{"record":{"id":"1ec7d607a40c7942","repo":"google-gemini/gemini-cli","slug":"running-sandbox-from-a-sensitive-host-directory","errorCode":null,"errorMessage":"Running sandbox from a sensitive host directory '${configTargetDir}' is strictly prohibited","messagePattern":"Running sandbox from a sensitive host directory '(.+?)' is strictly prohibited","errorType":"exception","errorClass":"FatalSandboxError","httpStatus":null,"severity":"critical","filePath":"packages/cli/src/utils/sandbox.ts","lineNumber":234,"sourceCode":"        const args = [\n          '-D',\n          `TARGET_DIR=${targetDir}`,\n          '-D',\n          `TMP_DIR=${resolvedTmpDir}`,\n          '-D',\n          `HOME_DIR=${fs.realpathSync(homedir())}`,\n          '-D',\n          `CACHE_DIR=${fs.realpathSync((await execAsync('getconf DARWIN_USER_CACHE_DIR')).stdout.trim())}`,\n        ];\n\n        // Add included directories from the workspace context\n        // Always add 5 INCLUDE_DIR parameters to ensure .sb files can reference them\n        const MAX_INCLUDE_DIRS = 5;\n        const configTargetDir = cliConfig?.getTargetDir()\n          ? resolveToRealPath(cliConfig.getTargetDir())\n          : targetDir;\n        if (cliConfig?.getTargetDir() && isSensitiveHostPath(configTargetDir)) {\n          throw new FatalSandboxError(\n            `Running sandbox from a sensitive host directory '${configTargetDir}' is strictly prohibited`,\n          );\n        }\n        const includedDirs: string[] = [];\n\n        if (cliConfig) {\n          const workspaceContext = cliConfig.getWorkspaceContext();\n          const directories = workspaceContext.getDirectories();\n\n          // Filter out TARGET_DIR\n          for (const dir of directories) {\n            const realDir = resolveToRealPath(dir);\n            if (!realDir) {\n              continue;\n            }\n            if (realDir !== targetDir && realDir !== configTargetDir) {\n              if (isSensitiveHostPath(realDir)) {\n                debugLogger.warn(","sourceCodeStart":216,"sourceCodeEnd":252,"githubUrl":"https://github.com/google-gemini/gemini-cli/blob/6a466a7e2fe2b1255752c1e74f69b31f0216084d/packages/cli/src/utils/sandbox.ts#L216-L252","documentation":"A second, config-driven guard in start_sandbox: when cliConfig.getTargetDir() is set, it is resolved via resolveToRealPath and checked with isSensitiveHostPath. If the configured target directory is sensitive, sandbox startup is refused with FatalSandboxError. This catches cases where the configured target differs from process.cwd().","triggerScenarios":"start_sandbox invoked with a cliConfig whose getTargetDir() returns a sensitive host path (as opposed to error 2, which checks process.cwd()).","commonSituations":"Setting the working/target directory in settings.json to '/' or the home directory, or launching with a --target/-C style flag pointing at a system path.","solutions":["Change the configured target directory (settings.json 'targetDir' or CLI flag) to a normal project folder.","Ensure the target path does not resolve (through symlinks) into a sensitive directory.","Move the project to a non-sensitive location like ~/projects/."],"exampleFix":"// before (settings.json)\n{ \"targetDir\": \"/\" }\n// after\n{ \"targetDir\": \"/home/user/projects/my-app\" }","handlingStrategy":"validation","validationCode":"const target = resolveToRealPath(cliConfig.getTargetDir());\nconst SENSITIVE = ['/', '/etc', '/usr', '/var', '/root', os.homedir()];\nif (SENSITIVE.includes(target)) {\n  throw new Error(`targetDir '${target}' is sensitive; fix settings.json`);\n}","typeGuard":null,"tryCatchPattern":"try {\n  await start_sandbox(...);\n} catch (e) {\n  if (e instanceof FatalSandboxError && e.message.includes('sensitive host directory')) {\n    // inspect cliConfig.getTargetDir() and correct it\n  }\n}","preventionTips":["Keep targetDir in settings.json pointing at a real project path.","Beware symlinks: resolve the configured path to its realpath before judging safety.","Lint settings.json at startup to reject sensitive targetDir values early."],"tags":["sandbox","security","configuration"],"backgroundTag":"sensitive-host-directory-blocked","analyzedSha":"6a466a7e2fe2b1255752c1e74f69b31f0216084d","analyzedAt":"2026-09-16T18:14:43.978Z","contentChangedAt":"2026-09-16T18:14:43.978Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}