Windows sandbox helper: exit code 259 after a slow terminate, .git restore, Started ordering, env sort
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 52/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- rust, typescript
- Domain
- desktop
Research direction
Start in native/sandbox-helper/src/win.rs, especially the cited sections around lines 552–588, 708, 842–895, 1337–1383, 1608–1617, and 2025–2063. Read the Windows sandbox process, permissions, and environment handling around each item, then run the relevant sandbox-helper tests on Windows. Done means all five listed behaviors are corrected and covered by tests.
Written by the indexing model from the issue text.
Description
Found in the 2026-10-07 code review (read).
Problems
- Exit code 259: after
TerminateJobObject, the result ofWaitForSingleObject(process, 5000)isn't checked (native/sandbox-helper/src/win.rs:2052-2063). A process that hasn't exited yet is reported with exit codeSTILL_ACTIVE(259), andreader.join()can block until it lets go of its pipe. .gitrestore:ProtectedPath::restorealways usesUNPROTECTED_DACL_SECURITY_INFORMATION(win.rs:552-588). This is correct only becauseoriginal_inheritancerecords only unprotected paths (win.rs:1337-1383). If a snapshot is reused fromowners(win.rs:1608-1617) after the user deliberately protected.gitbetween runs, restoring undoes the user's change.Startedordering:Startedis sent after the reader threads start and afterResumeThread(win.rs:2025-2036), so output can arrive before it. Nothing breaks today, but the comment describes a strict order.- Environment sort:
environment_blocksorts names withto_uppercase. Windows expects an ordinal, case-insensitive order on UTF-16 code units. - Capability case: the capability name uses Unicode
to_lowercase(win.rs:708), while the marker comparison useseq_ignore_ascii_case(win.rs:842-895). Projects with non-ASCII paths therefore propagate their grant again on every run.
Fix
- Check the wait result, and report
timed_out/-1when the process hasn't exited. - Store the original DACL control flags in
ProtectedPathand restore with the matching flag. - Send
StartedbeforeResumeThread. - Sort with
CompareStringOrdinal(..., TRUE)semantics. - Compare markers with the same Unicode lowercasing used to derive the capability.
- Dominant language
- TypeScript
- Stars
- 2
- Forks
- 2
- Avg merge
- 5h 28m
- Merged PRs (30d)
- 24
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from PierrunoYT/patch
-
enhancement platform: windows priority: low severity: low
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
PierrunoYT/patch#198 ·
Maintainers usually reply within 1 day
-
priority: medium security severity: low
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
PierrunoYT/patch#66 ·
Maintainers usually reply within 1 day
-
bug platform: macos priority: low severity: low tests
Difficulty 3/5 1-2 days Newbie friendliness 56/100
PierrunoYT/patch#218 · 1 comment ·
Maintainers usually reply within 1 day
-
enhancement priority: low security severity: low
Difficulty 4/5 3-5 days Newbie friendliness 55/100
PierrunoYT/patch#211 · 2 comments ·
Maintainers usually reply within 1 day
-
enhancement platform: windows priority: low security severity: low
Difficulty 4/5 3-5 days Newbie friendliness 55/100
PierrunoYT/patch#207 ·
Maintainers usually reply within 1 day
All issues in PierrunoYT/patch
Similar issues
-
Difficulty 1/5 1-3 hours Newbie friendliness 84/100
Maintainers usually reply within 1 day
-
core
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
vectorize-io/hindsight#5457 ·
Maintainers usually reply within 1 day
-
beginner friendly community contributions-welcome good first issue hacktoberfest help wanted testing up-for-grabs
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 85/100
lukilabs/beautiful-mermaid#160 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 66/100
rescript-lang/rescript-lang.org#1420 ·
Maintainers usually reply within 2 days