google-gemini/gemini-cli · critical · FatalSandboxError

Running sandbox from a sensitive host directory

Error message

Running sandbox from a sensitive host directory '${configTargetDir}' is strictly prohibited

What it means

A second, config-driven guard in start_sandbox: when cliConfig.getTargetDir() is set, it is resolved via resolveToRealPath and checked with isSensitiveHostPath. If the configured target directory is sensitive, sandbox startup is refused with FatalSandboxError. This catches cases where the configured target differs from process.cwd().

Solutions

  1. Change the configured target directory (settings.json 'targetDir' or CLI flag) to a normal project folder.
  2. Ensure the target path does not resolve (through symlinks) into a sensitive directory.
  3. Move the project to a non-sensitive location like ~/projects/.

Example fix

// before (settings.json)
{ "targetDir": "/" }
// after
{ "targetDir": "/home/user/projects/my-app" }
Defensive patterns

Strategy: validation

Validate before calling

const target = resolveToRealPath(cliConfig.getTargetDir());
const SENSITIVE = ['/', '/etc', '/usr', '/var', '/root', os.homedir()];
if (SENSITIVE.includes(target)) {
  throw new Error(`targetDir '${target}' is sensitive; fix settings.json`);
}

Try / catch

try {
  await start_sandbox(...);
} catch (e) {
  if (e instanceof FatalSandboxError && e.message.includes('sensitive host directory')) {
    // inspect cliConfig.getTargetDir() and correct it
  }
}

Prevention

When it happens

Trigger: start_sandbox invoked with a cliConfig whose getTargetDir() returns a sensitive host path (as opposed to error 2, which checks process.cwd()).

Common situations: Setting the working/target directory in settings.json to '/' or the home directory, or launching with a --target/-C style flag pointing at a system path.

Related errors


AI-assisted analysis of google-gemini/gemini-cli@6a466a7e2f (2026-09-16). Data as JSON: /api/errors/1ec7d607a40c7942. Report an issue: GitHub.

Appendix: source

Thrown at packages/cli/src/utils/sandbox.ts:234

        const args = [
          '-D',
          `TARGET_DIR=${targetDir}`,
          '-D',
          `TMP_DIR=${resolvedTmpDir}`,
          '-D',
          `HOME_DIR=${fs.realpathSync(homedir())}`,
          '-D',
          `CACHE_DIR=${fs.realpathSync((await execAsync('getconf DARWIN_USER_CACHE_DIR')).stdout.trim())}`,
        ];

        // Add included directories from the workspace context
        // Always add 5 INCLUDE_DIR parameters to ensure .sb files can reference them
        const MAX_INCLUDE_DIRS = 5;
        const configTargetDir = cliConfig?.getTargetDir()
          ? resolveToRealPath(cliConfig.getTargetDir())
          : targetDir;
        if (cliConfig?.getTargetDir() && isSensitiveHostPath(configTargetDir)) {
          throw new FatalSandboxError(
            `Running sandbox from a sensitive host directory '${configTargetDir}' is strictly prohibited`,
          );
        }
        const includedDirs: string[] = [];

        if (cliConfig) {
          const workspaceContext = cliConfig.getWorkspaceContext();
          const directories = workspaceContext.getDirectories();

          // Filter out TARGET_DIR
          for (const dir of directories) {
            const realDir = resolveToRealPath(dir);
            if (!realDir) {
              continue;
            }
            if (realDir !== targetDir && realDir !== configTargetDir) {
              if (isSensitiveHostPath(realDir)) {
                debugLogger.warn(

View on GitHub (pinned to 6a466a7e2f)