Hmbown/CodeWhale · error

sandbox_mode ' ' is not allowed by requirements ( )

Error message

sandbox_mode '{mode}' is not allowed by requirements ({})

What it means

The TUI config loader validates `sandbox_mode` against `requirements.allowed_sandbox_modes` when that list is non-empty. If the configured mode (case-insensitively compared) is not in the allowlist, loading fails with the list of permitted values. This prevents running with a sandbox mode the deployment's requirements disallow.

Solutions

  1. Set `sandbox_mode` to one of the allowed values shown in the error message
  2. Adjust the `requirements.allowed_sandbox_modes` allowlist if the mode is legitimately needed
  3. Correct the value spelling in your config (comparison is case-insensitive)

Example fix

// before
sandbox_mode = "full-access"
// after
sandbox_mode = "workspace-write"
Defensive patterns

Strategy: validation

Validate before calling

if !requirements.allowed_sandbox_modes.is_empty()
    && !requirements.allowed_sandbox_modes.iter().any(|m| m.eq_ignore_ascii_case(&mode)) {
    eprintln!("sandbox_mode {mode} not allowed; allowed: {:?}", requirements.allowed_sandbox_modes);
}

Type guard

fn sandbox_mode_allowed(mode: &str, requirements: &Requirements) -> bool {
    requirements.allowed_sandbox_modes.is_empty()
        || requirements.allowed_sandbox_modes.iter().any(|m| m.eq_ignore_ascii_case(mode))
}

Prevention

When it happens

Trigger: Setting `sandbox_mode` (e.g. `read-only`, `workspace-write`, `danger-full-access`) to a value missing from a non-empty `requirements.allowed_sandbox_modes` list during config validation.

Common situations: Typo in config.toml; copy-pasting a sandbox mode from older docs; enterprise requirements files that only allow read-only modes while a user config sets workspace-write.

Understand the failure class

Background: "Invalid value" and "allowed values are" config errors: what your library rejected and how to fix it — this error's family across 41 libraries.

Related errors


AI-assisted analysis of Hmbown/CodeWhale@73e0f67d83 (2026-09-22). Data as JSON: /api/errors/9bad900ddaf2fe6b. Report an issue: GitHub.

Appendix: source

Thrown at crates/tui/src/config.rs:11756

            .iter()
            .any(|p| p.eq_ignore_ascii_case(&policy))
        {
            anyhow::bail!(
                "approval_policy '{policy}' is not allowed by requirements ({})",
                requirements.allowed_approval_policies.join(", ")
            );
        }
    }
    if !requirements.allowed_sandbox_modes.is_empty()
        && let Some(mode) = config.sandbox_mode.as_ref()
    {
        let mode = mode.to_ascii_lowercase();
        if !requirements
            .allowed_sandbox_modes
            .iter()
            .any(|m| m.eq_ignore_ascii_case(&mode))
        {
            anyhow::bail!(
                "sandbox_mode '{mode}' is not allowed by requirements ({})",
                requirements.allowed_sandbox_modes.join(", ")
            );
        }
    }

    Ok(())
}

fn merge_features(
    base: Option<FeaturesToml>,
    override_cfg: Option<FeaturesToml>,
) -> Option<FeaturesToml> {
    match (base, override_cfg) {
        (None, None) => None,
        (Some(mut base), Some(override_cfg)) => {
            for (key, value) in override_cfg.entries {
                base.entries.insert(key, value);

View on GitHub (pinned to 73e0f67d83)