REAL_NODE="$(command -v node).real"
    exec "$REAL_NODE" "${NODE_ARGS[@]}" "$@"

    Using in a Dockerfile for the the Dev Container:

    COPY node-wrapper.sh /usr/bin/node-wrapper.sh
    RUN chmod +x /usr/bin/node-wrapper.sh && \
        NODE_BIN="$(command -v node)" && \     
        # Move the original node binary to .real
        mv "$NODE_BIN" "${NODE_BIN}.real" && \
        # Move the wrapper in place
        mv /usr/bin/node-wrapper.sh "$NODE_BIN"
  7. github-actions commented on Jun 27, 2026

    @github-actions
    Contributor

    This issue has been marked as stale due to 210 days of inactivity.
    It will be automatically closed in 30 days if no further activity occurs. If this is still relevant, please leave a comment or update it to keep it open.

  8. added
    staleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.
    on Jun 27, 2026
  9. connor4312 commented on Jun 28, 2026

    @connor4312
    ContributorAuthor

    not stale

  10. removed
    staleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.
    on Jun 28, 2026
  11. github-actions commented on Sep 27, 2026

    @github-actions
    Contributor

    This issue has been marked as stale due to 90 days of inactivity.
    It will be automatically closed in 30 days if no further activity occurs. If this is still relevant, please leave a comment or update it to keep it open.

  12. added
    staleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.
    on Sep 27, 2026
  13. EricMCornelius commented on Sep 27, 2026

    @EricMCornelius

    Not stale.

  14. removed
    staleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.
    on Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    linuxIssues and PRs related to the Linux platform.securityIssues and PRs related to security.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions