google-gemini/gemini-cli · error · FatalSandboxError
Missing mount path ' ' listed in SANDBOX_MOUNTS
Error message
Missing mount path '${from}' listed in SANDBOX_MOUNTS What it means
Thrown while parsing SANDBOX_MOUNTS when a mount source path (`from`) is absolute but does not exist on the host filesystem (fs.existsSync returns false). Mounting a nonexistent host path causes Docker to create an empty directory owned by root, which is rarely intended, so it is rejected up front.
Solutions
- Create the missing host directory: `mkdir -p /opt/data`.
- Correct the path in SANDBOX_MOUNTS to the actual location.
- Ensure any service that populates the directory runs before the sandbox starts.
Example fix
// before // SANDBOX_MOUNTS=/opt/missing:/data:ro // after // mkdir -p /opt/missing // SANDBOX_MOUNTS=/opt/missing:/data:ro
Defensive patterns
Strategy: validation
Validate before calling
const fs = require('fs');
const path = require('path');
function ensureMountsExist(mountsStr) {
for (const raw of (mountsStr || '').split(',')) {
const m = raw.trim();
if (!m) continue;
const from = m.split(':')[0];
if (path.isAbsolute(from) && !fs.existsSync(from)) {
fs.mkdirSync(from, {recursive:true});
}
}
} Prevention
- Provision mount directories in your setup script before launching the sandbox.
- Use existence checks in a pre-flight validation step.
When it happens
Trigger: SANDBOX_MOUNTS contains an absolute path like /opt/data:/data but /opt/data does not exist on the host. Occurs right after the absolute-path check at sandbox.ts:482.
Common situations: Path was correct on a different machine. Typo in the absolute path. The directory is created by a sibling service that hasn't run yet. Mounting a path inside a container that was never bind-created on the host.
Related errors
- Path ' ' listed in SANDBOX_MOUNTS must be absolute
- SANDBOX_ENV must be a comma-separated list of key=value…
- Access to forbidden path is denied
- Cannot build sandbox using installed gemini binary; run…
- Circular symlink detected
AI-assisted analysis of google-gemini/gemini-cli@6a466a7e2f (2026-09-16).
Data as JSON: /api/errors/882a93b896b9602f.
Report an issue: GitHub.
Appendix: source
Thrown at packages/cli/src/utils/sandbox.ts:618
// parse mount as from:to:opts
let [from, to, opts] = mount.trim().split(':');
to = to || from; // default to mount at same path inside container
opts = opts || 'ro'; // default to read-only
mount = `${from}:${to}:${opts}`;
// check that from path is absolute
if (!path.isAbsolute(from)) {
throw new FatalSandboxError(
`Path '${from}' listed in SANDBOX_MOUNTS must be absolute`,
);
}
if (isSensitiveHostPath(from)) {
throw new FatalSandboxError(
`Mounting sensitive host path '${from}' listed in SANDBOX_MOUNTS is strictly prohibited`,
);
}
// check that from path exists on host
if (!fs.existsSync(from)) {
throw new FatalSandboxError(
`Missing mount path '${from}' listed in SANDBOX_MOUNTS`,
);
}
debugLogger.log(`SANDBOX_MOUNTS: ${from} -> ${to} (${opts})`);
args.push('--volume', mount);
}
}
}
// mount paths listed in config.allowedPaths
if (config.allowedPaths) {
for (const hostPath of config.allowedPaths) {
if (hostPath && path.isAbsolute(hostPath) && fs.existsSync(hostPath)) {
if (isSensitiveHostPath(hostPath)) {
debugLogger.warn(
`Skipping sensitive path '${hostPath}' in config.allowedPaths`,
);
continue;View on GitHub (pinned to 6a466a7e2f)