{"record":{"id":"4299d6b0d81589b5","repo":"deepseek-ai/deepseek-harness","slug":"aclsandbox-workspace-and-temp-write-sids-must-be-d","errorCode":null,"errorMessage":"AclSandbox workspace and temp write SIDs must be distinct","messagePattern":"AclSandbox workspace and temp write SIDs must be distinct","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"packages/sandbox/sandbox-windows-acl/src/index.ts","lineNumber":212,"sourceCode":"      throw new Error('AclSandbox workspace-write requires a write SID — derive it from the workspace via workspaceWriteSid()')\n    }\n    if (this.mode === 'workspace-write' && this.tempDirOption === undefined) {\n      throw new Error('AclSandbox workspace-write requires an explicit private temp directory or null')\n    }\n    if (this.mode === 'read-only' && this.tempDirOption !== undefined && this.tempDirOption !== null) {\n      throw new Error('AclSandbox read-only does not accept a temp directory')\n    }\n    if (this.mode === 'read-only' && (this.writeSid !== undefined || this.tempWriteSid !== undefined)) {\n      throw new Error('AclSandbox read-only does not accept write SIDs')\n    }\n    if (this.mode === 'workspace-write' && this.tempDirOption !== null && this.tempWriteSid === undefined) {\n      throw new Error('AclSandbox workspace-write with temp requires a temp write SID — derive it via tempWriteSid()')\n    }\n    if (this.tempDirOption === null && this.tempWriteSid !== undefined) {\n      throw new Error('AclSandbox temp write SID requires a temp directory')\n    }\n    if (this.writeSid !== undefined && this.tempWriteSid === this.writeSid) {\n      throw new Error('AclSandbox workspace and temp write SIDs must be distinct')\n    }\n  }\n\n  /** Resolved temp directory (available after init; null when temp grants are disabled). */\n  get tempDir(): string | null | undefined {\n    return this.tempDirResolved\n  }\n\n  /** Create the restricted token and apply the capability-SID grants. Idempotent-unsafe: once per instance. */\n  async init(): Promise<void> {\n    if (this.api !== undefined) throw new Error('AclSandbox is already initialized')\n    const api = await win32()\n    const currentToken = openCurrentProcessToken(api)\n    let currentTokenOpen = true\n    let restrictedToken: NativePtr | undefined\n    try {\n      const parseSid = (sid: string): NativePtr => {\n        const sidSlot = allocPtrSlot()","sourceCodeStart":194,"sourceCodeEnd":230,"githubUrl":"https://github.com/deepseek-ai/deepseek-harness/blob/b150a551b8d465e31e418e1b2eaf5e79bbb7d28e/packages/sandbox/sandbox-windows-acl/src/index.ts#L194-L230","documentation":"Error \"AclSandbox workspace and temp write SIDs must be distinct\" thrown in deepseek-ai/deepseek-harness.","triggerScenarios":"Thrown at packages/sandbox/sandbox-windows-acl/src/index.ts:212 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Use distinct SIDs for the workspace and temp write grants; derive each with its own helper."],"exampleFix":null,"handlingStrategy":null,"validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"b150a551b8d465e31e418e1b2eaf5e79bbb7d28e","analyzedAt":"2026-08-24T18:12:29.105Z","schemaVersion":2},"datasetVersion":"2026-08-24T22:17:12.610Z"}