{"record":{"id":"4a2f5a0f87f8af4a","repo":"openai/codex","slug":"verify-fd-mount-is-only-supported-in-the-inner-s","errorCode":null,"errorMessage":"--verify-fd-mount is only supported in the inner sandbox stage","messagePattern":"--verify-fd-mount is only supported in the inner sandbox stage","errorType":"panic","errorClass":null,"httpStatus":null,"severity":"error","filePath":"codex-rs/linux-sandbox/src/linux_run_main.rs","lineNumber":177,"sourceCode":"pub fn run_main() -> ! {\n    let LandlockCommand {\n        sandbox_policy_cwd,\n        command_cwd,\n        permission_profile,\n        use_legacy_landlock,\n        apply_seccomp_then_exec,\n        allow_network_for_proxy,\n        proxy_route_spec,\n        verify_fd_mounts,\n        no_proc,\n        command,\n    } = LandlockCommand::parse();\n\n    if command.is_empty() {\n        panic!(\"No command specified to execute.\");\n    }\n    if !apply_seccomp_then_exec && !verify_fd_mounts.is_empty() {\n        panic!(\"--verify-fd-mount is only supported in the inner sandbox stage\");\n    }\n    ensure_inner_stage_mode_is_valid(apply_seccomp_then_exec, use_legacy_landlock);\n    let EffectivePermissions {\n        permission_profile,\n        mut file_system_sandbox_policy,\n        network_sandbox_policy,\n    } = resolve_permission_profile(permission_profile).unwrap_or_else(|err| panic!(\"{err}\"));\n    ensure_legacy_landlock_mode_supports_policy(\n        use_legacy_landlock,\n        &file_system_sandbox_policy,\n        network_sandbox_policy,\n        &sandbox_policy_cwd,\n    );\n\n    // Inner stage: apply seccomp/no_new_privs after bubblewrap has already\n    // established the filesystem view.\n    if apply_seccomp_then_exec {\n        if let Err(err) = crate::fd_mount::verify_fd_mounts(&verify_fd_mounts) {","sourceCodeStart":159,"sourceCodeEnd":195,"githubUrl":"https://github.com/openai/codex/blob/339751715c64496cb86246bfb3935f40e309dd3d/codex-rs/linux-sandbox/src/linux_run_main.rs#L159-L195","documentation":"Error \"--verify-fd-mount is only supported in the inner sandbox stage\" thrown in openai/codex.","triggerScenarios":"Thrown at codex-rs/linux-sandbox/src/linux_run_main.rs:177 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":[],"exampleFix":null,"handlingStrategy":null,"validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"339751715c64496cb86246bfb3935f40e309dd3d","analyzedAt":"2026-08-25T05:35:09.876Z","schemaVersion":2},"datasetVersion":"2026-08-25T06:17:31.827Z"}