google-gemini/gemini-cli · critical · FatalSandboxError
Running sandbox from a sensitive host directory
Error message
Running sandbox from a sensitive host directory '${targetDir}' is strictly prohibited What it means
Before starting the sandbox, the CLI resolves the current working directory (fs.realpathSync(process.cwd())) and rejects it with FatalSandboxError if isSensitiveHostPath classifies it as sensitive (e.g. /, /etc, /root, home dir itself, system paths). This prevents mounting or exposing critical host directories inside the sandbox container.
Solutions
- cd into a dedicated project directory (e.g. mkdir ~/projects/app && cd ~/projects/app) before launching.
- Pass --workspace-root or the equivalent CLI flag pointing at a non-sensitive project directory.
- If the path is genuinely safe, move the project out of the sensitive location rather than bypassing the check.
Example fix
// before cd ~ && gemini --sandbox // after cd ~/projects/my-app && gemini --sandbox
Defensive patterns
Strategy: validation
Validate before calling
const cwd = fs.realpathSync(process.cwd());
const SENSITIVE = ['/', '/etc', '/usr', '/var', '/root', os.homedir()];
if (SENSITIVE.includes(cwd)) {
throw new Error(`Refusing to run sandbox from sensitive dir: ${cwd}`);
} Try / catch
try {
await start_sandbox(...);
} catch (e) {
if (e instanceof FatalSandboxError && e.message.includes('sensitive host directory')) {
console.error('Run from a dedicated project directory, not a system path.');
}
} Prevention
- Always launch the CLI from a dedicated project folder.
- Avoid opening terminals in / or ~ as a habit.
- Set WorkingDirectory explicitly in scripts/services that invoke the CLI.
When it happens
Trigger: Calling start_sandbox when the resolved process.cwd() is a sensitive host path such as /, /etc, /usr, the user's home directory, or another path matched by isSensitiveHostPath.
Common situations: Launching the CLI from '/' after cd /, from a shell opened in the home directory (~), or from system directories while trying to 'edit all files'.
Related errors
- Access to forbidden path is denied
- Circular symlink detected
- ENOENT
- Failed to mount workspace into LXC container
- Missing mount path ' ' listed in SANDBOX_MOUNTS
AI-assisted analysis of google-gemini/gemini-cli@6a466a7e2f (2026-09-16).
Data as JSON: /api/errors/4f19bd3065eef641.
Report an issue: GitHub.
Appendix: source
Thrown at packages/cli/src/utils/sandbox.ts:190
}
}
try {
if (!fs.existsSync(profileFile)) {
throw new FatalSandboxError(
`Missing macos seatbelt profile file '${profileFile}'`,
);
}
debugLogger.log(`using macos seatbelt (profile: ${profile}) ...`);
// if DEBUG is set, convert to --inspect-brk in NODE_OPTIONS
const nodeOptions = [
...(process.env['DEBUG'] ? ['--inspect-brk'] : []),
...nodeArgs,
].join(' ');
const targetDir = fs.realpathSync(process.cwd());
if (isSensitiveHostPath(targetDir)) {
throw new FatalSandboxError(
`Running sandbox from a sensitive host directory '${targetDir}' is strictly prohibited`,
);
}
const hostTmpDir = fs.realpathSync(os.tmpdir());
const resolvedTmpDir = fs.mkdtempSync(
path.join(hostTmpDir, 'gemini-sandbox-'),
);
try {
fs.chmodSync(resolvedTmpDir, 0o700);
} catch {
// Silently ignore permission errors on non-POSIX filesystems
}
sandboxTmpDir = resolvedTmpDir;
const userHome = homedir();
if (userHome) {
const seatbeltCacheDir = path.join(userHome, '.cache', GEMINI_DIR);View on GitHub (pinned to 6a466a7e2f)