windows-acl sandbox: cached private temp dir is never re-validated — one external delete permanently bricks the sandbox mid-session #6801
UncleBright
started this conversation in
General
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Environment
@deepseek-ai/dsh0.1.5-rc.1@deepseek-ai/dsh-sandbox-local0.1.5-rc.2@deepseek-ai/dsh-sandbox-windows-acl0.1.5-rc.2workspace-writeSummary
dsh-sandbox-localcreates one private temp dir per[sessionId, workspaceRoot]and caches it.On a cache hit it returns the cached path without checking that the directory still exists.
dsh-sandbox-windows-acl's runner requires--tempto exist, so once that directory is deletedby anything outside DSH, every subsequent command in the session fails — and the session
never recovers on its own.
Symptom
Error: sandbox mode "workspace-write" is requested but no sandbox backend is usable on this host; refusing to run the command unconfined. ... Runner failure: windows-acl-run: --temp is not an existing directory: C:\Users\AppData\Local\Temp\dsh-XXXXXX
The identical error (same dir name) recurs for every later command until the
session/provider is recreated.
Root cause
packages/sandbox/sandbox-local/lib/index.js(materializeAclGrant):All reactions