google-gemini/gemini-cli · critical · FatalSandboxError
Running sandbox from a sensitive host directory
Error message
Running sandbox from a sensitive host directory '${configTargetDir}' is strictly prohibited What it means
A second, config-driven guard in start_sandbox: when cliConfig.getTargetDir() is set, it is resolved via resolveToRealPath and checked with isSensitiveHostPath. If the configured target directory is sensitive, sandbox startup is refused with FatalSandboxError. This catches cases where the configured target differs from process.cwd().
Solutions
- Change the configured target directory (settings.json 'targetDir' or CLI flag) to a normal project folder.
- Ensure the target path does not resolve (through symlinks) into a sensitive directory.
- Move the project to a non-sensitive location like ~/projects/.
Example fix
// before (settings.json)
{ "targetDir": "/" }
// after
{ "targetDir": "/home/user/projects/my-app" } Defensive patterns
Strategy: validation
Validate before calling
const target = resolveToRealPath(cliConfig.getTargetDir());
const SENSITIVE = ['/', '/etc', '/usr', '/var', '/root', os.homedir()];
if (SENSITIVE.includes(target)) {
throw new Error(`targetDir '${target}' is sensitive; fix settings.json`);
} Try / catch
try {
await start_sandbox(...);
} catch (e) {
if (e instanceof FatalSandboxError && e.message.includes('sensitive host directory')) {
// inspect cliConfig.getTargetDir() and correct it
}
} Prevention
- Keep targetDir in settings.json pointing at a real project path.
- Beware symlinks: resolve the configured path to its realpath before judging safety.
- Lint settings.json at startup to reject sensitive targetDir values early.
When it happens
Trigger: start_sandbox invoked with a cliConfig whose getTargetDir() returns a sensitive host path (as opposed to error 2, which checks process.cwd()).
Common situations: Setting the working/target directory in settings.json to '/' or the home directory, or launching with a --target/-C style flag pointing at a system path.
Related errors
- Access to forbidden path is denied
- [Configuration] Untrusted workspace detected. Stripping…
- [Configuration] Untrusted workspace detected. Stripping…
- [Configuration] Untrusted workspace detected. Stripping…
- [Configuration] Untrusted workspace detected. Stripping…
AI-assisted analysis of google-gemini/gemini-cli@6a466a7e2f (2026-09-16).
Data as JSON: /api/errors/1ec7d607a40c7942.
Report an issue: GitHub.
Appendix: source
Thrown at packages/cli/src/utils/sandbox.ts:234
const args = [
'-D',
`TARGET_DIR=${targetDir}`,
'-D',
`TMP_DIR=${resolvedTmpDir}`,
'-D',
`HOME_DIR=${fs.realpathSync(homedir())}`,
'-D',
`CACHE_DIR=${fs.realpathSync((await execAsync('getconf DARWIN_USER_CACHE_DIR')).stdout.trim())}`,
];
// Add included directories from the workspace context
// Always add 5 INCLUDE_DIR parameters to ensure .sb files can reference them
const MAX_INCLUDE_DIRS = 5;
const configTargetDir = cliConfig?.getTargetDir()
? resolveToRealPath(cliConfig.getTargetDir())
: targetDir;
if (cliConfig?.getTargetDir() && isSensitiveHostPath(configTargetDir)) {
throw new FatalSandboxError(
`Running sandbox from a sensitive host directory '${configTargetDir}' is strictly prohibited`,
);
}
const includedDirs: string[] = [];
if (cliConfig) {
const workspaceContext = cliConfig.getWorkspaceContext();
const directories = workspaceContext.getDirectories();
// Filter out TARGET_DIR
for (const dir of directories) {
const realDir = resolveToRealPath(dir);
if (!realDir) {
continue;
}
if (realDir !== targetDir && realDir !== configTargetDir) {
if (isSensitiveHostPath(realDir)) {
debugLogger.warn(View on GitHub (pinned to 6a466a7e2f)