Copy Block Deny Write
CopyBlockDenyWrite is a sandbox setting in Sandboxie Ini, available since Sandboxie Plus 0.6.5. It controls what happens to an open that needs file migration when Sandboxie has decided not to copy the host file.
Usage:
The syntax is CopyBlockDenyWrite=[program,]y|n. The optional Program Name Prefix makes the value apply only to that executable. Multiple entries can provide values for different programs, but this is a yes-or-no setting rather than a path list.
For initial migration, when set to y, an open that requires a sandbox copy fails with access denied if the migration decision is do not copy. When absent or set to n, Sandboxie instead removes write and delete rights from the request and retries the open against the host file. A read-capable request may therefore succeed as read-only; a request that cannot be satisfied after those rights are removed may still fail.
The do not copy decision can come from a matching DontCopy rule or from the normal size decision controlled by CopyLimitKb, including when a large-file prompt is unavailable or declined. This setting does not itself choose files or prevent successful migrations.
Matching CopyAlways and CopyEmpty rules select copy modes instead, so CopyBlockDenyWrite does not act on those outcomes. When CopyNewer initiates a refresh, this setting can affect the refresh migration's result. A failed refresh does not necessarily deny the subsequent open of the already-existing sandbox copy.
CopyLimitSilent only controls message SBIE2102 for a size-based refusal; it does not change the migration decision. For an explicit DontCopy rule, enabling NotifyNoCopy produces SBIE2114 when this setting is y, or SBIE2115 when it is n. These messages describe the selected mode, not the final result of opening an existing copy after a refresh attempt.
In SandMan, open Sandbox Options > General Options > File Migration. The checkbox is phrased in the opposite direction: When a file cannot be migrated, open it in read-only mode instead. Clearing that checkbox enables CopyBlockDenyWrite=y.
Related Sandboxie Ini settings: DontCopy, CopyAlways, CopyEmpty, CopyLimitKb, CopyLimitSilent, NotifyNoCopy. See also File Migration Settings.