deepseek-ai/deepseek-harness · error
AclSandbox private temp directory must be disjoint from writ
Error message
AclSandbox private temp directory must be disjoint from writable directories: writable=${writableDir}; temp=${tempDir} What it means
Error "AclSandbox private temp directory must be disjoint from writable directories: writable=${writableDir}; temp=${tempDir}" thrown in deepseek-ai/deepseek-harness.
Source
Thrown at packages/sandbox/sandbox-windows-acl/src/path-boundary.ts:37
* @param workspaceRoot - the canonical workspace root that receives the standing ACE.
* @param tempRoot - the existing parent beneath which a private temp child would be created.
*/
export function assertTempRootOutsideWorkspace(workspaceRoot: string, tempRoot: string): void {
if (containsDirectory(workspaceRoot, tempRoot)) {
throw new Error(`Windows ACL temp root must be outside the workspace: workspace=${workspaceRoot}; temp=${tempRoot}`)
}
}
/**
* Reject overlap between an actual private temp directory and any writable
* directory: either inheritance direction would merge the two capabilities.
* @param writableDirs - directories carrying the standing workspace capability.
* @param tempDir - the existing directory carrying the revocable temp capability.
*/
export function assertPrivateTempDisjoint(writableDirs: readonly string[], tempDir: string): void {
for (const writableDir of writableDirs) {
if (containsDirectory(writableDir, tempDir) || containsDirectory(tempDir, writableDir)) {
throw new Error(`AclSandbox private temp directory must be disjoint from writable directories: writable=${writableDir}; temp=${tempDir}`)
}
}
}
View on GitHub (pinned to b150a551b8)
Solutions
- Choose a private temp directory that is not inside and does not contain any writable directory.
When it happens
Trigger: Thrown at packages/sandbox/sandbox-windows-acl/src/path-boundary.ts:37 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of deepseek-ai/deepseek-harness@b150a551b8 (2026-08-24).
Data as JSON: /api/errors/0e99b626e21a595f.
Report an issue: GitHub.