Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Windows sandbox: first permission propagation in a large project can exceed other helpers' 60 s lock timeout

Aperta
#176 1 commento 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
48/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
typescript
Ambito
desktop, security

Direzione di ricerca

Start with the Windows permission and lock code in win.rs: inspect ensure_project_grant (lines 867-885), revoke_project (887-907), and PermissionLock::acquire (1149-1165), along with the measurements from #103. Determine how to avoid helpers timing out during propagation while preserving crash safety; done when the large-project scenario no longer causes lock-acquisition failures and the error message explains ongoing propagation.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

bug platform: windows priority: medium severity: medium

Found in the 2026-10-07 code review (inferred from #103's measurements and the lock scopes; not reproduced).

Problem

ensure_project_grant (win.rs:867-885) spreads FILE_MODIFY across the whole project tree while holding the global Local\PatchSandboxPermissions mutex. PermissionLock::acquire (win.rs:1149-1165) waits only 60 s. Every helper start also takes that lock (recover_abandoned_runs), and so does revoke_project (win.rs:887-907). #103 measured 23.4 s per 100,000 files, so a project of roughly 260,000 files or more exceeds the timeout.

Scenario

  1. The agent starts npm run dev in the background in a large monorepo.
  2. The tool returns after 3 s while the helper is still propagating.
  3. The agent's next run_command fails after a minute with "cannot acquire sandbox permission lock".
  4. Closing the project during propagation makes all 5 revoke attempts fail, so the grant is kept.

Fix

Hold a per-project lock (a named mutex derived from the capability name) during propagation instead of the global one; the marker file already handles crash safety. Or wait without a limit while the lock holder is alive (WAIT_ABANDONED covers its death). Make the error message say that propagation is in progress.

Lingua principale
TypeScript
Stelle
2
Fork
2
Merge medio
5h 28m
PR unite (30g)
24

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di PierrunoYT/patch

Tutte le issue di PierrunoYT/patch

Issue simili

Altre issue su TypeScript

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.