Writing simple files to workspace is difficult and by-passes security #3936
Replies: 3 comments
|
Those files landed on Do not approve Keep |
|
I will have to slightly disagree, from what I saw the file paths looked like normal file paths, either with forward or backward slashes, maybe both were tried, maybe AI model got confused, I also tried relative paths, none of these seemed to work, leading to privelage escalation which is weird. I suspect it might be a parsing error inside deepseek harness for different types of slashes/etc. Also notice how the trajectory is hard to paste/hard to read. Perhaps add some new lines or include them as well, so it becomes more readable or is this not possible for some reason ? Very hard to see the actual file paths that were being supplied, so there is a copy & paste problems ? File paths are getting cut off .... |
|
你贴的 trajectory 里有一条很关键的证据,可能改变这个问题的归属:
工作区路径是明确告诉了模型的,就在每轮的运行时上下文里。而文件最后落在了 这一点很重要,因为它决定该修什么:
从你的证据看是后者。验证办法很简单:给它一次明确的绝对路径("把文件写到 关于 "by-passes security"你说得对,但因果链是这样的:模型请求提权 → 你批准了 → 提权后沙箱不再限制 → 于是它编出来的路径也能写成功。在 所以最直接的缓解是:这类任务不要批准提权。写工作区内的文件本来就不需要 full access——模型之所以去要,很可能是它先写错了地方被拦,然后把"被拦"理解成"权限不够",而不是"路径不对"。这个误判在 DSH 社区是一族已知现象(#1069 / #201 / #4412 讲的是这个 换一个更强的模型试一次,也能很快区分是模型问题还是 harness 问题——这不是敷衍,是因为你现在这份证据指向的正是模型侧。 利益相关:我维护 pi2dsh,这条回复里没有任何要你装的东西。 |
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Step 1. Workspace added:
G:\Junk\test deepseek harness
Step 2. setup ollama
Step 3. load qwen ai model
Step 4. chat with it to write some basic files.
End result is bad:
g:\sandbox\helloworld.pas
written
second test:
g:\workspace\test.txt
written
On windows 11.
In both cases privilege/full access was asked and given, AI fails to understand how to write files to workspace and instead asks privilege escalation leading to files being written in the wrong folders...
Here is the trajectory:
All reactions