deepseek-ai/deepseek-harness · error

AclSandbox private temp directory must be disjoint from writ

Error message

AclSandbox private temp directory must be disjoint from writable directories: writable=${writableDir}; temp=${tempDir}

What it means

Error "AclSandbox private temp directory must be disjoint from writable directories: writable=${writableDir}; temp=${tempDir}" thrown in deepseek-ai/deepseek-harness.

Source

Thrown at packages/sandbox/sandbox-windows-acl/src/path-boundary.ts:37

 * @param workspaceRoot - the canonical workspace root that receives the standing ACE.
 * @param tempRoot - the existing parent beneath which a private temp child would be created.
 */
export function assertTempRootOutsideWorkspace(workspaceRoot: string, tempRoot: string): void {
  if (containsDirectory(workspaceRoot, tempRoot)) {
    throw new Error(`Windows ACL temp root must be outside the workspace: workspace=${workspaceRoot}; temp=${tempRoot}`)
  }
}

/**
 * Reject overlap between an actual private temp directory and any writable
 * directory: either inheritance direction would merge the two capabilities.
 * @param writableDirs - directories carrying the standing workspace capability.
 * @param tempDir - the existing directory carrying the revocable temp capability.
 */
export function assertPrivateTempDisjoint(writableDirs: readonly string[], tempDir: string): void {
  for (const writableDir of writableDirs) {
    if (containsDirectory(writableDir, tempDir) || containsDirectory(tempDir, writableDir)) {
      throw new Error(`AclSandbox private temp directory must be disjoint from writable directories: writable=${writableDir}; temp=${tempDir}`)
    }
  }
}

View on GitHub (pinned to b150a551b8)

Solutions

  1. Choose a private temp directory that is not inside and does not contain any writable directory.

When it happens

Trigger: Thrown at packages/sandbox/sandbox-windows-acl/src/path-boundary.ts:37 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of deepseek-ai/deepseek-harness@b150a551b8 (2026-08-24). Data as JSON: /api/errors/0e99b626e21a595f. Report an issue: GitHub.