Repository navigation
Windows:ACL 诊断/修复技能会奖励「模型不用 DSH 文件工具、改用命令行」的错误路径,在沙箱正常拒绝时触发主动提权与自制工具 #9361
Replies: 4 comments
|
The safest fix is to make the tool-choice boundary explicit before changing ACLs. A normal workspace-write denial for an out-of-workspace path or a read-only target is an expected confinement result, not evidence that the Windows ACL is broken. I would change the flow in three places:
This preserves the useful repair workflow for genuine host failures while preventing a tool-selection mistake from escalating privileges or leaving probe files. If this matches the intended behavior, could you please click GitHub’s Mark as answer on this reply? |
|
Source-verified follow-up on the mechanism, and a precise answer to which of your five suggestions a plugin can actually reach. Your citations hold at HEAD, checked line by line.
The text already draws the line you are asking for; the problem is where it asks the model to draw it. The frontmatter description ends with "Expected confinement denials need no ACL repair", and the "Run it" section enumerates the expected categories: "writes outside the workspace, any write in Which of your suggestions a plugin can reach (against the actual seams).
Where I would place the boundary inside such a plugin. The denial is the decision point, so an advisory attached to the denial result is the natural place — but I would keep it an annotation and not suppress the escalation affordance, because an out-of-workspace read is precisely what escalation exists for. What must not happen is a repair run or a probe file. So the notice would carry the triage in order: this is a confinement policy result under mode X and not evidence that the host is broken; if If that ordering matches your intent, I will build it and test it against one of your anonymized transcripts — the report's step-by-step record is exactly the fixture such a plugin needs. |
|
The source check strengthens the boundary: the bundled skill is registered from |
|
Thanks for checking the current source and confirming the exact registration and plugin seams. That supports the proposed split: classify expected confinement denials in the tool result, gate escalation before dispatch, and reserve ACL diagnosis for a reproducible in-workspace failure. The two regression fixtures you described should preserve that distinction. If this gives the maintainer the needed direction, please mark the original answer as answered. |
Uh oh!
There was an error while loading. Please reload this page.
摘要
在 Windows 上,模型本来就更倾向于用
Bash/PowerShell工具去列目录、找文件,而不是用 DSH 自带的glob/read/grep。这不是 ACL 技能引起的,但自v0.2.0-rc.1引入、并在v0.2.1-alpha.2合并为「一次调用同时诊断并修复」的diagnose-windows-sandbox-acl技能,会把这条错误路径的后果进一步放大:当模型用命令行做本该由 DSH 文件工具完成的事、并被沙箱正常拒绝时,技能目录里常驻的 ACL 诊断技能会让模型把「预期内的拒绝」误判成「需要修复的环境故障」,进而
而正确的行为本应是:改用 DSH 文件工具,或把预期拒绝直接解释给用户。结果是模型既没有回到 DSH 工具,又额外动了文件系统和权限。
影响
workspace-write下最普通的越界写入拒绝(本应直接解释)尤其容易误触发。复现路径
环境:Windows + 内置 Windows runner(未配置
runnerCommand),文件策略workspace-write。Get-ChildItem -Force,而不是glob。diagnose-windows-sandbox-acl。glob/read/grep——而它们本来可以正常完成同一件事。关键点:第 2 步就是错的(DSH 提示词本就要求用文件工具而非 shell),而技能的存在让第 3 步之后的走向从「改正」变成了「升级权限 + 造工具」。
触发机制(源码定位)
sandbox-local在内置 Windows runner 下自动注册为常驻技能目录条目:packages/sandbox/sandbox-local/src/index.ts第 301–303 行packages/sandbox/sandbox-windows-acl/src/acl-skill.ts(提取SKILL.md与脚本到临时目录,modelInvocable: true, userInvocable: true)。packages/sandbox/sandbox-windows-acl/assets/diagnose-windows-sandbox-acl/SKILL.md。也就是说,只要有内置 Windows runner,这个技能就始终出现在技能目录里,与是否真的发生故障无关。
版本证据
dsh-v0.1.6-alpha.2packages/sandbox/sandbox-windows-acl/assets/diagnose-windows-sandbox-acl/SKILL.md返回 404dsh-v0.2.0-rc.1v0.1.7-rc.2以来的变更)。此时是分步流程:先纯诊断拿到CULPRIT/PRECONDITION/BOTH判定,再单独用-Fix或-GrantFullControl发起第二次修复dsh-v0.2.1-alpha.2(当前)这个合并是放大效应的重要一步:分步设计下,模型至少要先做一次不改任何东西的纯诊断;合并后,一次调用就直接走到「改权限」,从「看到拒绝」到「申请提权」之间少了一道天然缓冲。
建议
glob/read/grep。如果能在工具层强化或强制这一点,整条放大链会自动消失。read-only下写入」这类预期类别时,不向模型展示该技能,或在工具结果里直接标注「这是预期拒绝,不要修复」。技能正文其实已经写了这条(Expected confinement denials need no ACL repair),但它依赖模型先正确分类——而这恰是失败的一环。glob/read/grep可替代的操作,先改用该工具,不得因此申请提权或创建诊断脚本/探针文件」。补充:实例记录
以下记录来自一次真实会话,已做匿名化(不涉及用户内容):
Get-ChildItem -Force(DSH 提示词明确要求此类操作用glob,此处是错误)。skill加载diagnose-windows-sandbox-acl。.ps1、缺少pwsh而未真正执行,第三次被用户拒绝)。glob+read;而它们本可以完成同样的事,且不会触发任何权限问题。需要说明的是:第 2 步是判断失误,技能本身并不「命令」做这些。但要强调的是——技能的存在把一次本可即时纠正的小失误,导向了提权申请与文件系统改动。如果没有这个常驻技能,在第 3 步最自然的反应就是换用 DSH 文件工具。
All reactions