google-gemini/gemini-cli · critical · FatalSandboxError

Running sandbox from a sensitive host directory

Error message

Running sandbox from a sensitive host directory '${targetDir}' is strictly prohibited

What it means

Before starting the sandbox, the CLI resolves the current working directory (fs.realpathSync(process.cwd())) and rejects it with FatalSandboxError if isSensitiveHostPath classifies it as sensitive (e.g. /, /etc, /root, home dir itself, system paths). This prevents mounting or exposing critical host directories inside the sandbox container.

Solutions

  1. cd into a dedicated project directory (e.g. mkdir ~/projects/app && cd ~/projects/app) before launching.
  2. Pass --workspace-root or the equivalent CLI flag pointing at a non-sensitive project directory.
  3. If the path is genuinely safe, move the project out of the sensitive location rather than bypassing the check.

Example fix

// before
cd ~ && gemini --sandbox
// after
cd ~/projects/my-app && gemini --sandbox
Defensive patterns

Strategy: validation

Validate before calling

const cwd = fs.realpathSync(process.cwd());
const SENSITIVE = ['/', '/etc', '/usr', '/var', '/root', os.homedir()];
if (SENSITIVE.includes(cwd)) {
  throw new Error(`Refusing to run sandbox from sensitive dir: ${cwd}`);
}

Try / catch

try {
  await start_sandbox(...);
} catch (e) {
  if (e instanceof FatalSandboxError && e.message.includes('sensitive host directory')) {
    console.error('Run from a dedicated project directory, not a system path.');
  }
}

Prevention

When it happens

Trigger: Calling start_sandbox when the resolved process.cwd() is a sensitive host path such as /, /etc, /usr, the user's home directory, or another path matched by isSensitiveHostPath.

Common situations: Launching the CLI from '/' after cd /, from a shell opened in the home directory (~), or from system directories while trying to 'edit all files'.

Related errors


AI-assisted analysis of google-gemini/gemini-cli@6a466a7e2f (2026-09-16). Data as JSON: /api/errors/4f19bd3065eef641. Report an issue: GitHub.

Appendix: source

Thrown at packages/cli/src/utils/sandbox.ts:190

        }
      }

      try {
        if (!fs.existsSync(profileFile)) {
          throw new FatalSandboxError(
            `Missing macos seatbelt profile file '${profileFile}'`,
          );
        }
        debugLogger.log(`using macos seatbelt (profile: ${profile}) ...`);
        // if DEBUG is set, convert to --inspect-brk in NODE_OPTIONS
        const nodeOptions = [
          ...(process.env['DEBUG'] ? ['--inspect-brk'] : []),
          ...nodeArgs,
        ].join(' ');

        const targetDir = fs.realpathSync(process.cwd());
        if (isSensitiveHostPath(targetDir)) {
          throw new FatalSandboxError(
            `Running sandbox from a sensitive host directory '${targetDir}' is strictly prohibited`,
          );
        }

        const hostTmpDir = fs.realpathSync(os.tmpdir());
        const resolvedTmpDir = fs.mkdtempSync(
          path.join(hostTmpDir, 'gemini-sandbox-'),
        );
        try {
          fs.chmodSync(resolvedTmpDir, 0o700);
        } catch {
          // Silently ignore permission errors on non-POSIX filesystems
        }
        sandboxTmpDir = resolvedTmpDir;

        const userHome = homedir();
        if (userHome) {
          const seatbeltCacheDir = path.join(userHome, '.cache', GEMINI_DIR);

View on GitHub (pinned to 6a466a7e2f)