github / github/app

PowerShell and search tools fail on Windows when sandbox fallback requires WRITE_DAC

未关闭
#3,097 2 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
没有语言数据
星标
2.1k
派生
153
PR 合并指标
30 天内没有已合并 PR

描述

## Reported behavior

Multiple users reported that sandbox-backed tools stop working on Windows in existing chats and automations. The failure persists across repeated attempts and does not recover during the session.

## Affected tools

- PowerShell and shell execution
- `grep`
- `glob`

## Unaffected tools

- File viewing and editing
- SQL
- Canvases
- MCP tools
- Session tools

A normal shell launched through the terminal canvas works for the same non-elevated user. This suggests that general process execution is available and that the failure is specific to the sandbox-backed tool path.

## Error

```text
backend_unavailable: BaseContainer is unavailable; DACL fallback requires
write-DAC permission on '', which the current user lacks
(ERROR_ACCESS_DENIED (WRITE_DAC not granted)).
```

The affected directory has varied between reports, including an application installation directory and a tools directory.

## Environment

- Windows
- Standard, non-elevated user
- Existing chats and automations
- The affected path is not writable by the current user

## Impact

The agent cannot run builds, commands, or repository searches through its normal tools. Users must route commands through a terminal canvas and poll for completion manually.

This workaround does not provide the same completion signaling. Users may need to ask for status updates or use sentinel files for long-running operations.

## Possible cause

This is an inference from the error, not a confirmed root cause.

The primary `BaseContainer` backend appears to be unavailable. The fallback then attempts a DACL operation that requires `WRITE_DAC` on a protected directory. A standard user does not have that permission, so both execution paths fail.

It is not clear why `BaseContainer` is unavailable or why the fallback needs to modify permissions on that directory.

## Expected behavior

- Shell and search tools work without administrator access.
- The fallback uses a user-writable location or another viable execution strategy.
- Read-only search tools can use a safe degraded path when sandbox execution is unavailable.
- The app reports the degraded state once, with actionable diagnostics, instead of failing every tool call separately.

贡献指南

打开贡献指南

调研方向

Start by reproducing the failure on Windows as a standard, non-elevated user with PowerShell, shell execution, grep, and glob. Trace the BaseContainer path and its DACL fallback, focusing on the reported WRITE_DAC error and the affected protected directories. Done means these tools work without administrator access or provide a safe degraded path and actionable diagnostics when sandbox execution is unavailable.

由索引模型根据 Issue 内容生成。

评估

技术栈
powershell
领域
desktop, tooling
Issue 类型
缺陷
难度
5/5
预计耗时
一周以上
活跃度
活跃
描述清晰度
需要澄清
新手友好度
30/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。