Replies: 1 comment
|
The diagnosis in your report is right, and it is the case the package documents as a boundary rather than as a bug — the workspace sits outside the user profile and inherits its access from the volume root ("Authenticated Users: Modify",
For the shape failing closed at session start, so every command including - insert:
- id: sandbox-grant-advisor
name: '@argszero/cordis-plugin-sandbox-grant-advisor' |
Uh oh!
There was an error while loading. Please reload this page.
Windows 上,如果工作区不在用户配置目录里(比如
D:\save),而且它的权限是从卷根继承来的——权限列表里没有当前用户本人,只通过Authenticated Users组拿到「修改」——一开会话就报:SetNamedSecurityInfoW failed (Win32 5): grantWrite(D:\save)
因为是 fail-closed,这个会话里所有 shell 命令都跑不了,连
whoami都不行,而报错里没有任何提示告诉用户该怎么办。原因:沙箱要给工作区目录打一个 Low 完整性标签,标签存在 SACL 里,写它需要
WRITE_OWNER;而「所有者」身份只隐含READ_CONTROL和WRITE_DAC,不含这一项,于是整次调用一起失败。对照:同一台机器、同一版本、同一个模式,工作区放在
C:\Users\<用户>\下(用户有 Full Control)就一切正常,连开 3 个会话都没问题。手动补一条权限后授权阶段即通过(不需要提权):icacls "D:\save" /grant "<用户>:(OI)(CI)(WO)"
环境:0.2.0-rc.2 桌面版,Windows 11 10.0.26100,本地非管理员账户,
workspace-write。All reactions