Hmbown/CodeWhale · error
sandbox_mode ' ' is not allowed by requirements ( )
Error message
sandbox_mode '{mode}' is not allowed by requirements ({}) What it means
The TUI config loader validates `sandbox_mode` against `requirements.allowed_sandbox_modes` when that list is non-empty. If the configured mode (case-insensitively compared) is not in the allowlist, loading fails with the list of permitted values. This prevents running with a sandbox mode the deployment's requirements disallow.
Solutions
- Set `sandbox_mode` to one of the allowed values shown in the error message
- Adjust the `requirements.allowed_sandbox_modes` allowlist if the mode is legitimately needed
- Correct the value spelling in your config (comparison is case-insensitive)
Example fix
// before sandbox_mode = "full-access" // after sandbox_mode = "workspace-write"
Defensive patterns
Strategy: validation
Validate before calling
if !requirements.allowed_sandbox_modes.is_empty()
&& !requirements.allowed_sandbox_modes.iter().any(|m| m.eq_ignore_ascii_case(&mode)) {
eprintln!("sandbox_mode {mode} not allowed; allowed: {:?}", requirements.allowed_sandbox_modes);
} Type guard
fn sandbox_mode_allowed(mode: &str, requirements: &Requirements) -> bool {
requirements.allowed_sandbox_modes.is_empty()
|| requirements.allowed_sandbox_modes.iter().any(|m| m.eq_ignore_ascii_case(mode))
} Prevention
- Use only sandbox modes permitted by your deployment's requirements file
- Re-check sandbox_mode after changing environments (dev vs enterprise)
- Prefer the modes listed in the error's allowlist
When it happens
Trigger: Setting `sandbox_mode` (e.g. `read-only`, `workspace-write`, `danger-full-access`) to a value missing from a non-empty `requirements.allowed_sandbox_modes` list during config validation.
Common situations: Typo in config.toml; copy-pasting a sandbox mode from older docs; enterprise requirements files that only allow read-only modes while a user config sets workspace-write.
Understand the failure class
Background: "Invalid value" and "allowed values are" config errors: what your library rejected and how to fix it — this error's family across 41 libraries.
Related errors
- Invalid sandbox_mode
- Unsupported sandbox_backend setting. Choose opensandbox, or…
- agent profile provider cannot be empty
- agent profile provider must be a simple provider id
- api_key cannot be empty string
AI-assisted analysis of Hmbown/CodeWhale@73e0f67d83 (2026-09-22).
Data as JSON: /api/errors/9bad900ddaf2fe6b.
Report an issue: GitHub.
Appendix: source
Thrown at crates/tui/src/config.rs:11756
.iter()
.any(|p| p.eq_ignore_ascii_case(&policy))
{
anyhow::bail!(
"approval_policy '{policy}' is not allowed by requirements ({})",
requirements.allowed_approval_policies.join(", ")
);
}
}
if !requirements.allowed_sandbox_modes.is_empty()
&& let Some(mode) = config.sandbox_mode.as_ref()
{
let mode = mode.to_ascii_lowercase();
if !requirements
.allowed_sandbox_modes
.iter()
.any(|m| m.eq_ignore_ascii_case(&mode))
{
anyhow::bail!(
"sandbox_mode '{mode}' is not allowed by requirements ({})",
requirements.allowed_sandbox_modes.join(", ")
);
}
}
Ok(())
}
fn merge_features(
base: Option<FeaturesToml>,
override_cfg: Option<FeaturesToml>,
) -> Option<FeaturesToml> {
match (base, override_cfg) {
(None, None) => None,
(Some(mut base), Some(override_cfg)) => {
for (key, value) in override_cfg.entries {
base.entries.insert(key, value);View on GitHub (pinned to 73e0f67d83)