You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Bug report: workspace-write sandbox fails with
SetNamedSecurityInfoW failed (Win32 5)after update (grantWrite requires WRITE_OWNER)环境(脱敏)
workspace-write,审批askD:\<workspace>(NTFS,根目录继承自盘根的Authenticated Users: Modify级 ACE,无用户 FullControl 显式 ACE)症状
更新后,workspace-write 模式下任何命令都在沙箱授权阶段失败,命令体从未执行:
Win32 5 = ERROR_ACCESS_DENIED。切换权限预设到
danger-full-access后立即恢复正常(跳过授权环节),可佐证故障点在沙箱运行器的 ACL 授权一步。根因分析
本次更新后,
@deepseek-ai/dsh-sandbox-windows-acl的grantWrite从「仅写 DACL」(SECURITY_INFORMATION = 4)变为「DACL + Low 强制完整性标签一次写入」(= 20,同一次SetNamedSecurityInfoW同时补 world SID 的FILE_DELETE_CHILDdeny 与 Low label)。写 SACL/label 要求调用方持有WRITE_OWNER,而 owner 隐式权利只有READ_CONTROL+WRITE_DAC(模块源码注释亦写明:"The directory must be owned by the caller AND grant WRITE_OWNER … a Full-control workspace satisfies both")。常见的工作区目录(用户自建、仅继承
Authenticated Users: Modify)恰好不满足该前提 →SetNamedSecurityInfoW返回 Win32 5,且发生在授权阶段,导致该工作区内所有命令不可用。旧版仅写 DACL(owner 隐式有WRITE_DAC),因此更新前无感。叠加的第二层问题(同一报错的另一种触发路径)
工作区内若存在管理员权限进程创建的子目录(owner =
BUILTIN\Administrators,且 DACL/SACL 保护位打开、脱离继承),它拿不到工作区能力 SID(S-1-4-*)的继承 ACE,也没有 Low label。此时grantWrite已正常通过,但受限令牌(WRITE_RESTRICTED 双通道检查 + 完整性检查)写该子目录时得到EPERM,GUI 报[sandbox: file access denied under workspace-write mode]——与第一层报错文本不同,但用户同样难以自行定位。复现步骤
Authenticated Users: Modify级权限(无用户显式 FullControl / 无WRITE_OWNER)。workspace-write预设运行任意命令。SetNamedSecurityInfoW failed (Win32 5): grantWrite(<workspace>)。有效权限可用
Get-Acl/AccessCheck 验证:owner 为当前用户、WRITE_DAC=true、WRITE_OWNER=false。当前 workaround
danger-full-access(仅建议用于确认根因,不建议长期使用)。改进建议(对 dsh-runtime)
grantWrite在应用前 AccessCheck 检测WRITE_OWNER缺失时,抛出携带明确修复指引的错误(如「工作区目录需当前用户 FullControl;见 XXX 文档」),而不是裸抛 Win32 5。当前错误文本无法与权限修复路径关联,用户(和 agent)只能全靠排查。WRITE_OWNER,可提示或引导一次修复(或文档化「工作区根需 Full Control」为硬性要求)。icacls /setintegritylevel (OI)(CI)Low在 PowerShell 中必须给参数加引号,值得写进排查文档。附:与另一已知故障的区分
dsh文档已记录过另一类「pwsh 空输出、退出码恒 0、无副作用」的 win32 运行器故障(切danger-full-access可恢复)。本次故障同样可通过切预设缓解,但报错文本(SetNamedSecurityInfoW failed (Win32 5): grantWrite(...))不同、根因不同,建议归档为独立 issue。All reactions