Hmbown/CodeWhale · error · RuntimeError
Codewhale terminal receipt sandbox did not match launch
Error message
Codewhale terminal receipt sandbox did not match launch
What it means
The receipt's sandbox_posture must equal the sandbox value the harness computed for the launch (the literal config.sandbox, or 'workspace-write'/'external-sandbox' when sandbox='auto' resolves by runtime type). A mismatch means the binary ran under a different isolation level than the rollout declared.
Solutions
- Compare terminal.sandbox_posture in the receipt with the resolved sandbox ('workspace-write' on subprocess runtimes, 'external-sandbox' in isolated runtimes)
- Set config.sandbox explicitly to the posture your runtime supports instead of 'auto'
- Ensure the binary is the pinned release that honors --sandbox
Defensive patterns
Strategy: try-catch
Try / catch
try:
result = await harness.launch(ctx, trace, runtime, endpoint, secret, mcp_urls)
except RuntimeError as e:
if "sandbox did not match launch" in str(e):
# compare receipt sandbox_posture with resolved sandbox; set config.sandbox explicitly
...
else:
raise Prevention
- Set config.sandbox explicitly rather than relying on 'auto' resolution
- Know the resolved mapping: subprocess -> workspace-write, isolated -> external-sandbox
- Use sandbox-capable pinned binaries
When it happens
Trigger: launch() with config.sandbox set (or auto-resolved) where the binary reports a different sandbox_posture — e.g. the binary lacks sandbox support, ignored --sandbox, or fell back to a default because the requested mode is unavailable in the runtime.
Common situations: Auto-resolution surprise: expecting 'auto' to appear in the receipt instead of the resolved value; a custom binary without sandbox support; runtime type changed between subprocess and isolated, changing the resolved posture.
Understand the failure class
Background: "invalid response format", "malformed payload", "missing data field": when an API returns 200 but the response shape is wrong — this error's family across 23 libraries.
Related errors
- Codewhale terminal receipt did not confirm auto tools
- Codewhale successful run contained an error event
- Codewhale terminal receipt did not use provider openai
- Codewhale terminal receipt model did not match rollout
- Cloud agent harness execution failed
AI-assisted analysis of Hmbown/CodeWhale@433685b202 (2026-09-15).
Data as JSON: /api/errors/4a725c9dfc4930ce.
Report an issue: GitHub.
Appendix: source
Thrown at integrations/verifiers-codewhale/codewhale_harness/harness.py:234
argv.extend(["--max-turns", str(self.config.max_turns)])
if self.config.disabled_tools:
argv.extend(["--disallowed-tools", ",".join(self.config.disabled_tools)])
if system:
argv.extend(["--append-system-prompt", system])
argv.extend(["--", str(prompt or "")])
result = await runtime.run_program(argv, env)
if result.exit_code == 0:
receipt = _parse_stream_receipt(result.stdout)
terminal = receipt["terminal"]
if terminal.get("provider") != "openai":
raise RuntimeError("Codewhale terminal receipt did not use provider openai")
if terminal.get("model") != ctx.model:
raise RuntimeError("Codewhale terminal receipt model did not match rollout")
if terminal.get("approval_posture") != "auto_tools":
raise RuntimeError("Codewhale terminal receipt did not confirm auto tools")
if terminal.get("sandbox_posture") != sandbox:
raise RuntimeError("Codewhale terminal receipt sandbox did not match launch")
if receipt["events"].get("error", 0) != 0:
raise RuntimeError("Codewhale successful run contained an error event")
if terminal.get("status") != "completed":
raise RuntimeError("Codewhale terminal receipt did not report completion")
if terminal.get("termination_reason") != "resolved":
raise RuntimeError("Codewhale terminal receipt was not resolved")
trace.info["codewhale"] = receipt
return result
def _has_version(output: str, version: str) -> bool:
return (
re.search(
rf"(?<![0-9A-Za-z.+-]){re.escape(version)}(?![0-9A-Za-z.+-])",
output,
)
is not None
)View on GitHub (pinned to 433685b202)