feat(sandbox): Windows ACL write-restriction sandbox (restricted-token runner)
Confine Windows command execution through a WRITE_RESTRICTED token whose restricting SIDs carry an orphan-SID write allowlist, ported from https://github.com/huoyaoyuan/windows-acl-restrict-poc (@ 10e4dfb). Every Win32 call is checked and fails closed - the POC silently ran children with the FULL token when CreateRestrictedToken failed.
- @deepseek-ai/dsh-sandbox-windows-acl: koffi primitives verified against the MinGW Windows headers (verify/abi-probe.cpp) plus the confinement runner ([node, runner, --workspace, --temp, --mode, --, argv...]: kill-on-close job, stdio passthrough, exit-code mirroring, windows-acl-run: failure signature, grant revocation). read-only = strict zero grants (NUL device not writable; documented). Windows-only execution: exempted from the Linux coverage lane (windowsOnlyCoverageExclusions).
- @deepseek-ai/dsh-sandbox-local: PLATFORM_CHAINS.win32 filled with the windows-acl runner (full enforcement, ACL denial dialect, runner-failure rules).
- @deepseek-ai/dsh-pwsh-sandbox: sandbox-consuming pwsh executor (call-for-call mirror of dsh-bash-sandbox) over a new argv-level seam in dsh-pwsh-local; per-file coverage complete via the fake-provider spec.
- bundle/base: the Windows platform layer mounts the confined pwsh roster - sandbox/policy/fs-sandbox/permission/approval re-enabled, the POSIX bash stack stays disabled.
Co-authored-by: Huo Yaoyuan <huoyaoyuan@hotmail.com>
2026-08-08 01:24:33 +08:00
/ * *
* End - to - end runner tests : spawn the REAL runner entry through tsx ( exactly
* the argv shape dsh - sandbox - local ' s confine ( ) builds ) , with piped stdio
* inherited through the runner into the confined child — the same chain a
* production confined execution walks .
* /
import { spawnSync } from 'node:child_process'
import { existsSync , mkdirSync , mkdtempSync , rmSync , writeFileSync } from 'node:fs'
import { tmpdir } from 'node:os'
import { join } from 'node:path'
import { fileURLToPath } from 'node:url'
import { afterAll , beforeAll , describe , expect , it } from 'vitest'
2026-08-08 14:32:01 +08:00
import { resolvePwshPath } from '@deepseek-ai/dsh-pwsh-local'
2026-08-08 17:29:43 +08:00
import { AclWriteGrant } from '../src/index.ts'
2026-08-08 14:32:01 +08:00
feat(sandbox): Windows ACL write-restriction sandbox (restricted-token runner)
Confine Windows command execution through a WRITE_RESTRICTED token whose restricting SIDs carry an orphan-SID write allowlist, ported from https://github.com/huoyaoyuan/windows-acl-restrict-poc (@ 10e4dfb). Every Win32 call is checked and fails closed - the POC silently ran children with the FULL token when CreateRestrictedToken failed.
- @deepseek-ai/dsh-sandbox-windows-acl: koffi primitives verified against the MinGW Windows headers (verify/abi-probe.cpp) plus the confinement runner ([node, runner, --workspace, --temp, --mode, --, argv...]: kill-on-close job, stdio passthrough, exit-code mirroring, windows-acl-run: failure signature, grant revocation). read-only = strict zero grants (NUL device not writable; documented). Windows-only execution: exempted from the Linux coverage lane (windowsOnlyCoverageExclusions).
- @deepseek-ai/dsh-sandbox-local: PLATFORM_CHAINS.win32 filled with the windows-acl runner (full enforcement, ACL denial dialect, runner-failure rules).
- @deepseek-ai/dsh-pwsh-sandbox: sandbox-consuming pwsh executor (call-for-call mirror of dsh-bash-sandbox) over a new argv-level seam in dsh-pwsh-local; per-file coverage complete via the fake-provider spec.
- bundle/base: the Windows platform layer mounts the confined pwsh roster - sandbox/policy/fs-sandbox/permission/approval re-enabled, the POSIX bash stack stays disabled.
Co-authored-by: Huo Yaoyuan <huoyaoyuan@hotmail.com>
2026-08-08 01:24:33 +08:00
const isWin32 = process . platform === 'win32'
const runnerEntry = fileURLToPath ( new URL ( '../src/runner.ts' , import . meta . url ) )
2026-08-08 14:32:01 +08:00
// Functional probe, not where.exe: spawnSync never throws on a missing
// binary (status null) and where.exe exits 1 without pwsh — only an actual
// pwsh invocation's exit status is truth.
feat(sandbox): Windows ACL write-restriction sandbox (restricted-token runner)
Confine Windows command execution through a WRITE_RESTRICTED token whose restricting SIDs carry an orphan-SID write allowlist, ported from https://github.com/huoyaoyuan/windows-acl-restrict-poc (@ 10e4dfb). Every Win32 call is checked and fails closed - the POC silently ran children with the FULL token when CreateRestrictedToken failed.
- @deepseek-ai/dsh-sandbox-windows-acl: koffi primitives verified against the MinGW Windows headers (verify/abi-probe.cpp) plus the confinement runner ([node, runner, --workspace, --temp, --mode, --, argv...]: kill-on-close job, stdio passthrough, exit-code mirroring, windows-acl-run: failure signature, grant revocation). read-only = strict zero grants (NUL device not writable; documented). Windows-only execution: exempted from the Linux coverage lane (windowsOnlyCoverageExclusions).
- @deepseek-ai/dsh-sandbox-local: PLATFORM_CHAINS.win32 filled with the windows-acl runner (full enforcement, ACL denial dialect, runner-failure rules).
- @deepseek-ai/dsh-pwsh-sandbox: sandbox-consuming pwsh executor (call-for-call mirror of dsh-bash-sandbox) over a new argv-level seam in dsh-pwsh-local; per-file coverage complete via the fake-provider spec.
- bundle/base: the Windows platform layer mounts the confined pwsh roster - sandbox/policy/fs-sandbox/permission/approval re-enabled, the POSIX bash stack stays disabled.
Co-authored-by: Huo Yaoyuan <huoyaoyuan@hotmail.com>
2026-08-08 01:24:33 +08:00
function pwshAvailable ( ) : boolean {
2026-08-08 14:32:01 +08:00
return spawnSync ( resolvePwshPath ( ) , [ '-NoLogo' , '-NoProfile' , '-NonInteractive' , '-Command' , '$true' ] , { encoding : 'utf8' } ) . status === 0
feat(sandbox): Windows ACL write-restriction sandbox (restricted-token runner)
Confine Windows command execution through a WRITE_RESTRICTED token whose restricting SIDs carry an orphan-SID write allowlist, ported from https://github.com/huoyaoyuan/windows-acl-restrict-poc (@ 10e4dfb). Every Win32 call is checked and fails closed - the POC silently ran children with the FULL token when CreateRestrictedToken failed.
- @deepseek-ai/dsh-sandbox-windows-acl: koffi primitives verified against the MinGW Windows headers (verify/abi-probe.cpp) plus the confinement runner ([node, runner, --workspace, --temp, --mode, --, argv...]: kill-on-close job, stdio passthrough, exit-code mirroring, windows-acl-run: failure signature, grant revocation). read-only = strict zero grants (NUL device not writable; documented). Windows-only execution: exempted from the Linux coverage lane (windowsOnlyCoverageExclusions).
- @deepseek-ai/dsh-sandbox-local: PLATFORM_CHAINS.win32 filled with the windows-acl runner (full enforcement, ACL denial dialect, runner-failure rules).
- @deepseek-ai/dsh-pwsh-sandbox: sandbox-consuming pwsh executor (call-for-call mirror of dsh-bash-sandbox) over a new argv-level seam in dsh-pwsh-local; per-file coverage complete via the fake-provider spec.
- bundle/base: the Windows platform layer mounts the confined pwsh roster - sandbox/policy/fs-sandbox/permission/approval re-enabled, the POSIX bash stack stays disabled.
Co-authored-by: Huo Yaoyuan <huoyaoyuan@hotmail.com>
2026-08-08 01:24:33 +08:00
}
function runRunner ( args : string [ ] , timeoutMs = 30 _000 ) {
return spawnSync ( process . execPath , [ '--import' , 'tsx/esm' , runnerEntry , . . . args ] , {
timeout : timeoutMs ,
encoding : 'utf8' ,
} )
}
describe . skipIf ( ! isWin32 || ! pwshAvailable ( ) ) ( 'windows-acl runner' , ( ) = > {
let scratchRoot ! : string
let writableDir ! : string
let isolatedTemp ! : string
let secretFile ! : string
let escapeFile ! : string
2026-08-08 21:55:02 +08:00
// The ambient-writable probe target: a subdirectory of C:\Users\Public.
// INTERACTIVE/LOCAL are absent from BOTH restricting lists, so the Public
// tree's INTERACTIVE grant must NOT satisfy the write check — the ambient
// boundary the dual-list design closes (bot-reported blind spot). The
// Public tree may be unavailable or unwritable for the test user on some
// hosts; the probe test skips itself when the directory cannot be created.
let publicProbeDir : string | undefined
feat(sandbox): Windows ACL write-restriction sandbox (restricted-token runner)
Confine Windows command execution through a WRITE_RESTRICTED token whose restricting SIDs carry an orphan-SID write allowlist, ported from https://github.com/huoyaoyuan/windows-acl-restrict-poc (@ 10e4dfb). Every Win32 call is checked and fails closed - the POC silently ran children with the FULL token when CreateRestrictedToken failed.
- @deepseek-ai/dsh-sandbox-windows-acl: koffi primitives verified against the MinGW Windows headers (verify/abi-probe.cpp) plus the confinement runner ([node, runner, --workspace, --temp, --mode, --, argv...]: kill-on-close job, stdio passthrough, exit-code mirroring, windows-acl-run: failure signature, grant revocation). read-only = strict zero grants (NUL device not writable; documented). Windows-only execution: exempted from the Linux coverage lane (windowsOnlyCoverageExclusions).
- @deepseek-ai/dsh-sandbox-local: PLATFORM_CHAINS.win32 filled with the windows-acl runner (full enforcement, ACL denial dialect, runner-failure rules).
- @deepseek-ai/dsh-pwsh-sandbox: sandbox-consuming pwsh executor (call-for-call mirror of dsh-bash-sandbox) over a new argv-level seam in dsh-pwsh-local; per-file coverage complete via the fake-provider spec.
- bundle/base: the Windows platform layer mounts the confined pwsh roster - sandbox/policy/fs-sandbox/permission/approval re-enabled, the POSIX bash stack stays disabled.
Co-authored-by: Huo Yaoyuan <huoyaoyuan@hotmail.com>
2026-08-08 01:24:33 +08:00
beforeAll ( ( ) = > {
scratchRoot = mkdtempSync ( join ( tmpdir ( ) , 'dsh-acl-runner-' ) )
writableDir = join ( scratchRoot , 'writable' )
mkdirSync ( writableDir )
isolatedTemp = mkdtempSync ( join ( tmpdir ( ) , 'dsh-acl-runner-temp-' ) )
secretFile = join ( scratchRoot , 'secret.txt' )
writeFileSync ( secretFile , 'top secret - must stay readable to prove the read boundary' )
escapeFile = join ( scratchRoot , 'escaped.txt' )
2026-08-08 21:55:02 +08:00
try {
publicProbeDir = mkdtempSync ( join ( process . env . PUBLIC ? ? 'C:\\Users\\Public' , 'dsh-acl-public-' ) )
} catch {
publicProbeDir = undefined
}
feat(sandbox): Windows ACL write-restriction sandbox (restricted-token runner)
Confine Windows command execution through a WRITE_RESTRICTED token whose restricting SIDs carry an orphan-SID write allowlist, ported from https://github.com/huoyaoyuan/windows-acl-restrict-poc (@ 10e4dfb). Every Win32 call is checked and fails closed - the POC silently ran children with the FULL token when CreateRestrictedToken failed.
- @deepseek-ai/dsh-sandbox-windows-acl: koffi primitives verified against the MinGW Windows headers (verify/abi-probe.cpp) plus the confinement runner ([node, runner, --workspace, --temp, --mode, --, argv...]: kill-on-close job, stdio passthrough, exit-code mirroring, windows-acl-run: failure signature, grant revocation). read-only = strict zero grants (NUL device not writable; documented). Windows-only execution: exempted from the Linux coverage lane (windowsOnlyCoverageExclusions).
- @deepseek-ai/dsh-sandbox-local: PLATFORM_CHAINS.win32 filled with the windows-acl runner (full enforcement, ACL denial dialect, runner-failure rules).
- @deepseek-ai/dsh-pwsh-sandbox: sandbox-consuming pwsh executor (call-for-call mirror of dsh-bash-sandbox) over a new argv-level seam in dsh-pwsh-local; per-file coverage complete via the fake-provider spec.
- bundle/base: the Windows platform layer mounts the confined pwsh roster - sandbox/policy/fs-sandbox/permission/approval re-enabled, the POSIX bash stack stays disabled.
Co-authored-by: Huo Yaoyuan <huoyaoyuan@hotmail.com>
2026-08-08 01:24:33 +08:00
} )
afterAll ( ( ) = > {
rmSync ( scratchRoot , { recursive : true , force : true } )
rmSync ( isolatedTemp , { recursive : true , force : true } )
2026-08-08 21:55:02 +08:00
if ( publicProbeDir !== undefined ) rmSync ( publicProbeDir , { recursive : true , force : true } )
feat(sandbox): Windows ACL write-restriction sandbox (restricted-token runner)
Confine Windows command execution through a WRITE_RESTRICTED token whose restricting SIDs carry an orphan-SID write allowlist, ported from https://github.com/huoyaoyuan/windows-acl-restrict-poc (@ 10e4dfb). Every Win32 call is checked and fails closed - the POC silently ran children with the FULL token when CreateRestrictedToken failed.
- @deepseek-ai/dsh-sandbox-windows-acl: koffi primitives verified against the MinGW Windows headers (verify/abi-probe.cpp) plus the confinement runner ([node, runner, --workspace, --temp, --mode, --, argv...]: kill-on-close job, stdio passthrough, exit-code mirroring, windows-acl-run: failure signature, grant revocation). read-only = strict zero grants (NUL device not writable; documented). Windows-only execution: exempted from the Linux coverage lane (windowsOnlyCoverageExclusions).
- @deepseek-ai/dsh-sandbox-local: PLATFORM_CHAINS.win32 filled with the windows-acl runner (full enforcement, ACL denial dialect, runner-failure rules).
- @deepseek-ai/dsh-pwsh-sandbox: sandbox-consuming pwsh executor (call-for-call mirror of dsh-bash-sandbox) over a new argv-level seam in dsh-pwsh-local; per-file coverage complete via the fake-provider spec.
- bundle/base: the Windows platform layer mounts the confined pwsh roster - sandbox/policy/fs-sandbox/permission/approval re-enabled, the POSIX bash stack stays disabled.
Co-authored-by: Huo Yaoyuan <huoyaoyuan@hotmail.com>
2026-08-08 01:24:33 +08:00
} )
it ( 'workspace-write: the confined child writes granted directories only' , ( ) = > {
const probe = [
"$ErrorActionPreference='SilentlyContinue';" ,
2026-08-08 20:11:01 +08:00
// The restricted token puts pwsh into ConstrainedLanguage in BOTH modes
// (documented Known Limitation) — pinned here so a token change that
// silently restores FullLanguage is caught.
'\'LANGMODE: \' + $ExecutionContext.SessionState.LanguageMode;' ,
feat(sandbox): Windows ACL write-restriction sandbox (restricted-token runner)
Confine Windows command execution through a WRITE_RESTRICTED token whose restricting SIDs carry an orphan-SID write allowlist, ported from https://github.com/huoyaoyuan/windows-acl-restrict-poc (@ 10e4dfb). Every Win32 call is checked and fails closed - the POC silently ran children with the FULL token when CreateRestrictedToken failed.
- @deepseek-ai/dsh-sandbox-windows-acl: koffi primitives verified against the MinGW Windows headers (verify/abi-probe.cpp) plus the confinement runner ([node, runner, --workspace, --temp, --mode, --, argv...]: kill-on-close job, stdio passthrough, exit-code mirroring, windows-acl-run: failure signature, grant revocation). read-only = strict zero grants (NUL device not writable; documented). Windows-only execution: exempted from the Linux coverage lane (windowsOnlyCoverageExclusions).
- @deepseek-ai/dsh-sandbox-local: PLATFORM_CHAINS.win32 filled with the windows-acl runner (full enforcement, ACL denial dialect, runner-failure rules).
- @deepseek-ai/dsh-pwsh-sandbox: sandbox-consuming pwsh executor (call-for-call mirror of dsh-bash-sandbox) over a new argv-level seam in dsh-pwsh-local; per-file coverage complete via the fake-provider spec.
- bundle/base: the Windows platform layer mounts the confined pwsh roster - sandbox/policy/fs-sandbox/permission/approval re-enabled, the POSIX bash stack stays disabled.
Co-authored-by: Huo Yaoyuan <huoyaoyuan@hotmail.com>
2026-08-08 01:24:33 +08:00
` try{Set-Content -Path ' ${ writableDir } \\ child-wrote.txt' -Value ok -ErrorAction Stop;'TARGET-WRITE: OK'}catch{'TARGET-WRITE: DENIED'}; ` ,
` try{Set-Content -Path ' ${ isolatedTemp } \\ child-wrote.txt' -Value ok -ErrorAction Stop;'TEMP-WRITE: OK'}catch{'TEMP-WRITE: DENIED'}; ` ,
` try{Set-Content -Path ' ${ escapeFile } ' -Value ok -ErrorAction Stop;'ESCAPE-WRITE: OK (ESCAPE!)'}catch{'ESCAPE-WRITE: DENIED'}; ` ,
2026-08-08 17:29:43 +08:00
` try{Get-Content ' ${ secretFile } ' -ErrorAction Stop | Out-Null;'SECRET-READ: OK'}catch{'SECRET-READ: DENIED'}; ` ,
2026-08-08 21:55:02 +08:00
// Authenticated Users is absent from BOTH lists: the WMI namespace
// security check fails (0x80041003) — CIM is unavailable under every
// confined mode (the documented contract; the C:\-root tree-creation
// escape is closed in both as the other side of the trade).
2026-08-08 17:29:43 +08:00
"try{Get-CimInstance Win32_OperatingSystem -ErrorAction Stop | Out-Null;'CIM: OK'}catch{'CIM: DENIED'}" ,
feat(sandbox): Windows ACL write-restriction sandbox (restricted-token runner)
Confine Windows command execution through a WRITE_RESTRICTED token whose restricting SIDs carry an orphan-SID write allowlist, ported from https://github.com/huoyaoyuan/windows-acl-restrict-poc (@ 10e4dfb). Every Win32 call is checked and fails closed - the POC silently ran children with the FULL token when CreateRestrictedToken failed.
- @deepseek-ai/dsh-sandbox-windows-acl: koffi primitives verified against the MinGW Windows headers (verify/abi-probe.cpp) plus the confinement runner ([node, runner, --workspace, --temp, --mode, --, argv...]: kill-on-close job, stdio passthrough, exit-code mirroring, windows-acl-run: failure signature, grant revocation). read-only = strict zero grants (NUL device not writable; documented). Windows-only execution: exempted from the Linux coverage lane (windowsOnlyCoverageExclusions).
- @deepseek-ai/dsh-sandbox-local: PLATFORM_CHAINS.win32 filled with the windows-acl runner (full enforcement, ACL denial dialect, runner-failure rules).
- @deepseek-ai/dsh-pwsh-sandbox: sandbox-consuming pwsh executor (call-for-call mirror of dsh-bash-sandbox) over a new argv-level seam in dsh-pwsh-local; per-file coverage complete via the fake-provider spec.
- bundle/base: the Windows platform layer mounts the confined pwsh roster - sandbox/policy/fs-sandbox/permission/approval re-enabled, the POSIX bash stack stays disabled.
Co-authored-by: Huo Yaoyuan <huoyaoyuan@hotmail.com>
2026-08-08 01:24:33 +08:00
] . join ( '' )
const result = runRunner ( [
'--workspace' , writableDir , '--temp' , isolatedTemp , '--mode' , 'workspace-write' ,
'--' , 'pwsh' , '/NoLogo' , '/NonInteractive' , '/NoProfile' , '/Command' , probe ,
] )
expect ( result . status , ` stderr: ${ result . stderr } ` ) . toBe ( 0 )
2026-08-08 20:11:01 +08:00
expect ( result . stdout ) . toContain ( 'LANGMODE: ConstrainedLanguage' )
feat(sandbox): Windows ACL write-restriction sandbox (restricted-token runner)
Confine Windows command execution through a WRITE_RESTRICTED token whose restricting SIDs carry an orphan-SID write allowlist, ported from https://github.com/huoyaoyuan/windows-acl-restrict-poc (@ 10e4dfb). Every Win32 call is checked and fails closed - the POC silently ran children with the FULL token when CreateRestrictedToken failed.
- @deepseek-ai/dsh-sandbox-windows-acl: koffi primitives verified against the MinGW Windows headers (verify/abi-probe.cpp) plus the confinement runner ([node, runner, --workspace, --temp, --mode, --, argv...]: kill-on-close job, stdio passthrough, exit-code mirroring, windows-acl-run: failure signature, grant revocation). read-only = strict zero grants (NUL device not writable; documented). Windows-only execution: exempted from the Linux coverage lane (windowsOnlyCoverageExclusions).
- @deepseek-ai/dsh-sandbox-local: PLATFORM_CHAINS.win32 filled with the windows-acl runner (full enforcement, ACL denial dialect, runner-failure rules).
- @deepseek-ai/dsh-pwsh-sandbox: sandbox-consuming pwsh executor (call-for-call mirror of dsh-bash-sandbox) over a new argv-level seam in dsh-pwsh-local; per-file coverage complete via the fake-provider spec.
- bundle/base: the Windows platform layer mounts the confined pwsh roster - sandbox/policy/fs-sandbox/permission/approval re-enabled, the POSIX bash stack stays disabled.
Co-authored-by: Huo Yaoyuan <huoyaoyuan@hotmail.com>
2026-08-08 01:24:33 +08:00
expect ( result . stdout ) . toContain ( 'TARGET-WRITE: OK' )
expect ( result . stdout ) . toContain ( 'TEMP-WRITE: OK' )
expect ( result . stdout ) . toContain ( 'ESCAPE-WRITE: DENIED' )
expect ( result . stdout ) . toContain ( 'SECRET-READ: OK' )
2026-08-08 21:55:02 +08:00
expect ( result . stdout ) . toContain ( 'CIM: DENIED' )
feat(sandbox): Windows ACL write-restriction sandbox (restricted-token runner)
Confine Windows command execution through a WRITE_RESTRICTED token whose restricting SIDs carry an orphan-SID write allowlist, ported from https://github.com/huoyaoyuan/windows-acl-restrict-poc (@ 10e4dfb). Every Win32 call is checked and fails closed - the POC silently ran children with the FULL token when CreateRestrictedToken failed.
- @deepseek-ai/dsh-sandbox-windows-acl: koffi primitives verified against the MinGW Windows headers (verify/abi-probe.cpp) plus the confinement runner ([node, runner, --workspace, --temp, --mode, --, argv...]: kill-on-close job, stdio passthrough, exit-code mirroring, windows-acl-run: failure signature, grant revocation). read-only = strict zero grants (NUL device not writable; documented). Windows-only execution: exempted from the Linux coverage lane (windowsOnlyCoverageExclusions).
- @deepseek-ai/dsh-sandbox-local: PLATFORM_CHAINS.win32 filled with the windows-acl runner (full enforcement, ACL denial dialect, runner-failure rules).
- @deepseek-ai/dsh-pwsh-sandbox: sandbox-consuming pwsh executor (call-for-call mirror of dsh-bash-sandbox) over a new argv-level seam in dsh-pwsh-local; per-file coverage complete via the fake-provider spec.
- bundle/base: the Windows platform layer mounts the confined pwsh roster - sandbox/policy/fs-sandbox/permission/approval re-enabled, the POSIX bash stack stays disabled.
Co-authored-by: Huo Yaoyuan <huoyaoyuan@hotmail.com>
2026-08-08 01:24:33 +08:00
expect ( existsSync ( escapeFile ) ) . toBe ( false )
expect ( existsSync ( join ( writableDir , 'child-wrote.txt' ) ) ) . toBe ( true )
} , 30 _000 )
2026-08-08 21:55:02 +08:00
it ( 'read-only: strict zero grants — no writes anywhere (not even NUL), reads and $null redirection fine, CIM unavailable' , ( ) = > {
feat(sandbox): Windows ACL write-restriction sandbox (restricted-token runner)
Confine Windows command execution through a WRITE_RESTRICTED token whose restricting SIDs carry an orphan-SID write allowlist, ported from https://github.com/huoyaoyuan/windows-acl-restrict-poc (@ 10e4dfb). Every Win32 call is checked and fails closed - the POC silently ran children with the FULL token when CreateRestrictedToken failed.
- @deepseek-ai/dsh-sandbox-windows-acl: koffi primitives verified against the MinGW Windows headers (verify/abi-probe.cpp) plus the confinement runner ([node, runner, --workspace, --temp, --mode, --, argv...]: kill-on-close job, stdio passthrough, exit-code mirroring, windows-acl-run: failure signature, grant revocation). read-only = strict zero grants (NUL device not writable; documented). Windows-only execution: exempted from the Linux coverage lane (windowsOnlyCoverageExclusions).
- @deepseek-ai/dsh-sandbox-local: PLATFORM_CHAINS.win32 filled with the windows-acl runner (full enforcement, ACL denial dialect, runner-failure rules).
- @deepseek-ai/dsh-pwsh-sandbox: sandbox-consuming pwsh executor (call-for-call mirror of dsh-bash-sandbox) over a new argv-level seam in dsh-pwsh-local; per-file coverage complete via the fake-provider spec.
- bundle/base: the Windows platform layer mounts the confined pwsh roster - sandbox/policy/fs-sandbox/permission/approval re-enabled, the POSIX bash stack stays disabled.
Co-authored-by: Huo Yaoyuan <huoyaoyuan@hotmail.com>
2026-08-08 01:24:33 +08:00
const probe = [
"$ErrorActionPreference='SilentlyContinue';" ,
'\'LANGMODE: \' + $ExecutionContext.SessionState.LanguageMode;' ,
` try{Set-Content -Path ' ${ writableDir } \\ readonly-child-wrote.txt' -Value ok -ErrorAction Stop;'TARGET-WRITE: OK'}catch{'TARGET-WRITE: DENIED'}; ` ,
` try{Set-Content -Path ' ${ isolatedTemp } \\ readonly-child-wrote.txt' -Value ok -ErrorAction Stop;'TEMP-WRITE: OK'}catch{'TEMP-WRITE: DENIED'}; ` ,
// The NUL device is a securable object: strict zero grants deny it too.
'try{Set-Content -Path \'NUL\' -Value ok -ErrorAction Stop;\'NUL-WRITE: OK\'}catch{\'NUL-WRITE: DENIED\'};' ,
// PowerShell's $null redirection discards without opening NUL — must keep working.
'echo hi > $null;\'DOLLAR-NULL: OK\';' ,
2026-08-08 17:29:43 +08:00
` try{Get-Content ' ${ secretFile } ' -ErrorAction Stop | Out-Null;'SECRET-READ: OK'}catch{'SECRET-READ: DENIED'}; ` ,
2026-08-08 21:55:02 +08:00
// BOTH lists drop Authenticated Users: the WMI namespace security
// check fails (0x80041003) — the documented CIM boundary of every
// confined mode, the price of the zero ambient-write surface.
2026-08-08 17:29:43 +08:00
"try{Get-CimInstance Win32_OperatingSystem -ErrorAction Stop | Out-Null;'CIM: OK'}catch{'CIM: DENIED'}" ,
feat(sandbox): Windows ACL write-restriction sandbox (restricted-token runner)
Confine Windows command execution through a WRITE_RESTRICTED token whose restricting SIDs carry an orphan-SID write allowlist, ported from https://github.com/huoyaoyuan/windows-acl-restrict-poc (@ 10e4dfb). Every Win32 call is checked and fails closed - the POC silently ran children with the FULL token when CreateRestrictedToken failed.
- @deepseek-ai/dsh-sandbox-windows-acl: koffi primitives verified against the MinGW Windows headers (verify/abi-probe.cpp) plus the confinement runner ([node, runner, --workspace, --temp, --mode, --, argv...]: kill-on-close job, stdio passthrough, exit-code mirroring, windows-acl-run: failure signature, grant revocation). read-only = strict zero grants (NUL device not writable; documented). Windows-only execution: exempted from the Linux coverage lane (windowsOnlyCoverageExclusions).
- @deepseek-ai/dsh-sandbox-local: PLATFORM_CHAINS.win32 filled with the windows-acl runner (full enforcement, ACL denial dialect, runner-failure rules).
- @deepseek-ai/dsh-pwsh-sandbox: sandbox-consuming pwsh executor (call-for-call mirror of dsh-bash-sandbox) over a new argv-level seam in dsh-pwsh-local; per-file coverage complete via the fake-provider spec.
- bundle/base: the Windows platform layer mounts the confined pwsh roster - sandbox/policy/fs-sandbox/permission/approval re-enabled, the POSIX bash stack stays disabled.
Co-authored-by: Huo Yaoyuan <huoyaoyuan@hotmail.com>
2026-08-08 01:24:33 +08:00
] . join ( '' )
const result = runRunner ( [
'--workspace' , writableDir , '--temp' , isolatedTemp , '--mode' , 'read-only' ,
'--' , 'pwsh' , '/NoLogo' , '/NonInteractive' , '/NoProfile' , '/Command' , probe ,
] )
expect ( result . status , ` stderr: ${ result . stderr } ` ) . toBe ( 0 )
2026-08-08 20:11:01 +08:00
expect ( result . stdout ) . toContain ( 'LANGMODE: ConstrainedLanguage' )
feat(sandbox): Windows ACL write-restriction sandbox (restricted-token runner)
Confine Windows command execution through a WRITE_RESTRICTED token whose restricting SIDs carry an orphan-SID write allowlist, ported from https://github.com/huoyaoyuan/windows-acl-restrict-poc (@ 10e4dfb). Every Win32 call is checked and fails closed - the POC silently ran children with the FULL token when CreateRestrictedToken failed.
- @deepseek-ai/dsh-sandbox-windows-acl: koffi primitives verified against the MinGW Windows headers (verify/abi-probe.cpp) plus the confinement runner ([node, runner, --workspace, --temp, --mode, --, argv...]: kill-on-close job, stdio passthrough, exit-code mirroring, windows-acl-run: failure signature, grant revocation). read-only = strict zero grants (NUL device not writable; documented). Windows-only execution: exempted from the Linux coverage lane (windowsOnlyCoverageExclusions).
- @deepseek-ai/dsh-sandbox-local: PLATFORM_CHAINS.win32 filled with the windows-acl runner (full enforcement, ACL denial dialect, runner-failure rules).
- @deepseek-ai/dsh-pwsh-sandbox: sandbox-consuming pwsh executor (call-for-call mirror of dsh-bash-sandbox) over a new argv-level seam in dsh-pwsh-local; per-file coverage complete via the fake-provider spec.
- bundle/base: the Windows platform layer mounts the confined pwsh roster - sandbox/policy/fs-sandbox/permission/approval re-enabled, the POSIX bash stack stays disabled.
Co-authored-by: Huo Yaoyuan <huoyaoyuan@hotmail.com>
2026-08-08 01:24:33 +08:00
expect ( result . stdout ) . toContain ( 'TARGET-WRITE: DENIED' )
expect ( result . stdout ) . toContain ( 'TEMP-WRITE: DENIED' )
expect ( result . stdout ) . toContain ( 'NUL-WRITE: DENIED' )
expect ( result . stdout ) . toContain ( 'DOLLAR-NULL: OK' )
expect ( result . stdout ) . toContain ( 'SECRET-READ: OK' )
2026-08-08 17:29:43 +08:00
expect ( result . stdout ) . toContain ( 'CIM: DENIED' )
feat(sandbox): Windows ACL write-restriction sandbox (restricted-token runner)
Confine Windows command execution through a WRITE_RESTRICTED token whose restricting SIDs carry an orphan-SID write allowlist, ported from https://github.com/huoyaoyuan/windows-acl-restrict-poc (@ 10e4dfb). Every Win32 call is checked and fails closed - the POC silently ran children with the FULL token when CreateRestrictedToken failed.
- @deepseek-ai/dsh-sandbox-windows-acl: koffi primitives verified against the MinGW Windows headers (verify/abi-probe.cpp) plus the confinement runner ([node, runner, --workspace, --temp, --mode, --, argv...]: kill-on-close job, stdio passthrough, exit-code mirroring, windows-acl-run: failure signature, grant revocation). read-only = strict zero grants (NUL device not writable; documented). Windows-only execution: exempted from the Linux coverage lane (windowsOnlyCoverageExclusions).
- @deepseek-ai/dsh-sandbox-local: PLATFORM_CHAINS.win32 filled with the windows-acl runner (full enforcement, ACL denial dialect, runner-failure rules).
- @deepseek-ai/dsh-pwsh-sandbox: sandbox-consuming pwsh executor (call-for-call mirror of dsh-bash-sandbox) over a new argv-level seam in dsh-pwsh-local; per-file coverage complete via the fake-provider spec.
- bundle/base: the Windows platform layer mounts the confined pwsh roster - sandbox/policy/fs-sandbox/permission/approval re-enabled, the POSIX bash stack stays disabled.
Co-authored-by: Huo Yaoyuan <huoyaoyuan@hotmail.com>
2026-08-08 01:24:33 +08:00
expect ( existsSync ( join ( writableDir , 'readonly-child-wrote.txt' ) ) ) . toBe ( false )
} , 30 _000 )
2026-08-08 14:32:01 +08:00
it ( 'workspace-write: Remove-Item and Rename-Item succeed in the granted workspace (DELETE + FILE_DELETE_CHILD)' , ( ) = > {
// Deleting a file and renaming a directory both hit the second access
// check on the workspace itself: the grant must carry DELETE (on the
// object) and FILE_DELETE_CHILD (on its parent).
const victimFile = join ( writableDir , 'delete-me.txt' )
writeFileSync ( victimFile , 'remove me' )
const victimDir = join ( writableDir , 'rename-me' )
mkdirSync ( victimDir )
const renamedDir = join ( writableDir , 'renamed-by-child' )
const probe = [
"$ErrorActionPreference='SilentlyContinue';" ,
` try{Remove-Item -LiteralPath ' ${ victimFile } ' -ErrorAction Stop;'DELETE-FILE: OK'}catch{'DELETE-FILE: DENIED'}; ` ,
` try{Rename-Item -LiteralPath ' ${ victimDir } ' -NewName 'renamed-by-child' -ErrorAction Stop;'RENAME-DIR: OK'}catch{'RENAME-DIR: DENIED'} ` ,
] . join ( '' )
const result = runRunner ( [
'--workspace' , writableDir , '--temp' , isolatedTemp , '--mode' , 'workspace-write' ,
'--' , 'pwsh' , '/NoLogo' , '/NonInteractive' , '/NoProfile' , '/Command' , probe ,
] )
expect ( result . status , ` stderr: ${ result . stderr } ` ) . toBe ( 0 )
expect ( result . stdout ) . toContain ( 'DELETE-FILE: OK' )
expect ( result . stdout ) . toContain ( 'RENAME-DIR: OK' )
expect ( existsSync ( victimFile ) ) . toBe ( false )
expect ( existsSync ( renamedDir ) ) . toBe ( true )
} , 30 _000 )
2026-08-08 17:29:43 +08:00
it ( '--write-sid: the runner trusts the caller-owned grants — private temp subdir via the TMP/TEMP env rewrite, no grants of its own' , ( ) = > {
const writeSid = 'S-1-4-9000-99'
const privateTemp = join ( isolatedTemp , 'private-subdir' )
mkdirSync ( privateTemp )
const grant = AclWriteGrant . create ( writeSid )
grant . add ( privateTemp )
try {
const probe = [
"$ErrorActionPreference='SilentlyContinue';" ,
` try{Set-Content -Path ' ${ writableDir } \\ server-granted.txt' -Value ok -ErrorAction Stop;'WORKSPACE-WRITE: OK'}catch{'WORKSPACE-WRITE: DENIED'}; ` ,
` try{Set-Content -Path ' ${ privateTemp } \\ server-granted.txt' -Value ok -ErrorAction Stop;'PRIVATE-TEMP-WRITE: OK'}catch{'PRIVATE-TEMP-WRITE: DENIED'}; ` ,
"'TEMP-ENV: ' + $env:TEMP;" ,
"'TMP-ENV: ' + $env:TMP" ,
] . join ( '' )
const result = runRunner ( [
'--workspace' , writableDir , '--temp' , privateTemp , '--mode' , 'workspace-write' , '--write-sid' , writeSid ,
'--' , 'pwsh' , '/NoLogo' , '/NonInteractive' , '/NoProfile' , '/Command' , probe ,
] )
expect ( result . status , ` stderr: ${ result . stderr } ` ) . toBe ( 0 )
// The runner granted nothing (only the caller's private-temp grant
// stands): the workspace write is denied, the private temp write lands,
// and the child's TMP/TEMP point at the private subdirectory.
expect ( result . stdout ) . toContain ( 'WORKSPACE-WRITE: DENIED' )
expect ( result . stdout ) . toContain ( 'PRIVATE-TEMP-WRITE: OK' )
expect ( result . stdout ) . toContain ( ` TEMP-ENV: ${ privateTemp } ` )
expect ( result . stdout ) . toContain ( ` TMP-ENV: ${ privateTemp } ` )
expect ( existsSync ( join ( writableDir , 'server-granted.txt' ) ) ) . toBe ( false )
expect ( existsSync ( join ( privateTemp , 'server-granted.txt' ) ) ) . toBe ( true )
} finally {
grant . dispose ( )
rmSync ( privateTemp , { recursive : true , force : true } )
}
} , 30 _000 )
2026-08-09 12:34:48 +08:00
it ( 'confined children spawn grandchildren with inherited stdio; piped capture stays denied (named-pipe default SD template)' , ( ) = > {
// Two-layer pin of the grandchild-spawn boundary:
// - the token default DACL carries a restricting-SID ACE (set in init),
// so ANONYMOUS pipe creation (CreatePipe — the token-default-DACL
// consumer) works and inherited/ignored stdio spawns succeed;
// - libuv's pipe-stdio uses NAMED pipes, whose default security
2026-08-09 16:34:09 +08:00
// descriptor is the Win32 layer's user-mode default SD template
// (built by KernelBase — owner/SYSTEM/Admins full, Everyone/ANONYMOUS
// read-only) — NOT the token default DACL, which is what the kernel
// applies to a raw SD-null create — so the client-end open requests
// write access no restricting SID is
2026-08-09 12:34:48 +08:00
// granted: ERROR_ACCESS_DENIED, surfaced as spawn EPERM. That is the
// POC-documented "no output redirection" boundary of WRITE_RESTRICTED
// tokens; piped capture cannot work and is pinned as DENIED.
const probe = [
"const { spawnSync } = require('child_process');" ,
"const t = (name, opts) => { const s = spawnSync(process.execPath, ['-e', '1'], { encoding: 'utf8', ...opts }); console.log(name + ':' + (s.status === 0 ? 'OK' : 'DENIED')); };" ,
"t('inherit', { stdio: 'inherit' });" ,
"t('ignore', { stdio: 'ignore' });" ,
"t('pipe', { stdio: 'pipe' });" ,
] . join ( '' )
for ( const mode of [ 'workspace-write' , 'read-only' ] as const ) {
const result = runRunner ( [
'--workspace' , writableDir , '--temp' , isolatedTemp , '--mode' , mode ,
'--' , 'node' , '-e' , probe ,
] )
expect ( result . status , ` stderr: ${ result . stderr } ` ) . toBe ( 0 )
expect ( result . stdout , ` mode: ${ mode } ` ) . toContain ( 'inherit:OK' )
expect ( result . stdout , ` mode: ${ mode } ` ) . toContain ( 'ignore:OK' )
expect ( result . stdout , ` mode: ${ mode } ` ) . toContain ( 'pipe:DENIED' )
}
} , 30 _000 )
2026-08-08 20:11:01 +08:00
it ( 'mode-downgrade leak regression: a STANDING workspace grant is inert under read-only and effective again on re-upgrade' , ( ) = > {
// The reported defect: a session that materialized its grant in
// workspace-write keeps the ACE standing for the server lifetime. After
2026-08-08 21:55:02 +08:00
// switching to read-only, the restricted token's read-only list must carry NO
2026-08-08 20:11:01 +08:00
// orphan SID — the standing ACE stays but the pass-2 check cannot use
// it, so the workspace write is denied (previously it LEAKED). The
// switch back reuses the SAME standing ACE: the re-upgrade write lands
// without any re-grant.
const writeSid = 'S-1-4-9001-7'
const grant = AclWriteGrant . create ( writeSid )
grant . add ( writableDir )
try {
const downgradeProbe = [
"$ErrorActionPreference='SilentlyContinue';" ,
` try{Set-Content -Path ' ${ writableDir } \\ downgraded.txt' -Value ok -ErrorAction Stop;'DOWNGRADE-WRITE: OK (LEAK!)'}catch{'DOWNGRADE-WRITE: DENIED'} ` ,
] . join ( '' )
const downgraded = runRunner ( [
'--workspace' , writableDir , '--temp' , isolatedTemp , '--mode' , 'read-only' , '--write-sid' , writeSid ,
'--' , 'pwsh' , '/NoLogo' , '/NonInteractive' , '/NoProfile' , '/Command' , downgradeProbe ,
] )
expect ( downgraded . status , ` stderr: ${ downgraded . stderr } ` ) . toBe ( 0 )
expect ( downgraded . stdout ) . toContain ( 'DOWNGRADE-WRITE: DENIED' )
expect ( existsSync ( join ( writableDir , 'downgraded.txt' ) ) ) . toBe ( false )
const reupgradeProbe = [
"$ErrorActionPreference='SilentlyContinue';" ,
` try{Set-Content -Path ' ${ writableDir } \\ reupgraded.txt' -Value ok -ErrorAction Stop;'REUPGRADE-WRITE: OK'}catch{'REUPGRADE-WRITE: DENIED'} ` ,
] . join ( '' )
const reupgraded = runRunner ( [
'--workspace' , writableDir , '--temp' , isolatedTemp , '--mode' , 'workspace-write' , '--write-sid' , writeSid ,
'--' , 'pwsh' , '/NoLogo' , '/NonInteractive' , '/NoProfile' , '/Command' , reupgradeProbe ,
] )
expect ( reupgraded . status , ` stderr: ${ reupgraded . stderr } ` ) . toBe ( 0 )
expect ( reupgraded . stdout ) . toContain ( 'REUPGRADE-WRITE: OK' )
expect ( existsSync ( join ( writableDir , 'reupgraded.txt' ) ) ) . toBe ( true )
} finally {
grant . dispose ( )
}
} , 30 _000 )
2026-08-08 21:55:02 +08:00
it ( 'ambient-writable escape regression: a C:\\Users\\Public subdirectory is denied under BOTH modes (INTERACTIVE absent from both lists)' , ( ctx ) = > {
// The Public tree grants write to INTERACTIVE; the D1-D6 matrix pinned
// that removing INTERACTIVE from the restricting lists closes the escape.
// The committed suites never probed it — this pins the ambient boundary
// end to end with the real restricted token.
if ( publicProbeDir === undefined ) {
ctx . skip ( ) // Public unavailable/unwritable on this host
return
}
const probe = [
"$ErrorActionPreference='SilentlyContinue';" ,
` try{Set-Content -Path ' ${ publicProbeDir } \\ public-escaped.txt' -Value ok -ErrorAction Stop;'PUBLIC-WRITE: OK (ESCAPE!)'}catch{'PUBLIC-WRITE: DENIED'} ` ,
] . join ( '' )
for ( const mode of [ 'read-only' , 'workspace-write' ] as const ) {
const result = runRunner ( [
'--workspace' , writableDir , '--temp' , isolatedTemp , '--mode' , mode ,
'--' , 'pwsh' , '/NoLogo' , '/NonInteractive' , '/NoProfile' , '/Command' , probe ,
] )
expect ( result . status , ` stderr: ${ result . stderr } ` ) . toBe ( 0 )
expect ( result . stdout , ` mode: ${ mode } ` ) . toContain ( 'PUBLIC-WRITE: DENIED' )
expect ( existsSync ( join ( publicProbeDir , 'public-escaped.txt' ) ) , ` mode: ${ mode } ` ) . toBe ( false )
}
} , 30 _000 )
feat(sandbox): Windows ACL write-restriction sandbox (restricted-token runner)
Confine Windows command execution through a WRITE_RESTRICTED token whose restricting SIDs carry an orphan-SID write allowlist, ported from https://github.com/huoyaoyuan/windows-acl-restrict-poc (@ 10e4dfb). Every Win32 call is checked and fails closed - the POC silently ran children with the FULL token when CreateRestrictedToken failed.
- @deepseek-ai/dsh-sandbox-windows-acl: koffi primitives verified against the MinGW Windows headers (verify/abi-probe.cpp) plus the confinement runner ([node, runner, --workspace, --temp, --mode, --, argv...]: kill-on-close job, stdio passthrough, exit-code mirroring, windows-acl-run: failure signature, grant revocation). read-only = strict zero grants (NUL device not writable; documented). Windows-only execution: exempted from the Linux coverage lane (windowsOnlyCoverageExclusions).
- @deepseek-ai/dsh-sandbox-local: PLATFORM_CHAINS.win32 filled with the windows-acl runner (full enforcement, ACL denial dialect, runner-failure rules).
- @deepseek-ai/dsh-pwsh-sandbox: sandbox-consuming pwsh executor (call-for-call mirror of dsh-bash-sandbox) over a new argv-level seam in dsh-pwsh-local; per-file coverage complete via the fake-provider spec.
- bundle/base: the Windows platform layer mounts the confined pwsh roster - sandbox/policy/fs-sandbox/permission/approval re-enabled, the POSIX bash stack stays disabled.
Co-authored-by: Huo Yaoyuan <huoyaoyuan@hotmail.com>
2026-08-08 01:24:33 +08:00
it ( 'runner-side failure: signature on stderr and exit 127, the command never runs' , ( ) = > {
const result = runRunner ( [ '--workspace' , writableDir , '--temp' , isolatedTemp , '--mode' , 'workspace-write' ] )
expect ( result . status ) . toBe ( 127 )
expect ( result . stderr ) . toContain ( 'windows-acl-run: ' )
} , 15 _000 )
} )