You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
sandbox-windows-acl: 0.1.5 → 0.1.7-rc.2 Windows enforcement regression — confined child lands in ConstrainedLanguage, granted writes DENIED; 14 suite failures on the same machine and on a pristine official tree
#8219
Defect C — sandbox-windows-acl Windows enforcement regression: 0.1.5-generation suite fully green → 0.1.7-rc.2 14 failures on the same machine (restricted child processes fall to ConstrainedLanguage; every granted write/read probe DENIED); reproduces on the pristine official tree
Reported: 2026-09-29 by a downstream consumer team.
Prepared 2026-09-29 by ops from verified campaign evidence: DEBT-ledger.md §B1 (authoritative ledger), P2-progress.md REVIEW-SYNC-P2 修正3, P3-compat-diagnosis.md §3.1–3.3/§7 (all in this campaign directory). Items marked [ops re-verified 2026-09-29] were independently re-checked (git commands / log line reads) during report preparation; items marked [evidence from retained campaign logs, not re-run] cite on-disk logs without re-executing the test runs.
Title (issue/discussion-ready)
sandbox-windows-acl: 0.1.5 → 0.1.7-rc.2 Windows enforcement regression — confined child lands in ConstrainedLanguage, granted writes DENIED; 14 suite failures on the same machine and on a pristine official tree
Version affected
Verified failing:dsh-v0.1.7-rc.2 (tag 477b4f4205) — on (a) our downstream merged tree, which has zero diff to packages/sandbox/sandbox-windows-acl since the merge-base, and (b) a pristine official checkout (detached worktree at the tag + pnpm install --frozen-lockfile, unbuilt).
Verified green (same machine, 0.1.5 generation): our pre-sync base f30e0da8df era — full-suite log shows runner.spec.ts 14/14 passed and probe.spec.ts 3/3 passed (Evidence 1); and the 2026-09-27 campaign full green round: 21879 tests / 0 failed on the 0.1.5-rc.2 downstream baseline, established after OS update KB5129195 (2026-09-16) [evidence from campaign record 2026-09-27-upgrade-process-v2/CAMPAIGN-STATE.md].
Not tested by us:dsh-v0.2.0-rc.1 (published 2026-09-28T12:36:21Z) and current master. We note post-rc.2 upstream activity on this package (Evidence 8) and ask maintainers to confirm whether the signature below is addressed there; we can re-test on request.
Environment (failing runs)
Windows 10.0.26200 (Insider), x64; Node v24.19.0; pnpm 11.7.0.
Host PowerShell = FullLanguage. Machine policy state checked clean: Smart App Control VerifiedAndReputablePolicyState=0; __PSLockdownPolicy not set; WDAC CodeIntegrityPolicyEnforcementStatus=2 (kernel CI/HVCI on), UsermodeCodeIntegrity=0.
OS updates installed at both the green 0.1.5 baseline and the red 0.1.7 runs: KB5129195 (2026-09-16), KB5126052 (2026-09-11), KB5124007 (2026-09-09) → same OS build across the regression window.
Honesty note on Node versions: the retained 0.1.5-era full-suite log (Evidence 1) was produced under Node v22.16.0; the 2026-09-27 green round (21879/0F) ran during a campaign window in which our machine records show Node v24.19.0 (indirect evidence, A2-baseline.md:5); the 0.1.7-rc.2 red runs are Node v24.19.0. The pristine-official-tree reproduction (Evidence 3) is Node v24.19.0. We did not run a 0.1.5 tree under Node 24 as a dedicated control; the failure mode (restricted pwsh/node child processes, Windows token/ACL layer) is not obviously Node-major-dependent, but we disclose the difference rather than claim a controlled constant.
Summary
On the same physical machine, the sandbox-windows-acl functional suite went from fully green (0.1.5 generation: runner.spec 14 tests, probe.spec 3 tests) to 14 failures on 0.1.7-rc.2 (runner.spec 13 of 19 failed; probe.spec 1 of 3 failed). Between the merge-base and the rc.2 tag, upstream rewrote this package substantially (22 files changed, +1767/−319), while our fork carries zero diff to it. The failure signature is uniform across every functional case that spawns a real restricted child process:
the confined pwsh child reports LANGMODE: ConstrainedLanguage (tests assert FullLanguage; the host pwsh is FullLanguage);
all capability probes inside the child return DENIED — TARGET-WRITE, TEMP-WRITE, ESCAPE-WRITE, SECRET-READ, CIM — i.e. granted writes do not materialize and the workspace-write policy effectively degrades to read-only semantics.
Unit-level suites that do not spawn real restricted children (acl / grant / token / ffi / workspace-sid / path-boundary / failure-paths) all pass, so the authorization data plane looks correct; the break is in the enforcement path (restricted token × ACE × Low integrity label × MIC interaction) on this OS build. The same signature makes the official workflow-ptc "Session file policy workspace-write" test fail deterministically on the pristine official tree (companion report, Evidence 7).
Reproduction
Pristine official tree, isolated worktree (does not touch any downstream working tree):
git worktree add --detach <path>/acl-repro 477b4f4205 # tag dsh-v0.1.7-rc.2
cd <path>/acl-repro
pnpm install --frozen-lockfile # pnpm 11.7.0
pnpm exec vitest run packages/sandbox/sandbox-windows-acl
# Observed: Test Files 2 failed | 11 passed (13)
# Tests 14 failed | 150 passed (164)
Representative failure output (verbatim, ANSI stripped) — runner.spec.ts first failure:
FAIL packages/sandbox/sandbox-windows-acl/tests/probe.spec.ts > AclSandbox write restriction > allows writes only in granted directories and denies the escape write
AssertionError: child output:
TARGET-WRITE: DENIED
TEMP-WRITE: DENIED
ESCAPE-WRITE: DENIED
SECRET-READ: DENIED
: expected 'TARGET-WRITE: DENIED\r\nTEMP-WRITE: D…' to contain 'TARGET-WRITE: OK'
❯ packages/sandbox/sandbox-windows-acl/tests/probe.spec.ts:85:48
Evidence
0.1.5-generation green baseline, same machine — retained full-suite log G:\000Github\zDSH\zDSH-docs\TMP\vitest-full.log: line 1160 ✓ packages/sandbox/sandbox-windows-acl/tests/runner.spec.ts (14 tests) 10534ms with per-test green lines (e.g. "workspace-write: the confined child writes granted directories only ✓ 772ms"); line 2670 ✓ packages/sandbox/sandbox-windows-acl/tests/probe.spec.ts (3 tests) 728ms. [ops re-verified 2026-09-29 by direct log read] Additionally, the 2026-09-27 campaign recorded a 21879 tests / 0 failed full green round on the 0.1.5-rc.2 baseline, after KB5129195 was installed [evidence from campaign record].
0.1.7-rc.2 red on our merged tree — retained full-suite log G:\000Github\DSH\TMP\sync-p2-vitest-final.log: line 149 ❯ packages/sandbox/sandbox-windows-acl/tests/runner.spec.ts (19 tests | 13 failed) 18712ms; line 20 ❯ .../probe.spec.ts (3 tests | 1 failed) 842ms; verbatim failure blocks quoted in Reproduction (log lines 8487–8539). [ops re-verified 2026-09-29 by direct log read]
Pristine official tree reproduces — G:\000Github\zDSH\zDSH-wt\diag-acl-suite.log (detached worktree at tag 477b4f4205, frozen install, unbuilt, no downstream code present): Test Files 2 failed | 11 passed (13); Tests 14 failed | 150 passed (164). [ops re-verified 2026-09-29 by direct log read; run itself not repeated] This excludes fork-side code as the cause.
The failing assertion is unchanged across versions — tests/runner.spec.ts:100 reads expect(result.stdout).toContain('LANGMODE: FullLanguage') identically at f30e0da8df (0.1.5 base) and 477b4f4205 (rc.2) [ops re-verified 2026-09-29 via git show]. The suite grew from 14 to 19 runner tests (upstream added cases); the regression claim rests on the same assertions flipping green→red, and on the whole functional-child-process family failing.
Cross-package impact — on the same pristine official tree, packages/workflow/workflow-ptc/tests/source-runtime.compat.spec.ts "enforces the Session file policy workspace-write" fails deterministically with ENOENT ... workspace/inside.txt (authorized write never materializes) — full mechanism chain in our companion report (defect-f). [evidence from retained log diag-ptc-official-unbuilt.log; ops re-verified key lines 2026-09-29]
Suspect change window — upstream commits touching this package between merge-base and rc.2 include d5ad3baeb5 "fix(sandbox): confine Windows deletes with a Low integrity label", 36e632751e "fix(sandbox): deny the ambient parent-delete right inside granted roots", 3d5ba3b83f "fix(sandbox): scope the delete deny to containers", b35a3b29eb "fix(sandbox): pin ACL source resolution and recognize Node denials", among test/refactor commits [ops re-verified 2026-09-29 via git log c291e79..477b4f4]. Post-rc.2 master shows an active windows-acl workstream (1d56bd5628 diagnosis skill for ACL denials, 927b59e138, b876f825c7, 5bab07157f, d2d755077b, 99b887a177, shipped in dsh-v0.2.0-rc.1) [live GitHub API check 2026-09-29] — we have not tested whether these resolve the signature on our machine.
Expected: as asserted by the package's own tests and as observed on this machine with the 0.1.5 generation — a confined child process runs with a WRITE_RESTRICTED token yet keeps FullLanguage mode; granted directories are writable (TARGET-WRITE: OK, TEMP-WRITE: OK), escape writes and secret reads stay denied, CIM query works.
Actual: on 0.1.7-rc.2 the confined child lands in ConstrainedLanguage and every probe — including the ones that must succeed under a workspace-write grant — returns DENIED. The grant/authorization data plane still passes its unit tests; only real restricted-child-process enforcement fails, for both pwsh and node children.
Suggested fix direction
We do not claim a specific root cause — the exact broken Win32 link (Low integrity label vs. ACE materialization vs. restricting-SID/MIC interaction on build 26200) was not forensically isolated on our side (honest limitation). We suggest:
Investigate the interaction of the delete-confinement rework (d5ad3baeb5, 36e632751e, 3d5ba3b83f) with Windows Insider build 26200; the uniform ConstrainedLanguage + all-DENIED signature suggests the restricted/WriteRestricted token now triggers an OS lockdown evaluation that it did not in the 0.1.5 code path (our hypothesis, confidence: medium).
Confirm whether the post-rc.2 windows-sandbox-acl-diagnosis workstream already addresses this signature; if it does, a note here would help downstreams pinning rc.2.
Consider a Windows CI lane that runs the functional restricted-child-process assertions (from our reading of ci.yml, the node-compat matrix is ubuntu-only and the Windows lanes are build/coverage-oriented — inference from static reading, confidence: medium).
We are willing to run the new diagnosis skill / collect additional traces (Process Monitor, token dumps) on request.
Workaround (downstream)
None possible on the package itself (zero-diff surface for us). We record the 14 failures as platform-conditional red in our downstream test ledger (excluded from our regression gate, tracked per-release), and plan to re-verify against dsh-v0.2.0-rc.1.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Defect C —
sandbox-windows-aclWindows enforcement regression: 0.1.5-generation suite fully green → 0.1.7-rc.2 14 failures on the same machine (restricted child processes fall to ConstrainedLanguage; every granted write/read probe DENIED); reproduces on the pristine official treeTitle (issue/discussion-ready)
sandbox-windows-acl: 0.1.5 → 0.1.7-rc.2 Windows enforcement regression — confined child lands in ConstrainedLanguage, granted writes DENIED; 14 suite failures on the same machine and on a pristine official treeVersion affected
dsh-v0.1.7-rc.2(tag477b4f4205) — on (a) our downstream merged tree, which has zero diff topackages/sandbox/sandbox-windows-aclsince the merge-base, and (b) a pristine official checkout (detached worktree at the tag +pnpm install --frozen-lockfile, unbuilt).f30e0da8dfera — full-suite log showsrunner.spec.ts14/14 passed andprobe.spec.ts3/3 passed (Evidence 1); and the 2026-09-27 campaign full green round: 21879 tests / 0 failed on the 0.1.5-rc.2 downstream baseline, established after OS update KB5129195 (2026-09-16) [evidence from campaign record2026-09-27-upgrade-process-v2/CAMPAIGN-STATE.md].dsh-v0.2.0-rc.1(published 2026-09-28T12:36:21Z) and current master. We note post-rc.2 upstream activity on this package (Evidence 8) and ask maintainers to confirm whether the signature below is addressed there; we can re-test on request.Environment (failing runs)
VerifiedAndReputablePolicyState=0;__PSLockdownPolicynot set; WDACCodeIntegrityPolicyEnforcementStatus=2(kernel CI/HVCI on),UsermodeCodeIntegrity=0.A2-baseline.md:5); the 0.1.7-rc.2 red runs are Node v24.19.0. The pristine-official-tree reproduction (Evidence 3) is Node v24.19.0. We did not run a 0.1.5 tree under Node 24 as a dedicated control; the failure mode (restricted pwsh/node child processes, Windows token/ACL layer) is not obviously Node-major-dependent, but we disclose the difference rather than claim a controlled constant.Summary
On the same physical machine, the
sandbox-windows-aclfunctional suite went from fully green (0.1.5 generation: runner.spec 14 tests, probe.spec 3 tests) to 14 failures on 0.1.7-rc.2 (runner.spec 13 of 19 failed; probe.spec 1 of 3 failed). Between the merge-base and the rc.2 tag, upstream rewrote this package substantially (22 files changed, +1767/−319), while our fork carries zero diff to it. The failure signature is uniform across every functional case that spawns a real restricted child process:LANGMODE: ConstrainedLanguage(tests assertFullLanguage; the host pwsh is FullLanguage);DENIED—TARGET-WRITE,TEMP-WRITE,ESCAPE-WRITE,SECRET-READ,CIM— i.e. granted writes do not materialize and the workspace-write policy effectively degrades to read-only semantics.Unit-level suites that do not spawn real restricted children (acl / grant / token / ffi / workspace-sid / path-boundary / failure-paths) all pass, so the authorization data plane looks correct; the break is in the enforcement path (restricted token × ACE × Low integrity label × MIC interaction) on this OS build. The same signature makes the official
workflow-ptc"Session file policy workspace-write" test fail deterministically on the pristine official tree (companion report, Evidence 7).Reproduction
Pristine official tree, isolated worktree (does not touch any downstream working tree):
Representative failure output (verbatim, ANSI stripped) —
runner.spec.tsfirst failure:and
probe.spec.ts:Evidence
G:\000Github\zDSH\zDSH-docs\TMP\vitest-full.log: line 1160✓ packages/sandbox/sandbox-windows-acl/tests/runner.spec.ts (14 tests) 10534mswith per-test green lines (e.g. "workspace-write: the confined child writes granted directories only ✓ 772ms"); line 2670✓ packages/sandbox/sandbox-windows-acl/tests/probe.spec.ts (3 tests) 728ms. [ops re-verified 2026-09-29 by direct log read] Additionally, the 2026-09-27 campaign recorded a 21879 tests / 0 failed full green round on the 0.1.5-rc.2 baseline, after KB5129195 was installed [evidence from campaign record].G:\000Github\DSH\TMP\sync-p2-vitest-final.log: line 149❯ packages/sandbox/sandbox-windows-acl/tests/runner.spec.ts (19 tests | 13 failed) 18712ms; line 20❯ .../probe.spec.ts (3 tests | 1 failed) 842ms; verbatim failure blocks quoted in Reproduction (log lines 8487–8539). [ops re-verified 2026-09-29 by direct log read]G:\000Github\zDSH\zDSH-wt\diag-acl-suite.log(detached worktree at tag477b4f4205, frozen install, unbuilt, no downstream code present):Test Files 2 failed | 11 passed (13);Tests 14 failed | 150 passed (164). [ops re-verified 2026-09-29 by direct log read; run itself not repeated] This excludes fork-side code as the cause.git diff --stat c291e7961a 477b4f4205 -- packages/sandbox/sandbox-windows-acl→ 22 files changed, 1767 insertions(+), 319 deletions(-). [ops re-verified 2026-09-29]git diff c291e7961a f30e0da8df -- packages/sandbox/sandbox-windows-acl→ 0 lines (merge-base to our pre-sync HEAD). [ops re-verified 2026-09-29]tests/runner.spec.ts:100readsexpect(result.stdout).toContain('LANGMODE: FullLanguage')identically atf30e0da8df(0.1.5 base) and477b4f4205(rc.2) [ops re-verified 2026-09-29 via git show]. The suite grew from 14 to 19 runner tests (upstream added cases); the regression claim rests on the same assertions flipping green→red, and on the whole functional-child-process family failing.packages/workflow/workflow-ptc/tests/source-runtime.compat.spec.ts"enforces the Session file policy workspace-write" fails deterministically withENOENT ... workspace/inside.txt(authorized write never materializes) — full mechanism chain in our companion report (defect-f). [evidence from retained logdiag-ptc-official-unbuilt.log; ops re-verified key lines 2026-09-29]d5ad3baeb5"fix(sandbox): confine Windows deletes with a Low integrity label",36e632751e"fix(sandbox): deny the ambient parent-delete right inside granted roots",3d5ba3b83f"fix(sandbox): scope the delete deny to containers",b35a3b29eb"fix(sandbox): pin ACL source resolution and recognize Node denials", among test/refactor commits [ops re-verified 2026-09-29 via git log c291e79..477b4f4]. Post-rc.2 master shows an active windows-acl workstream (1d56bd5628diagnosis skill for ACL denials,927b59e138,b876f825c7,5bab07157f,d2d755077b,99b887a177, shipped indsh-v0.2.0-rc.1) [live GitHub API check 2026-09-29] — we have not tested whether these resolve the signature on our machine.P0-campaign-card.md§4.1; [Bug][Windows][0.1.7-rc.2] 写会话投影缓存时 V8 FATAL(Isolate::PushStackTraceAndDie null prototype chain root),Host exit 134 并自动重启 #8011 existence live-verified 2026-09-29].Related upstream threads (checked live 2026-09-29 — all distinct signatures, listed to aid triage)
SetNamedSecurityInfoWWin32 5 atgrantWritewhen the workspace DACL lacks WRITE_OWNER; data-drive volume; fail-closed: no child ever spawns; thread confirms the Low-label write is new in 0.1.7-alpha.1 and still reproduces on rc.2), [Bug] Windows: `windows-acl` rung is auto-selected without a probe, but its host-side write grant always fails without SeSecurityPrivilege #7622 (SACL label write needs SeSecurityPrivilege for non-elevated hosts), workspace-write sandbox fails entirely on Windows when the workspace grants no WRITE_OWNER (SetNamedSecurityInfoW error 5) #7816, [Bug Report] Windows: workspace ACL with Modify-only (no WRITE_OWNER) makes the ACL sandbox fail at init, disabling all shell tools #7720, [Bug] Windows:工作区位于非系统盘时 ACL 沙箱必然初始化失败(Win32 5 / grantWrite)/ ACL sandbox fails on non-system drives: the default ACL grants the caller no WRITE_OWNER #7804. Ours differs: grant/init succeeds (children do spawn and produce output); the failure is enforcement-side — granted writes denied and child pwsh in ConstrainedLanguage; our workspace roots are on the system drive under the user profile; unit-level grant/ACE suites pass on our machine.Expected vs Actual
TARGET-WRITE: OK,TEMP-WRITE: OK), escape writes and secret reads stay denied, CIM query works.ConstrainedLanguageand every probe — including the ones that must succeed under a workspace-write grant — returnsDENIED. The grant/authorization data plane still passes its unit tests; only real restricted-child-process enforcement fails, for both pwsh and node children.Suggested fix direction
We do not claim a specific root cause — the exact broken Win32 link (Low integrity label vs. ACE materialization vs. restricting-SID/MIC interaction on build 26200) was not forensically isolated on our side (honest limitation). We suggest:
d5ad3baeb5,36e632751e,3d5ba3b83f) with Windows Insider build 26200; the uniformConstrainedLanguage+ all-DENIED signature suggests the restricted/WriteRestricted token now triggers an OS lockdown evaluation that it did not in the 0.1.5 code path (our hypothesis, confidence: medium).windows-sandbox-acl-diagnosisworkstream already addresses this signature; if it does, a note here would help downstreams pinning rc.2.ci.yml, the node-compat matrix is ubuntu-only and the Windows lanes are build/coverage-oriented — inference from static reading, confidence: medium).We are willing to run the new diagnosis skill / collect additional traces (Process Monitor, token dumps) on request.
Workaround (downstream)
None possible on the package itself (zero-diff surface for us). We record the 14 failures as platform-conditional red in our downstream test ledger (excluded from our regression gate, tracked per-release), and plan to re-verify against
dsh-v0.2.0-rc.1.All reactions