{"record":{"id":"6d7041f99a25914d","repo":"Hmbown/CodeWhale","slug":"read-only-execution-requires-an-enforcing-native-read-only","errorCode":null,"errorMessage":"read_only execution requires an enforcing native read-only sandbox; nothing was run","messagePattern":"read_only execution requires an enforcing native read-only sandbox; nothing was run","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"crates/tui/src/tools/shell.rs","lineNumber":4043,"sourceCode":"}\n\nfn is_native_readonly_sandbox(sandbox_type: SandboxType) -> bool {\n    match sandbox_type {\n        #[cfg(target_os = \"macos\")]\n        SandboxType::MacosSeatbelt => true,\n        #[cfg(all(target_os = \"linux\", not(target_env = \"ohos\")))]\n        SandboxType::LinuxBubblewrap => true,\n        _ => false,\n    }\n}\n\nfn require_native_readonly_execution(exec_env: &ExecEnv) -> Result<()> {\n    if matches!(exec_env.policy, ExecutionSandboxPolicy::ReadOnly)\n        && is_native_readonly_sandbox(exec_env.sandbox_type)\n    {\n        Ok(())\n    } else {\n        Err(anyhow!(\n            \"read_only execution requires an enforcing native read-only sandbox; nothing was run\"\n        ))\n    }\n}\n\n/// `exec_shell_input_is_parallel_readonly` with the agent-posture classifier:\n/// same input-shape restrictions (run action only, no background/tty/stdin),\n/// but commands are judged by [`is_agent_readonly_shell_command`] so\n/// `ShellPolicy::ReadOnly` agents keep a usable inspection surface\n/// (pipelines, globs, `git -C`, `find`, `sed -n`, `npm view`).\nfn exec_shell_input_agent_readonly(input: &serde_json::Value) -> bool {\n    if enforced_readonly_input(input) {\n        return true;\n    }\n    if !exec_shell_input_is_parallel_readonly_shape(input) {\n        return false;\n    }\n    let command = input","sourceCodeStart":4025,"sourceCodeEnd":4061,"githubUrl":"https://github.com/Hmbown/CodeWhale/blob/73e0f67d83c59909b571efdfc88c4bc28c309cb1/crates/tui/src/tools/shell.rs#L4025-L4061","documentation":"require_native_readonly_execution enforces that read_only execution runs only under an actually enforcing native sandbox (macOS Seatbelt or Linux bubblewrap, per platform); on any other sandbox type nothing is run, because claiming read-only enforcement without a kernel-level barrier would be false. This is a deliberate fail-closed guard, not a sandbox bug.","triggerScenarios":"Thrown at crates/tui/src/tools/shell.rs:4043 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Install/enable a native sandbox (macOS Seatbelt or Linux Bubblewrap) so read_only can be enforced.","Run without the read_only policy if no enforcing sandbox is available.","On distributions without bubblewrap, fall back to a non-read-only posture explicitly rather than relying on soft enforcement."],"exampleFix":null,"handlingStrategy":"fallback","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"73e0f67d83c59909b571efdfc88c4bc28c309cb1","analyzedAt":"2026-09-22T01:30:00.501Z","contentChangedAt":"2026-09-22T01:30:00.501Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}