Repository navigation
Windows desktop: a dsh-plugin that makes workspace-write confined shells start (fixes 0xC0000142) #9282
Replies: 2 comments
|
The diagnosis here matches a rule a published diagnostic asset already carries, which may help anyone who hits this failure on a build where the bundle is not installed.
Both are reported against the session's mode × host combination rather than as an intermittent failure, with the console-owning alternative named — so a Package: https://www.npmjs.com/package/@argszero/cordis-plugin-sandbox-grant-advisor — mount it on a profile and the matching It is an advisor only: it never changes the spawn, so it composes with a runner-side fix like the one in this thread instead of competing with it. |
Also fixed: the diagnostic env var no longer writes any file, a missing shim is no longer preloaded (it used to break every sandboxed command), the post-merge check now walks the token Default DACL, and the handle/SID/ACL leaks are released. If you installed |
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
What it is
A small Host-only bundle for the Windows desktop app. It fixes the failure where every confined shell
call under
workspace-writedies instantly with0xC0000142(STATUS_DLL_INIT_FAILED).Repo: https://github.com/TJZF-4j97/dsh-sandbox-console-fix (topic:
dsh-plugin)Report and evidence: #9280
Why it happens
dsh-sandbox-localspawns the Windows ACL sandbox runner as[process.execPath, runner.js]. In thepackaged app
process.execPathis the Electron binary — a GUI-subsystem image with no console. Therunner spawns the confined child without a console-isolation flag on purpose (a
CREATE_NO_WINDOW/CREATE_NEW_CONSOLEchild dies under the restricted token), so the child is expectedto inherit the runner's console. Nothing to inherit means the console-subsystem child creates its own
console, that creation fails in
workspace-write, and the process dies.read-onlyhappens to survive,which is why only
workspace-writelooks broken.What the plugin does
It subclasses
LocalSandboxProviderand changes exactly one thing: the ACL runner argv gains--import <console-shim>in front of the runner entry — the same argument shape dsh's own developmentrunner path already uses — so the runner process calls
AllocConsole()once at startup.Nothing else moves: the restricted token, write-restricted SIDs, Low integrity label, ACL grants and
denies, Job object, stdio plumbing, environment and the fs policy are inherited unchanged.
Install
The bundle declares no dependencies — dsh-shipped packages resolve from the dsh installation — so it
installs without downloads and without build-script approvals:
https://github.com/TJZF-4j97/dsh-sandbox-console-fix(or point it at a local checkout directory).
workspace-writeand run any shell command.Verified
Windows 11 22H2 x64, desktop
0.2.0-rc.2(Electron 44.0.0 / Node 24.18.1), installed through dsh's owninstall_bundle(Packages: +1, zero downloads, no pending build scripts) and after a restart:workspace-writeshell call returnspwsh 7.6.6instead of0xC0000142— the identical call failsbefore the bundle exists;
%USERPROFILE%,C:\Windows\Temp, the user temp dir — includingdeleting files there) are denied, and the files are absent afterwards.
Verification record, failure matrix and everything that was ruled out:
https://github.com/TJZF-4j97/dsh-bug-windows-sandbox-console
If dsh ships any of the fixes suggested in the report above, this bundle becomes unnecessary.
Positioning (added)
This bundle is a workaround, not the structural fix. Since 0.2.0 it merges
Everyoneinto the runner process token's Default DACL before the runner derives the restricted token — restoring exactly what the shippedread-onlypath already does — and keeps giving the runner a console as an automatic fallback. Measured: the child starts inworkspace-writeon the packaged desktop host; writes outside the workspace stay denied and absent; the child's own console stays hidden. The structural fix belongs upstream (one line; source patch attached in #9038 / #8775): routing index #9195, cross-check #9280.All reactions