{"record":{"id":"4cf8fdb6f41cbca2","repo":"google-gemini/gemini-cli","slug":"tool-sandboxing-is-not-yet-implemented","errorCode":null,"errorMessage":"Tool sandboxing is not yet implemented.","messagePattern":"Tool sandboxing is not yet implemented\\.","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"packages/core/src/services/sandboxManager.ts","lineNumber":344,"sourceCode":"  }\n\n  getWorkspace(): string {\n    return this.options?.workspace ?? process.cwd();\n  }\n\n  getOptions(): GlobalSandboxOptions | undefined {\n    return this.options;\n  }\n}\n\n/**\n * A SandboxManager implementation that just runs locally (no sandboxing yet).\n */\nexport class LocalSandboxManager implements SandboxManager {\n  constructor(private options?: GlobalSandboxOptions) {}\n\n  async prepareCommand(_req: SandboxRequest): Promise<SandboxedCommand> {\n    throw new Error('Tool sandboxing is not yet implemented.');\n  }\n\n  isKnownSafeCommand(_args: string[], _cwd?: string): boolean {\n    return false;\n  }\n\n  isDangerousCommand(_args: string[], _cwd?: string): boolean {\n    return false;\n  }\n\n  parseDenials(): undefined {\n    return undefined;\n  }\n\n  getWorkspace(): string {\n    return this.options?.workspace ?? process.cwd();\n  }\n","sourceCodeStart":326,"sourceCodeEnd":362,"githubUrl":"https://github.com/google-gemini/gemini-cli/blob/6a466a7e2fe2b1255752c1e74f69b31f0216084d/packages/core/src/services/sandboxManager.ts#L326-L362","documentation":"LocalSandboxManager is a placeholder implementation of SandboxManager that runs commands without sandboxing. Its prepareCommand is a stub that unconditionally throws, signaling that per-tool sandboxing has not been implemented in the local (non-sandboxed) manager. Callers should use the real sandboxed manager or avoid requesting a sandboxed command here.","triggerScenarios":"Calling prepareCommand on a LocalSandboxManager instance (i.e. requesting a SandboxedCommand while the CLI/core is configured with the local, no-sandbox manager).","commonSituations":"Enabling a tool-sandboxing feature or code path while running without a configured sandbox backend; using an API that assumes a Docker/LXC-backed SandboxManager but getting the local default.","solutions":["Enable a real sandbox (e.g. --sandbox docker/lxc or the equivalent settings entry) so a backed SandboxManager is used.","Route the command through non-sandboxed execution if sandboxing is not required.","Wait for/upgrade to a version that implements tool sandboxing in LocalSandboxManager."],"exampleFix":"// before\ngemini  # default (local manager), calls tool.prepareCommand\n// after\ngemini --sandbox docker","handlingStrategy":"try-catch","validationCode":"if (manager instanceof LocalSandboxManager) {\n  throw new Error('tool sandboxing requires a docker/lxc sandbox manager');\n}","typeGuard":null,"tryCatchPattern":"try {\n  const cmd = await manager.prepareCommand(req);\n} catch (e) {\n  if (e.message.includes('not yet implemented')) {\n    // fall back to unsandboxed execution or enable --sandbox docker/lxc\n  }\n}","preventionTips":["Enable a real sandbox backend before exercising sandboxed tool execution.","Feature-detect: check the manager type rather than assuming prepareCommand works.","Track CLI/core release notes for when local tool sandboxing ships."],"tags":["sandbox","not-implemented","configuration"],"backgroundTag":"method-not-implemented","analyzedSha":"6a466a7e2fe2b1255752c1e74f69b31f0216084d","analyzedAt":"2026-09-16T18:14:43.978Z","contentChangedAt":"2026-09-16T18:14:43.978Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}