litedb-org/LiteDB · critical · Win32Exception
Failed to create security descriptor for shared mutex.
Error message
Failed to create security descriptor for shared mutex.
What it means
Thrown inside WindowsMutex.Create when the native ConvertStringSecurityDescriptorToSecurityDescriptor P/Invoke returns false, meaning the SDDL string 'D:(A;;GA;;;WD)' could not be parsed into a SECURITY_DESCRIPTOR. The last Win32 error code (via Marshal.GetLastWin32Error) gives the specific failure reason.
Source
Thrown at LiteDB/Client/Shared/SharedMutexFactory.cs:66
{
return RuntimeInformation.IsOSPlatform(OSPlatform.Windows);
}
#endif
private static class WindowsMutex
{
private const string WorldAccessSecurityDescriptor = "D:(A;;GA;;;WD)";
private const uint SddlRevision1 = 1;
public static Mutex Create(string name)
{
IntPtr descriptor = IntPtr.Zero;
try
{
if (!NativeMethods.ConvertStringSecurityDescriptorToSecurityDescriptor(WorldAccessSecurityDescriptor, SddlRevision1, out descriptor, out _))
{
throw new Win32Exception(Marshal.GetLastWin32Error(), "Failed to create security descriptor for shared mutex.");
}
var attributes = new NativeMethods.SECURITY_ATTRIBUTES
{
nLength = (uint)Marshal.SizeOf<NativeMethods.SECURITY_ATTRIBUTES>(),
bInheritHandle = 0,
lpSecurityDescriptor = descriptor
};
var handle = NativeMethods.CreateMutexEx(ref attributes, name, 0, NativeMethods.MUTEX_ALL_ACCESS);
if (handle == IntPtr.Zero || handle == NativeMethods.InvalidHandleValue)
{
throw new Win32Exception(Marshal.GetLastWin32Error(), "Failed to create shared mutex with global access.");
}
var mutex = new Mutex();
mutex.SafeWaitHandle = new SafeWaitHandle(handle, ownsHandle: true);View on GitHub (pinned to f906a5f850)
Solutions
- Switch to Direct mode to avoid the security descriptor creation path entirely.
- Repair the Windows installation (sfc /scannow) if the advapi32 SDDL functions are malfunctioning.
- Run the process with sufficient privileges to create security descriptors.
- Report to LiteDB maintainers if it occurs on a standard, up-to-date Windows installation.
Example fix
// No code fix possible for a native API failure; use Direct mode
var cs = new ConnectionString { Connection = ConnectionType.Direct }; Defensive patterns
Strategy: try-catch
Validate before calling
// No reliable pre-check; probe by attempting mutex creation
try
{
var probe = SharedMutexProbe();
probe.Dispose();
}
catch { cs.Connection = ConnectionType.Direct; }
Mutex SharedMutexProbe()
{
// Attempt the same SDDL-based mutex creation path
return new Mutex(false, $"Global\\LiteDB_probe_{Guid.NewGuid():N}");
} Try / catch
try
{
using var db = new LiteDatabase(cs);
}
catch (Win32Exception ex) when (ex.Message.Contains("security descriptor"))
{
// SDDL conversion failed; use Direct mode
cs.Connection = ConnectionType.Direct;
using var db = new LiteDatabase(cs);
} Prevention
- Use Direct mode to bypass the SDDL security descriptor creation entirely.
- Ensure advapi32.dll is intact (run sfc /scannow if corrupted).
- Run with sufficient OS privileges for security descriptor operations.
When it happens
Trigger: connection=Shared on Windows when the advapi32 function rejects the SDDL descriptor string. Possible causes: ERROR_INVALID_SD (513), ERROR_INVALID_SECURITY_DESCR (1338), or memory/resource exhaustion preventing descriptor allocation.
Common situations: Corrupted or modified advapi32.dll. Running under an extremely constrained security context. Very rare; usually indicates a broken Windows installation or a non-standard Windows build that doesn't recognize the SDDL revision 1 format.
Related errors
- Shared mode is not supported because named mutex access cont
- Failed to create shared mutex with global access.
- Shared mode is not supported in platforms that do not implem
AI-assisted analysis of litedb-org/LiteDB@f906a5f850 (2026-08-13).
Data as JSON: /api/errors/c19262a5e92c71db.
Report an issue: GitHub.