Replies: 1 comment
Follow-up: broader than the 5.1 fallback - PowerShell 7 also crashes under the sandbox in Desktop modeAdditional evidence on the same machine (Windows 11 Pro 26200, DSH Desktop 0.1.4):
Conclusion: the documented sandbox boundary ("console isolation unavailable" - children created with a hidden/new console die with STATUS_DLL_INIT_FAILED under the restricted token) affects ANY PowerShell launched from the Desktop shell (Electron host without a console), not just the 5.1 fallback. In a console-host environment the child inherits the console and the sandbox works (which is presumably why the pwsh-7 path was verified); in the Desktop app the child gets a new hidden console and DLL init fails. Note: this also means installing the MSI build at the standard location will likely NOT avoid the crash under the Desktop app (the failure is at process/DLL-init level, not Store-specific) - untested here. Suggested handling (any of):
|
Uh oh!
There was an error while loading. Please reload this page.
摘要 / Summary
Windows 上未安装 PowerShell 7 时,DSH 的 pwsh 工具会按
resolvePwshPath的兜底逻辑回退到 Windows PowerShell 5.1(C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe)。在 Windows ACL 沙箱(workspace-write/read-only)下,5.1 每次启动都以0xC0000142(STATUS_DLL_INIT_FAILED)崩溃:零输出、命令从未执行、前台与后台 100% 复现。沙箱外 5.1 运行完全正常。环境 / Environment
0.1.0-rc.6(@deepseek-ai/dsh、@deepseek-ai/dsh-sandbox-windows-acl、@deepseek-ai/dsh-pwsh-local)0.1.4(DeepSeek Harness Desktop.exe)C:\Program Files\PowerShell\7不存在);调查过程中安装过商店版(MSIX),见「补充证据」powershell.exe -NoLogo -NoProfile -NonInteractive -Command "Write-Output ok"正常输出ok,排除 5.1 本身损坏)复现步骤 / Repro
Write-Output "hi");3221225794(0xC0000142),无任何 stdout/stderr;run_in_background: true的后台调用同样崩溃。根因分析 / Root cause
packages/shell/pwsh-local的resolvePwshPath依次探测「PowerShell 7 安装位置 → PATH 条目 → Windows PowerShell 5.1 兜底」。本机无 PS7,因此实际执行的是powershell.exe(5.1),且无任何提示。packages/sandbox/sandbox-windows-acl/runner.js)以受限令牌CreateProcessAsUserW(dwCreationFlags=0)spawn 子进程并镜像子进程退出码(runner 自身失败会以127+windows-acl-run:签名退出并被识别为SandboxUnavailableError,本场景未出现)。所以0xC0000142是 powershell.exe 的崩溃码,崩溃发生在早期 DLL 初始化阶段(命令执行之前)。0xC0000142是沙箱文档化的已知边界:sandbox-windows-acl/README.md「已验证边界 → 控制台隔离不可用」一节记载——「在受限令牌下,以CREATE_NO_WINDOW/CREATE_NEW_CONSOLE创建的子进程在 DLL 初始化期间以STATUS_DLL_INIT_FAILED(0xC0000142)死亡」;spawn.js注释同样写明 "hidden-console children die with STATUS_DLL_INIT_FAILED (0xC0000142) — verified empirically"。0xC0000142/0xE0434352);README 与测试均未提及powershell.exe/ Windows PowerShell 5.1。.NET Framework 的 5.1 在早期初始化上触发了这条受限令牌边界。期望行为 / Expected
winget install --id Microsoft.PowerShell;Windows PowerShell 5.1 兜底在沙箱下不可用」),而不是静默崩溃0xC0000142;建议修复 / Suggested fixes
resolvePwshPath回退到 5.1 且沙箱启用时,检测并抛出清晰的错误(可复用SandboxUnavailableError的呈现路径);附加信息 / Additional
Write-Output即崩);C:\Program Files\PowerShell\7\pwsh.exe,沙箱验证过的路径);补充证据:微软商店版(MSIX)pwsh 同样不可用(两条路径都失败)
调查中先安装了商店版 PowerShell 7(MSIX,经
C:\Users\<user>\AppData\Local\Microsoft\WindowsApps\pwsh.exe执行别名运行)。实测该版本无法作为 DSH 的 pwsh 使用,无论沙箱开关:Error: spawn ...\WindowsApps\pwsh.exe ENOENT—— DSH 宿主(Node/libuv)无法 spawn Windows 商店执行别名(reparse point);用户自己的终端可正常执行(cmd/Explorer 走系统 CreateProcess 解析)。windows-acl-run: CreateProcessAsUserW failed (Win32 2),同样无法解析/启动该别名。(附带观察:解析器命中商店版后,工具错误从「静默 0xC0000142」变为「runner 失败 + 提示切换 danger-full-access」,信息量改善,但结论不变。)
阶段性结论:Windows 上 DSH 的 pwsh 工具最可靠的路径是 MSI 版 PowerShell 7(
C:\Program Files\PowerShell\7\pwsh.exe真实 exe);5.1 兜底在沙箱下0xC0000142崩溃成立;商店版在包注册损坏时不可用(ENOENT / Win32 2),winget --force重装修复注册后可正常使用(见「验证结果」)。建议:winget install --id Microsoft.PowerShell --source winget --force」);验证结果 / Resolution(2026-08-15 实测)
winget install --id Microsoft.PowerShell --source winget --force成功(重装/修复了商店包注册)后,pwsh 工具完全恢复可用:PSVersion=7.6.4,PSHOME=C:\Program Files\WindowsApps\Microsoft.PowerShell_7.6.4.0_x64__8wekyb3d8bbwerun_in_background后台任务全部正常(exit 0)注意:本次验证在
danger-full-access(无沙箱)策略下进行。「PowerShell 7 + workspace-write 沙箱」组合在桌面应用环境下未验证——若用户恢复沙箱后 pwsh 7 仍报0xC0000142,说明该控制台/DLL 初始化边界对桌面壳(无控制台宿主)是普适的,本报告需按此升级(标题与根因将改为「任何 PowerShell 在桌面壳 + 受限令牌下 DLL 初始化失败」)。All reactions