/** * The windows-acl confinement runner: the argv-prefix wrapper the sandbox * seam spawns in place of the caller's command. It creates the * WRITE_RESTRICTED token with the workspace write-SID allowlist, spawns the * wrapped argv under it with the CALLER'S stdio inherited (bytes flow * straight through), mirrors the child's exit code, and revokes its temp * grant on exit (workspace ACEs stay standing as the reuse cache). * * Stable argv contract (the seam builds it; a native-exe replacement would * keep the same contract): * [node, runner.js, '--workspace', , '--temp', , * '--mode', , * ['--write-sid', ], '--', ] * * Modes: * - workspace-write: the workspace and temp directories carry the orphan-SID * Write grant; every other write is denied by the token intersection. * - read-only: STRICT zero grants — no directory is writable, not even the * NUL device (`> $null` fails with access denied); the restricting list * carries no orphan SID, so a standing grant ACE from an earlier * workspace-write period stays inert. BOTH modes drop Authenticated Users * (CIM unavailable — documented in README) and INTERACTIVE/LOCAL (the * Public tree writes are denied); the two lists share the keep-alive group * (logon SID, EVERYONE) and differ only by the orphan. * * `--write-sid`: the seam's grant contract — the CALLER has already * materialized the write-SID ACEs (the seam's workspace + private-temp * grants, server lifetime) and owns their revocation, so the runner neither * grants nor revokes (manageDacls: false). The carried SID is the * per-workspace identity ({@link workspaceWriteSid}) — the seam derives it * from the policy root; the flag's PRESENCE is the seam-managed marker (its * value must equal the workspace-derived SID). Absent `--write-sid` * (standalone/test use) the runner self-manages grants per invocation with * the same workspace-derived SID (its workspace ACEs are standing — the * reuse cache — and its temp ACE is revoked on exit). With `--write-sid` in * workspace-write mode, the runner rewrites the TMP/TEMP entries of its OWN * environment (SetEnvironmentVariableW) to the `--temp` directory — a * PRIVATE per-session temp subdirectory the seam provisions (bwrap `--tmpfs * /tmp` semantics) — and the child inherits the rewritten block (lpEnvironment * NULL; an explicit block through koffi trips ERROR_INVALID_PARAMETER in * CreateProcessAsUserW, verified empirically). Read-only leaves the ambient * temp entries untouched (writes there are denied anyway). * * Failure contract: every runner-side failure (bad args, missing * directories, token/grant/spawn errors) prints `windows-acl-run: ` * to stderr and exits 127 — the seam's RUNNER_FAILURE_RULES matches that * signature. The child is NEVER spawned unrestricted. * @module @deepseek-ai/dsh-sandbox-windows-acl/runner */ export {}; //# sourceMappingURL=runner.d.ts.map