概览
dsh-acl-sandbox-patch
Temporary fix for the DSH 0.1.7 Windows ACL sandbox failing on non-system-drive workspaces (grantWrite / SetNamedSecurityInfoW Win32 5) — restores workspace-write commands without touching any system ACL.
README / ZH
插件文档
目录摘要
Temporary fix for the DSH 0.1.7 Windows ACL sandbox failing on non-system-drive workspaces (grantWrite / SetNamedSecurityInfoW Win32 5) — restores workspace-write commands without touching any system ACL.
dsh.pub 核对固定版本的组合包契约、运行时事实与分发语义;完整 README 请查看源仓库。
在 GitHub 阅读完整 READMELIMITATIONS
已知限制
- **仅 Windows**;其他平台直接 no-op。 - 需要重启 DSH 生效(预加载要走进程启动)。 - **重启前已建立的会话,其命令通道可能是重启前的旧 runner 孤儿进程**(旧版行为:Low 令牌、无状态文件感知)——这是 DSH 重启不回收旧 runner 的进程管理行为,非插件缺陷;**新开会话即恢复正常**。 - **重启后首条命令慢**:降级后工作区的 exact-ACE skip 不再命中(Low 标签永远不在),每次 DSH 重启后对该工作区的首条 `workspace-write` 命令要做一次 DACL 全树传播(实测 44k 文件约 20 秒;沙箱机制的固有代价)。同进程内的后续命令与新会话走复用缓存,2 秒以内。 - 上游修复发布后(对应 discussion 关闭或沙箱包升级)应卸载本插件恢复出厂行为。
