Windows sandbox: one PATH folder whose permissions can't be read breaks every later helper start
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 52/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- rust, typescript
Research direction
Read win.rs around RecoveryRecord::undo (1216–1290), recover_abandoned_runs (1293–1335), and the grant logic (1588–1594, 1688–1708). Start by running the Rust tests for sandbox recovery; the issue requests a test where one failed undo does not prevent other records from recovering. Done means access-denied revocation is handled safely and recovery continues per record, quarantining records after repeated failures.
Written by the indexing model from the issue text.
Description
Found in the 2026-10-07 code review (traced through the code; not reproduced with a real folder that denies reading its permissions). Related to #152, which has a different trigger.
Problem
runrecords every existingread_onlypath inrecord.grantedbefore granting, and ignores grant failures for non-required paths (win.rs:1588-1594,1688-1708).RecoveryRecord::undo(win.rs:1216-1290) callsedit_acl(path, sid, 0, Revoke)for each one. That starts withGetNamedSecurityInfoWand returnsErrwhen the permissions can't be read.- The record is kept, and
DeleteAppContainerProfileis skipped. On the next start,recover_abandoned_runs(win.rs:1293-1335) hits the same error,servesendsError{id:null}, and the helper exits.
Scenario
PATH contains a folder that exists but whose permissions the user can't read (for example an admin's tool folder added machine-wide, or a restricted share). After the first sandboxed command, every sandboxed command fails with "cannot read the permissions of X". This lasts until the user deletes the record under %LOCALAPPDATA%\Patch\sandbox-recovery by hand.
Fix
- When revoking, treat
ERROR_ACCESS_DENIEDfromGetNamedSecurityInfoWas "nothing to undo". Without READ_CONTROL/WRITE_DAC the grant could never have been applied. - Recover each record on its own: log a failure, keep going with the other records, and quarantine a record after N failed attempts instead of aborting the helper.
- Rust test: one record whose undo fails, with the other records still recovered.
- Dominant language
- TypeScript
- Stars
- 2
- Forks
- 2
- Avg merge
- 5h 52m
- Merged PRs (30d)
- 18
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from PierrunoYT/patch
-
enhancement priority: low security severity: low
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
PierrunoYT/patch#208 ·
Maintainers usually reply within 1 day
-
enhancement platform: windows priority: low severity: low
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
PierrunoYT/patch#198 ·
Maintainers usually reply within 1 day
-
bug priority: low severity: low
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
PierrunoYT/patch#190 ·
Maintainers usually reply within 1 day
-
Unbounded waits: revokeProjectGrant has no timeout, and timed-out browser waiters are never removedOpenbug priority: low severity: low
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
PierrunoYT/patch#188 ·
Maintainers usually reply within 1 day
-
bug priority: medium severity: low
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
PierrunoYT/patch#179 ·
Maintainers usually reply within 1 day
All issues in PierrunoYT/patch
Similar issues
-
Tenant
Difficulty 2/5 1-3 hours Newbie friendliness 66/100
MTES-MCT/Dossier-Facile-Frontend#2061 ·
Maintainers usually reply within 1 day
-
area:frontend
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
interledger/publisher-tools#905 ·
Maintainers usually reply within 1 day
-
Add: Cbeebies PL SDOpenapproved check:passed streams:add
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
iptv-org/iptv#54525 · 1 comment ·
Maintainers usually reply within 1 day
-
DB-plane provider_chat_options.* is accepted by config set but never merged into the loaded configPossibly taken A pull request linked to this issue is open or already merged. Open
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
area:web
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
praetorianer777/GoTome#178 ·
Maintainers usually reply within 1 day