{"record":{"id":"4f19bd3065eef641","repo":"google-gemini/gemini-cli","slug":"running-sandbox-from-a-sensitive-host-directory-targetdir-is","errorCode":null,"errorMessage":"Running sandbox from a sensitive host directory '${targetDir}' is strictly prohibited","messagePattern":"Running sandbox from a sensitive host directory '(.+?)' is strictly prohibited","errorType":"exception","errorClass":"FatalSandboxError","httpStatus":null,"severity":"critical","filePath":"packages/cli/src/utils/sandbox.ts","lineNumber":190,"sourceCode":"        }\n      }\n\n      try {\n        if (!fs.existsSync(profileFile)) {\n          throw new FatalSandboxError(\n            `Missing macos seatbelt profile file '${profileFile}'`,\n          );\n        }\n        debugLogger.log(`using macos seatbelt (profile: ${profile}) ...`);\n        // if DEBUG is set, convert to --inspect-brk in NODE_OPTIONS\n        const nodeOptions = [\n          ...(process.env['DEBUG'] ? ['--inspect-brk'] : []),\n          ...nodeArgs,\n        ].join(' ');\n\n        const targetDir = fs.realpathSync(process.cwd());\n        if (isSensitiveHostPath(targetDir)) {\n          throw new FatalSandboxError(\n            `Running sandbox from a sensitive host directory '${targetDir}' is strictly prohibited`,\n          );\n        }\n\n        const hostTmpDir = fs.realpathSync(os.tmpdir());\n        const resolvedTmpDir = fs.mkdtempSync(\n          path.join(hostTmpDir, 'gemini-sandbox-'),\n        );\n        try {\n          fs.chmodSync(resolvedTmpDir, 0o700);\n        } catch {\n          // Silently ignore permission errors on non-POSIX filesystems\n        }\n        sandboxTmpDir = resolvedTmpDir;\n\n        const userHome = homedir();\n        if (userHome) {\n          const seatbeltCacheDir = path.join(userHome, '.cache', GEMINI_DIR);","sourceCodeStart":172,"sourceCodeEnd":208,"githubUrl":"https://github.com/google-gemini/gemini-cli/blob/6a466a7e2fe2b1255752c1e74f69b31f0216084d/packages/cli/src/utils/sandbox.ts#L172-L208","documentation":"Before starting the sandbox, the CLI resolves the current working directory (fs.realpathSync(process.cwd())) and rejects it with FatalSandboxError if isSensitiveHostPath classifies it as sensitive (e.g. /, /etc, /root, home dir itself, system paths). This prevents mounting or exposing critical host directories inside the sandbox container.","triggerScenarios":"Calling start_sandbox when the resolved process.cwd() is a sensitive host path such as /, /etc, /usr, the user's home directory, or another path matched by isSensitiveHostPath.","commonSituations":"Launching the CLI from '/' after cd /, from a shell opened in the home directory (~), or from system directories while trying to 'edit all files'.","solutions":["cd into a dedicated project directory (e.g. mkdir ~/projects/app && cd ~/projects/app) before launching.","Pass --workspace-root or the equivalent CLI flag pointing at a non-sensitive project directory.","If the path is genuinely safe, move the project out of the sensitive location rather than bypassing the check."],"exampleFix":"// before\ncd ~ && gemini --sandbox\n// after\ncd ~/projects/my-app && gemini --sandbox","handlingStrategy":"validation","validationCode":"const cwd = fs.realpathSync(process.cwd());\nconst SENSITIVE = ['/', '/etc', '/usr', '/var', '/root', os.homedir()];\nif (SENSITIVE.includes(cwd)) {\n  throw new Error(`Refusing to run sandbox from sensitive dir: ${cwd}`);\n}","typeGuard":null,"tryCatchPattern":"try {\n  await start_sandbox(...);\n} catch (e) {\n  if (e instanceof FatalSandboxError && e.message.includes('sensitive host directory')) {\n    console.error('Run from a dedicated project directory, not a system path.');\n  }\n}","preventionTips":["Always launch the CLI from a dedicated project folder.","Avoid opening terminals in / or ~ as a habit.","Set WorkingDirectory explicitly in scripts/services that invoke the CLI."],"tags":["sandbox","security","filesystem"],"backgroundTag":"sensitive-host-directory-blocked","analyzedSha":"6a466a7e2fe2b1255752c1e74f69b31f0216084d","analyzedAt":"2026-09-16T18:14:43.978Z","contentChangedAt":"2026-09-16T18:14:43.978Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}