Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Windows sandbox helper: exit code 259 after a slow terminate, .git restore, Started ordering, env sort

Open
#195 1 comment 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
52/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
rust, typescript
Domain
desktop

Research direction

Start in native/sandbox-helper/src/win.rs, especially the cited sections around lines 552–588, 708, 842–895, 1337–1383, 1608–1617, and 2025–2063. Read the Windows sandbox process, permissions, and environment handling around each item, then run the relevant sandbox-helper tests on Windows. Done means all five listed behaviors are corrected and covered by tests.

Written by the indexing model from the issue text.

Description

bug platform: windows priority: low severity: low

Found in the 2026-10-07 code review (read).

Problems

  • Exit code 259: after TerminateJobObject, the result of WaitForSingleObject(process, 5000) isn't checked (native/sandbox-helper/src/win.rs:2052-2063). A process that hasn't exited yet is reported with exit code STILL_ACTIVE (259), and reader.join() can block until it lets go of its pipe.
  • .git restore: ProtectedPath::restore always uses UNPROTECTED_DACL_SECURITY_INFORMATION (win.rs:552-588). This is correct only because original_inheritance records only unprotected paths (win.rs:1337-1383). If a snapshot is reused from owners (win.rs:1608-1617) after the user deliberately protected .git between runs, restoring undoes the user's change.
  • Started ordering: Started is sent after the reader threads start and after ResumeThread (win.rs:2025-2036), so output can arrive before it. Nothing breaks today, but the comment describes a strict order.
  • Environment sort: environment_block sorts names with to_uppercase. Windows expects an ordinal, case-insensitive order on UTF-16 code units.
  • Capability case: the capability name uses Unicode to_lowercase (win.rs:708), while the marker comparison uses eq_ignore_ascii_case (win.rs:842-895). Projects with non-ASCII paths therefore propagate their grant again on every run.

Fix

  • Check the wait result, and report timed_out/-1 when the process hasn't exited.
  • Store the original DACL control flags in ProtectedPath and restore with the matching flag.
  • Send Started before ResumeThread.
  • Sort with CompareStringOrdinal(..., TRUE) semantics.
  • Compare markers with the same Unicode lowercasing used to derive the capability.
Dominant language
TypeScript
Stars
2
Forks
2
Avg merge
5h 28m
Merged PRs (30d)
24

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from PierrunoYT/patch

All issues in PierrunoYT/patch

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.