{"record":{"id":"da1bab57bcaa0e45","repo":"Tencent/WeKnora","slug":"security-validation-failed","errorCode":null,"errorMessage":"security validation failed","messagePattern":"security validation failed","errorType":"error_code","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/sandbox/sandbox.go","lineNumber":105,"sourceCode":"\t// DefaultCubeHTTPTimeout bounds a single HTTP call to the CubeAPI\n\t// (excluding user script execution which has its own per-call timeout).\n\tDefaultCubeHTTPTimeout = 30 * time.Second\n\n\t// DefaultE2BSandboxTTL matches the E2B SDK's built-in default so an\n\t// unset E2BSandboxTTL still yields a valid sandbox lifetime.\n\tDefaultE2BSandboxTTL = 5 * time.Minute\n\t// DefaultE2BHTTPTimeout bounds a single HTTP call to the E2B API.\n\tDefaultE2BHTTPTimeout = 30 * time.Second\n)\n\n// Common errors\nvar (\n\tErrSandboxDisabled   = errors.New(\"sandbox is disabled\")\n\tErrTimeout           = errors.New(\"execution timed out\")\n\tErrScriptNotFound    = errors.New(\"script not found\")\n\tErrInvalidScript     = errors.New(\"invalid script\")\n\tErrExecutionFailed   = errors.New(\"script execution failed\")\n\tErrSecurityViolation = errors.New(\"security validation failed\")\n\tErrDangerousCommand  = errors.New(\"script contains dangerous command\")\n\tErrArgInjection      = errors.New(\"argument injection detected\")\n\tErrStdinInjection    = errors.New(\"stdin injection detected\")\n)\n\n// Sandbox defines the interface for isolated script execution\ntype Sandbox interface {\n\t// Execute runs a script in an isolated environment\n\tExecute(ctx context.Context, config *ExecuteConfig) (*ExecuteResult, error)\n\n\t// Cleanup releases sandbox resources\n\tCleanup(ctx context.Context) error\n\n\t// Type returns the sandbox type\n\tType() SandboxType\n\n\t// IsAvailable checks if the sandbox is available for use\n\tIsAvailable(ctx context.Context) bool","sourceCodeStart":87,"sourceCodeEnd":123,"githubUrl":"https://github.com/Tencent/WeKnora/blob/988cbb03305e055d8ebb7d46d9ac6cc0803cd074/internal/sandbox/sandbox.go#L87-L123","documentation":"Sentinel ErrSecurityViolation returned by the sandbox manager when the pre-execution security validator rejects a script (manager.go:100) or when the provider reports validation errors in its result (manager.go:137). The script was blocked before/at execution because it violated security policy — this is a deliberate rejection, not a runtime crash.","triggerScenarios":"Thrown at internal/sandbox/sandbox.go:105 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Inspect result.Stderr ('Security validation failed: ...') for the exact rule triggered","Remove the offending construct (network access, file system escapes, privileged commands) from the script","Do not retry unchanged — the block is deterministic by design","Log the attempt for security auditing"],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"988cbb03305e055d8ebb7d46d9ac6cc0803cd074","analyzedAt":"2026-09-02T14:41:08.344Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-08T10:18:20.063Z"}