Hmbown/CodeWhale · error

read_only execution requires an enforcing native read-only…

Error message

read_only execution requires an enforcing native read-only sandbox; nothing was run

What it means

require_native_readonly_execution enforces that read_only execution runs only under an actually enforcing native sandbox (macOS Seatbelt or Linux bubblewrap, per platform); on any other sandbox type nothing is run, because claiming read-only enforcement without a kernel-level barrier would be false. This is a deliberate fail-closed guard, not a sandbox bug.

Solutions

  1. Install/enable a native sandbox (macOS Seatbelt or Linux Bubblewrap) so read_only can be enforced.
  2. Run without the read_only policy if no enforcing sandbox is available.
  3. On distributions without bubblewrap, fall back to a non-read-only posture explicitly rather than relying on soft enforcement.
Defensive patterns

Strategy: fallback

When it happens

Trigger: Thrown at crates/tui/src/tools/shell.rs:4043 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of Hmbown/CodeWhale@73e0f67d83 (2026-09-22). Data as JSON: /api/errors/6d7041f99a25914d. Report an issue: GitHub.

Appendix: source

Thrown at crates/tui/src/tools/shell.rs:4043

}

fn is_native_readonly_sandbox(sandbox_type: SandboxType) -> bool {
    match sandbox_type {
        #[cfg(target_os = "macos")]
        SandboxType::MacosSeatbelt => true,
        #[cfg(all(target_os = "linux", not(target_env = "ohos")))]
        SandboxType::LinuxBubblewrap => true,
        _ => false,
    }
}

fn require_native_readonly_execution(exec_env: &ExecEnv) -> Result<()> {
    if matches!(exec_env.policy, ExecutionSandboxPolicy::ReadOnly)
        && is_native_readonly_sandbox(exec_env.sandbox_type)
    {
        Ok(())
    } else {
        Err(anyhow!(
            "read_only execution requires an enforcing native read-only sandbox; nothing was run"
        ))
    }
}

/// `exec_shell_input_is_parallel_readonly` with the agent-posture classifier:
/// same input-shape restrictions (run action only, no background/tty/stdin),
/// but commands are judged by [`is_agent_readonly_shell_command`] so
/// `ShellPolicy::ReadOnly` agents keep a usable inspection surface
/// (pipelines, globs, `git -C`, `find`, `sed -n`, `npm view`).
fn exec_shell_input_agent_readonly(input: &serde_json::Value) -> bool {
    if enforced_readonly_input(input) {
        return true;
    }
    if !exec_shell_input_is_parallel_readonly_shape(input) {
        return false;
    }
    let command = input

View on GitHub (pinned to 73e0f67d83)