deepseek-ai/deepseek-harness · error
AclSandbox workspace and temp write SIDs must be distinct
Error message
AclSandbox workspace and temp write SIDs must be distinct
What it means
Error "AclSandbox workspace and temp write SIDs must be distinct" thrown in deepseek-ai/deepseek-harness.
Source
Thrown at packages/sandbox/sandbox-windows-acl/src/index.ts:212
throw new Error('AclSandbox workspace-write requires a write SID — derive it from the workspace via workspaceWriteSid()')
}
if (this.mode === 'workspace-write' && this.tempDirOption === undefined) {
throw new Error('AclSandbox workspace-write requires an explicit private temp directory or null')
}
if (this.mode === 'read-only' && this.tempDirOption !== undefined && this.tempDirOption !== null) {
throw new Error('AclSandbox read-only does not accept a temp directory')
}
if (this.mode === 'read-only' && (this.writeSid !== undefined || this.tempWriteSid !== undefined)) {
throw new Error('AclSandbox read-only does not accept write SIDs')
}
if (this.mode === 'workspace-write' && this.tempDirOption !== null && this.tempWriteSid === undefined) {
throw new Error('AclSandbox workspace-write with temp requires a temp write SID — derive it via tempWriteSid()')
}
if (this.tempDirOption === null && this.tempWriteSid !== undefined) {
throw new Error('AclSandbox temp write SID requires a temp directory')
}
if (this.writeSid !== undefined && this.tempWriteSid === this.writeSid) {
throw new Error('AclSandbox workspace and temp write SIDs must be distinct')
}
}
/** Resolved temp directory (available after init; null when temp grants are disabled). */
get tempDir(): string | null | undefined {
return this.tempDirResolved
}
/** Create the restricted token and apply the capability-SID grants. Idempotent-unsafe: once per instance. */
async init(): Promise<void> {
if (this.api !== undefined) throw new Error('AclSandbox is already initialized')
const api = await win32()
const currentToken = openCurrentProcessToken(api)
let currentTokenOpen = true
let restrictedToken: NativePtr | undefined
try {
const parseSid = (sid: string): NativePtr => {
const sidSlot = allocPtrSlot()View on GitHub (pinned to b150a551b8)
Solutions
- Use distinct SIDs for the workspace and temp write grants; derive each with its own helper.
When it happens
Trigger: Thrown at packages/sandbox/sandbox-windows-acl/src/index.ts:212 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of deepseek-ai/deepseek-harness@b150a551b8 (2026-08-24).
Data as JSON: /api/errors/4299d6b0d81589b5.
Report an issue: GitHub.