Repository navigation
Unable to run sandboxed process when run as elevated under applocker #122951
Description
Activity
(Experimental duplicate detection)
Thanks for submitting this issue. Please also check if it is already covered by an existing one, like:Which specific insider build are you on? Please share the commit number. This should be in the about panel
Here you go:
Version: 1.56.0-insider (user setup)
Commit: 85f8ebf
Date: 2021-05-04T08:04:43.323ZThanks. Unfortunately I can't reproduce this issue with that build
Can you try launching VS Code by running
code-insiders --verbosefrom the command line. This will print more detailed logs that may help me investigate what is going onServiceWorker cannot be startedcan happen in the following situations,- |script_url| is on a different origin from |scope|
- Fetching |script_url| fails.
- |script_url| fails to parse or its top-level execution fails.
Based on the error message 1) and 2) are satisfied, very likely we are hitting 3) given the
TypeError.Lets check the webview devtools console log for any script errors thrown, if not we would have to expose a way to pause serviceworker execution on start to debug further, a similar feature provided by
chrome://serviceworker-internals/I see this stack appear before the error message:
[5660:0505/094114.425:INFO:CONSOLE(627)] "%c ERR color: #f33 Cannot read property 'resource' of undefined: TypeError: Cannot read property 'resource' of undefined at c.deserializeWebviewPanel (c:\Users\mahowa\AppData\Local\Programs\Microsoft VS Code Insiders\resources\app\extensions\markdown-language-features\dist\extension.js:1:107435) at s.$deserializeWebviewPanel (c:\Users\mahowa\AppData\Local\Programs\Microsoft VS Code Insiders\resources\app\out\vs\workbench\services\extensions\node\extensionHostProcess.js:88:68958) at l._doInvokeHandler (c:\Users\mahowa\AppData\Local\Programs\Microsoft VS Code Insiders\resources\app\out\vs\workbench\services\extensions\node\extensionHostProcess.js:91:12836) at l._invokeHandler (c:\Users\mahowa\AppData\Local\Programs\Microsoft VS Code Insiders\resources\app\out\vs\workbench\services\extensions\node\extensionHostProcess.js:91:12520) at l._receiveRequest (c:\Users\mahowa\AppData\Local\Programs\Microsoft VS Code Insiders\resources\app\out\vs\workbench\services\extensions\node\extensionHostProcess.js:91:11187) at l._receiveOneMessage (c:\Users\mahowa\AppData\Local\Programs\Microsoft VS Code Insiders\resources\app\out\vs\workbench\services\extensions\node\extensionHostProcess.js:91:9973) at c:\Users\mahowa\AppData\Local\Programs\Microsoft VS Code Insiders\resources\app\out\vs\workbench\services\extensions\node\extensionHostProcess.js:91:8074 at fire (c:\Users\mahowa\AppData\Local\Programs\Microsoft VS Code Insiders\resources\app\out\vs\workbench\services\extensions\node\extensionHostProcess.js:57:1836) at S.fire (c:\Users\mahowa\AppData\Local\Programs\Microsoft VS Code Insiders\resources\app\out\vs\workbench\services\extensions\node\extensionHostProcess.js:65:15497) at c:\Users\mahowa\AppData\Local\Programs\Microsoft VS Code Insiders\resources\app\out\vs\workbench\services\extensions\node\extensionHostProcess.js:106:29764 at fire (c:\Users\mahowa\AppData\Local\Programs\Microsoft VS Code Insiders\resources\app\out\vs\workbench\services\extensions\node\extensionHostProcess.js:57:1836) at S.fire (c:\Users\mahowa\AppData\Local\Programs\Microsoft VS Code Insiders\resources\app\out\vs\workbench\services\extensions\node\extensionHostProcess.js:65:15497) at t._receiveMessage (c:\Users\mahowa\AppData\Local\Programs\Microsoft VS Code Insiders\resources\app\out\vs\workbench\services\extensions\node\extensionHostProcess.js:65:20755) at c:\Users\mahowa\AppData\Local\Programs\Microsoft VS Code Insiders\resources\app\out\vs\workbench\services\extensions\node\extensionHostProcess.js:65:17641 at fire (c:\Users\mahowa\AppData\Local\Programs\Microsoft VS Code Insiders\resources\app\out\vs\workbench\services\extensions\node\extensionHostProcess.js:57:1836) at acceptChunk (c:\Users\mahowa\AppData\Local\Programs\Microsoft VS Code Insiders\resources\app\out\vs\workbench\services\extensions\node\extensionHostProcess.js:65:12862) at c:\Users\mahowa\AppData\Local\Programs\Microsoft VS Code Insiders\resources\app\out\vs\workbench\services\extensions\node\extensionHostProcess.js:65:12210 at Socket.v (c:\Users\mahowa\AppData\Local\Programs\Microsoft VS Code Insiders\resources\app\out\vs\workbench\services\extensions\node\extensionHostProcess.js:106:13195) at Socket.emit (events.js:315:20) at addChunk (internal/streams/readable.js:309:12) at readableAddChunk (internal/streams/readable.js:284:9) at Socket.Readable.push (internal/streams/readable.js:223:10) at Pipe.onStreamRead (internal/stream_base_commons.js:188:23)", source: file:///C:/Users/mahowa/AppData/Local/Programs/Microsoft VS Code Insiders/resources/app/out/vs/workbench/workbench.desktop.main.js (627) ... [5660:0505/094114.703:INFO:CONSOLE(627)] "%cDEBUG background: #eee; color: #888 Webview(8b913105-9191-43c8-a617-1606ad761eae): did post message on 'focus'", source: file:///C:/Users/mahowa/AppData/Local/Programs/Microsoft VS Code Insiders/resources/app/out/vs/workbench/workbench.desktop.main.js (627) [5660:0505/094114.706:INFO:CONSOLE(1728)] "[Embedded Page] Webview fatal error: Error: Could not register service workers: TypeError: Failed to register a ServiceWorker for scope ('vscode-webview://8b913105-9191-43c8-a617-1606ad761eae/') with script ('vscode-webview://8b913105-9191-43c8-a617-1606ad761eae/service-worker.js?platform=electron&id=8b913105-9191-43c8-a617-1606ad761eae&vscode-resource-origin=https%3A%2F%2F8b913105-9191-43c8-a617-1606ad761eae.vscode-webview-test.com'): ServiceWorker cannot be started.", source: file:///C:/Users/mahowa/AppData/Local/Programs/Microsoft VS Code Insiders/resources/app/out/vs/workbench/workbench.desktop.main.js (1728) [5660:0505/094114.707:INFO:CONSOLE(735)] "Error loading webview: Error: Could not register service workers: TypeError: Failed to register a ServiceWorker for scope ('vscode-webview://8b913105-9191-43c8-a617-1606ad761eae/') with script ('vscode-webview://8b913105-9191-43c8-a617-1606ad761eae/service-worker.js?platform=electron&id=8b913105-9191-43c8-a617-1606ad761eae&vscode-resource-origin=https%3A%2F%2F8b913105-9191-43c8-a617-1606ad761eae.vscode-webview-test.com'): ServiceWorker cannot be started.", source: file:///C:/Users/mahowa/AppData/Local/Programs/Microsoft VS Code Insiders/resources/app/out/vs/workbench/workbench.desktop.main.js (735) [5660:0505/094114.710:INFO:CONSOLE(627)] "%cDEBUG background: #eee; color: #888 Webview(8b913105-9191-43c8-a617-1606ad761eae): did post message on 'focus'", source: file:///C:/Users/mahowa/AppData/Local/Programs/Microsoft VS Code Insiders/resources/app/out/vs/workbench/workbench.desktop.main.js (627)I'm not sure if this is a Markdown-specific issue though. I can also try uninstalling and re-installing if you'd like.
Interesting, this looks a lot like the #120157 I saw earlier but then could not reproduce anymore.
Matt Howard (@moward) It happens for all webviews though, not just markdown previews, correct?
Image file previews are also broken. Do these use WebViews? I see an empty window but no error notification and don't see anything in the verbose logs. Also, I just upgraded a different machine to 85f8ebf and am now seeing the same problem there. 🙁
I have noticed this issue on the stable build of 1.56.0 that was just released. I have found it only happens if I run vscode as administrator. I noticed because I couldn't read the release notes 😂
Error loading webview: Error: Could not register service workers: TypeError: Failed to register a ServiceWorker for scope ('vscode-webview://vs_code_release_notes/') with script ('vscode-webview://vs_code_release_notes/service-worker.js?platform=electron&id=vs_code_release_notes&vscode-resource-origin=https%3A%2F%2Fvs_code_release_notes.vscode-webview-test.com'): ServiceWorker cannot be started.
Reacted by Diogo Rocha, GrooveGod and Jon LofthouseYou're absolutely right, Brian Hauger (@haugerbr). I always run as administrator and forgot to consider that. I just tried running without elevated permissions and the WebViews work
Matt Bierner (@mjbvz) Benjamin Pasero (@bpasero) can you try to repro using the info I posted. I have a feeling you that may start seeing more issues like this opened because I'm sure there are other people who need vscode to run as admin and while vscode can still be used, it degrades the experience significantly.
- addedinfo-neededIssue requires more information from posterIssue requires more information from poster
on May 6, 2021 139 remaining items
Upgraded to 1.79.2 and im still getting the same error.
Upgraded to 1.79.2 and im still getting the same error.
I’m not. But I suspect you’ll need to use the —highly annoying—
--no-sandbox --disable-gpu-sandboxworkaround… 🙄I'm happy to have new argument in argv.json (disable-chromium-sandbox) :D but warning on edit persists: "Property disable-chromium-sandbox is not allowed."
I'm running what I thought was a standard install. Version 1.18.1 (user setup). Not using UNC paths or accessing data on a network. The machine is domain-joined. If I try and run as an admin I get the "code 18" error as discussed at #185057
Verbose console output
[main 2023-09-04T11:15:12.023Z] PolicyConfiguration#initialize [main 2023-09-04T11:15:12.025Z] PolicyConfiguration#updatePolicyDefinitions [ 'http.proxy', 'http.proxyStrictSSL', 'http.proxyKerberosServicePrincipal', 'http.proxyAuthorization', 'http.proxySupport', 'http.systemCertificates', 'telemetry.telemetryLevel', 'telemetry.enableTelemetry', 'update.mode', 'update.channel', 'update.enableWindowsBackgroundUpdates', 'update.showReleaseNotes' ] [main 2023-09-04T11:15:12.027Z] NativePolicyService#_updatePolicyDefinitions - Found 1 policy definitions [main 2023-09-04T11:15:12.030Z] [File Watcher (node.js)] Request to start watching: c:\Users\user.name\AppData\Roaming\Code\User (excludes: <none>, includes: <all>),c:\Users\user.name\AppData\Roaming\Code\User\settings.json (excludes: <none>, includes: <all>) [main 2023-09-04T11:15:12.031Z] NativePolicyService#_onDidPolicyChange - Updated policy values: {} [main 2023-09-04T11:15:12.031Z] PolicyConfiguration#update [ 'update.mode' ] [main 2023-09-04T11:15:12.041Z] Starting VS Code [main 2023-09-04T11:15:12.042Z] from: c:\Program Files\Microsoft VS Code\resources\app [main 2023-09-04T11:15:12.042Z] args: { _: [], diff: false, merge: false, add: false, goto: false, 'new-window': false, 'reuse-window': false, wait: false, help: false, 'list-extensions': false, 'show-versions': false, 'pre-release': false, version: false, verbose: true, status: false, 'prof-startup': false, 'no-cached-data': false, 'prof-v8-extensions': false, 'disable-extensions': false, 'disable-gpu': false, 'disable-chromium-sandbox': false, 'ms-enable-electron-run-as-node': false, telemetry: false, debugRenderer: false, 'enable-smoke-test-driver': false, logExtensionHostCommunication: false, 'skip-release-notes': false, 'skip-welcome': false, 'disable-telemetry': false, 'disable-updates': false, 'disable-keytar': false, 'disable-workspace-trust': false, 'disable-crash-reporter': false, 'crash-reporter-id': 'd3cd63b1-4b41-4f4a-b105-cd982f6333af', 'skip-add-to-recently-opened': false, 'unity-launch': false, 'open-url': false, 'file-write': false, 'file-chmod': false, force: false, 'do-not-sync': false, trace: false, 'force-user-env': false, 'force-disable-user-env': false, 'open-devtools': false, 'disable-gpu-sandbox': false, '__enable-file-policy': false, 'enable-coi': false, 'no-proxy-server': false, 'no-sandbox': false, nolazy: false, 'force-renderer-accessibility': false, 'ignore-certificate-errors': false, 'allow-insecure-localhost': false, 'disable-dev-shm-usage': false, 'profile-temp': false, logsPath: 'C:\\Users\\user.name\\AppData\\Roaming\\Code\\logs\\20230904T121512' } [main 2023-09-04T11:15:12.042Z] Resolving machine identifier... [main 2023-09-04T11:15:12.042Z] Resolved machine identifier: 99b47c228839f905f764065af7f0b0948087264693cbc43469f75fb2dd7b24df [main 2023-09-04T11:15:12.043Z] Main->SharedProcess#connect [main 2023-09-04T11:15:12.043Z] PolicyConfiguration#updatePolicyDefinitions [ 'terminal.integrated.automationProfile.linux', 'terminal.integrated.automationProfile.osx', 'terminal.integrated.automationProfile.windows', 'terminal.integrated.profiles.windows', 'terminal.integrated.profiles.osx', 'terminal.integrated.profiles.linux', 'terminal.integrated.useWslProfiles', 'terminal.integrated.inheritEnv', 'terminal.integrated.persistentSessionScrollback', 'terminal.integrated.showLinkHover', 'terminal.integrated.ignoreProcessNames' ] [main 2023-09-04T11:15:12.043Z] PolicyConfiguration#updatePolicyDefinitions [ 'terminal.integrated.defaultProfile.linux', 'terminal.integrated.defaultProfile.osx', 'terminal.integrated.defaultProfile.windows' ] [main 2023-09-04T11:15:12.047Z] PolicyConfiguration#update [] [main 2023-09-04T11:15:12.047Z] PolicyConfiguration#update [] [main 2023-09-04T11:15:12.052Z] StorageMainService: creating application storage [main 2023-09-04T11:15:12.055Z] ElectronURLListener: waiting for window to be ready to handle URLs... [main 2023-09-04T11:15:12.055Z] lifecycle (main): phase changed (value: 2) [main 2023-09-04T11:15:12.055Z] windowsManager#open [main 2023-09-04T11:15:12.056Z] windowsManager#open pathsToOpen [ { backupPath: 'C:\\Users\\user.name\\AppData\\Roaming\\Code\\Backups\\1693824130872', remoteAuthority: undefined } ] [main 2023-09-04T11:15:12.056Z] windowsManager#doOpenEmpty { restore: true, remoteAuthority: undefined, filesToOpen: undefined, forceNewWindow: true } [main 2023-09-04T11:15:12.057Z] IPC Object URL: Registered new channel vscode:26fc8e76-2540-4841-a0c8-39557808a3e6. [main 2023-09-04T11:15:12.057Z] window#validateWindowState: validating window state on 3 display(s) { mode: 0, x: 694, y: 412, width: 960, height: 1040 } [main 2023-09-04T11:15:12.057Z] window#validateWindowState: multi-monitor working area { x: 0, y: 0, width: 3440, height: 1400 } [main 2023-09-04T11:15:12.057Z] window#ctor: using window state { mode: 0, x: 694, y: 412, width: 960, height: 1040 } [main 2023-09-04T11:15:12.101Z] window#load: attempt to load window (id: 1) [main 2023-09-04T11:15:12.115Z] windowsManager#open used window count 1 (workspacesToOpen: 0, foldersToOpen: 0, emptyToRestore: 1, emptyToOpen: 0) [main 2023-09-04T11:15:12.116Z] lifecycle (main): phase changed (value: 3) [main 2023-09-04T11:15:12.119Z] resolveShellEnv(): skipped (Windows) [main 2023-09-04T11:15:12.120Z] update#setState idle Renderer process launch-failed - see https://www.electronjs.org/docs/tutorial/application-debugging for potential debugging information. [main 2023-09-04T11:15:12.157Z] CodeWindow: renderer process gone (reason: launch-failed, code: 18) Renderer process launch-failed - see https://www.electronjs.org/docs/tutorial/application-debugging for potential debugging information. [main 2023-09-04T11:15:12.221Z] CodeWindow: renderer process gone (reason: launch-failed, code: 18) [main 2023-09-04T11:15:12.225Z] [File Watcher (node.js)] Started watching: 'c:\Users\user.name\AppData\Roaming\Code\User' [main 2023-09-04T11:15:12.226Z] [File Watcher (node.js)] Started watching: 'c:\Users\user.name\AppData\Roaming\Code\User\settings.json' [main 2023-09-04T11:15:12.292Z] [File Watcher (node.js)] [raw] ["change"] globalStorage [main 2023-09-04T11:15:12.292Z] [File Watcher (node.js)] [CHANGED] c:\Users\user.name\AppData\Roaming\Code\User\globalStorage [main 2023-09-04T11:15:12.293Z] [File Watcher (node.js)] [raw] ["change"] globalStorage [main 2023-09-04T11:15:12.293Z] [File Watcher (node.js)] [CHANGED] c:\Users\user.name\AppData\Roaming\Code\User\globalStorage [main 2023-09-04T11:15:12.371Z] [File Watcher (node.js)] >> normalized [CHANGED] c:\Users\user.name\AppData\Roaming\Code\User\globalStorage [main 2023-09-04T11:15:12.371Z] User data changed [main 2023-09-04T11:15:14.616Z] IPC Object URL: Removed channel vscode:26fc8e76-2540-4841-a0c8-39557808a3e6. [main 2023-09-04T11:15:14.617Z] Lifecycle#window.on('closed') - window ID 1 [main 2023-09-04T11:15:14.617Z] Lifecycle#onWillShutdown.fire() [main 2023-09-04T11:15:14.620Z] Lifecycle#onWillShutdown - begin 'instanceLockfile' [main 2023-09-04T11:15:14.620Z] storageMainService#onWillShutdown() [main 2023-09-04T11:15:14.621Z] Lifecycle#onWillShutdown - begin 'applicationStorage' [main 2023-09-04T11:15:14.621Z] Lifecycle#onWillShutdown - begin 'extHostStarter' [main 2023-09-04T11:15:14.621Z] Lifecycle#app.on(window-all-closed) [main 2023-09-04T11:15:14.621Z] Lifecycle#app.on(before-quit) [main 2023-09-04T11:15:14.622Z] Lifecycle#onBeforeShutdown.fire() [main 2023-09-04T11:15:14.622Z] [WindowsStateHandler] onBeforeShutdown { lastActiveWindow: { workspaceIdentifier: undefined, folder: undefined, backupPath: 'C:\\Users\\user.name\\AppData\\Roaming\\Code\\Backups\\1693824130872', remoteAuthority: undefined, uiState: [Object: null prototype] { mode: 0, x: 694, y: 412, width: 960, height: 1040 } }, lastPluginDevelopmentHostWindow: undefined, openedWindows: [] } [main 2023-09-04T11:15:14.623Z] Lifecycle#app.on(will-quit) - begin [main 2023-09-04T11:15:14.625Z] Lifecycle#onWillShutdown - end 'extHostStarter' [main 2023-09-04T11:15:14.637Z] [File Watcher (node.js)] Request to stop watching: c:\Users\user.name\AppData\Roaming\Code\User,c:\Users\user.name\AppData\Roaming\Code\User\settings.json [main 2023-09-04T11:15:14.638Z] [File Watcher (node.js)] stopping file watcher on c:\Users\user.name\AppData\Roaming\Code\User [main 2023-09-04T11:15:14.638Z] [File Watcher (node.js)] stopping file watcher on c:\Users\user.name\AppData\Roaming\Code\User\settings.json [main 2023-09-04T11:15:14.643Z] Lifecycle#onWillShutdown - end 'instanceLockfile' [main 2023-09-04T11:15:14.647Z] StorageMainService: closed application storage [main 2023-09-04T11:15:14.647Z] Lifecycle#onWillShutdown - end 'applicationStorage' [main 2023-09-04T11:15:14.648Z] Lifecycle#app.on(will-quit) - after fireOnWillShutdown [main 2023-09-04T11:15:14.648Z] Lifecycle#app.on(will-quit) - calling app.quit()Edit:
--no-sandbox --disable-gpu-sandboxis a workaround.Although I can get VSCode to launch with the command line options given above on a VDI image, how can I make that the default so that no matter how an end-user opens VSCode the switches above are applied. Right now, I just tweak the shortcut.
The reason I ask is that I have Azure Data Studio on the same VDI and it opens fine every time. So, somehow they were able to set that as the default.
Just a heads-up that 1.82.1 now needs
code --no-sandbox --disable-gpu-sandbox --user-data-dir=/tmporsomethingsimilarto run, previous versions ran with only--no-sandboxsupplied. System install on Win11 with applocker, running in administrator user's elevated prompt. I used an empty folder for user data dir as I'm only running it as admin to allow a system-wide update.Reacted by Michael KlementI am having the same issue as described in #128649 on OS-X in Version 1.82.2
Reacted by Almaz GalievOn Windows 11 (v1.82.2) with standard install, there is a workaround:
- Pin vscode to the taskbar.
- Right click the icon there -> New Window.
- For that session the WebViews load fine, I didn't see any warnings/errors.
Reacted by anuragfalconx and Philipp GfellerI was having this problem as well.
reproduce:
fresh install of vscode,
install plugin "Graphviz Interactive Preview"
used Fullscreen (IDK if this mattered)
added to the document, when I put in "" for "\n" in 'label="" ' immediately got the error bellow (null function or function signature mismatch):

tried refreshing after completing "\n" label error remained
fixed after close and restart
tried again only put in "" immediate error
put in "\n" restarted, "Graphviz Interactive Preview" window will not open.
tried to restart as admin no change.
tried fix read about on GitHub (pin to start and open new window) no change
still can't open "Graphviz Interactive Preview"I was having this problem as well.
- OS Version: Windows 11 24H2
- Vscode Version:1.96.0
I found that a triggering condition is to first run a window as a non administrator, then modify the compatibility settings in the shortcut properties to require running as an administrator, and then launch a window through a shortcut. This error occurs.


I dug around this problem a bit and found some use cases that trigger this
Could not register service workerspop-up that brakes all custom webviews!My info:
- OS Version: Ubuntu 22.04
- VS Code Version:1.100.0
- Using multiple VS Code versions at the same time
If I try to open a VS Code 1.100 first then start another instance with version 1.99, the second one will experience the
Could not register service workersnotification.- Sharing the same user data directory across machines
Part of my work involves working on different virtual machines, that share my home directory. This adds the possibility of having multiple VS Code instances started on different machines, yet sharing the same user data directory which also triggers the
Could not register service workerspop-up. I know it can be argued that this point can be extrapolated from 3rd point of the Not supported section of the requirements page, but this means knowing the processes structure of VS Code, and how starting a new windows behaves differently depending on whether there are other VS Code windows already opened.Most of the time, both cases tend to break the user data directory, resulting in new windows experiencing the same issue.
The easiest fix is to delete~/.config/Code/User/globalStorage, but that comes with losing anything store in the state.vscdb file, such as authorization tokens or the UI state which is not desirable. I suspect the mastercodeprocess somehow breaks the db file when multiple such processes try to access it.Is there any way VS Code can guard against these situations? Maybe give a better error message instead of the dreaded
Could not register service workers? For the average user, this message means nothing and gives no pointers towards any kind of resolution!- addedupstream-issue-linkedThis is an upstream issue that has been reported upstreamThis is an upstream issue that has been reported upstream
on Dec 10, 2025 - marked Can't open VSCode in admin mode #281101 as a duplicate of this issue
on Jan 5, 2026

Steps to Reproduce:
The same thing happens for other WebViews, like opening an extension from the Extensions sidebar, or using the "Issue Reporter".
Does this issue occur when all extensions are disabled?: Yes