Skip to content

refactor(core): use centralized path resolution for Linux sandbox#24985

Open
ehedlund wants to merge 3 commits intomainfrom
linux-refactor
Open

refactor(core): use centralized path resolution for Linux sandbox#24985
ehedlund wants to merge 3 commits intomainfrom
linux-refactor

Conversation

@ehedlund
Copy link
Copy Markdown
Contributor

@ehedlund ehedlund commented Apr 8, 2026

Summary

Refactor the Linux sandbox management (LinuxSandboxManager and buildBwrapArgs) to leverage the unified resolveSandboxPaths and ResolvedSandboxPaths from sandboxManager.ts. This change centralizes path resolution and symlink expansion, removing redundant and manual path handling from the Linux-specific implementation.

Details

  • Interface Alignment: Updated BwrapArgsOptions to accept ResolvedSandboxPaths, mirroring the architecture used in the Windows sandbox.
  • Simplified Argument Building: Removed manual tryRealpath and sanitizePaths calls in buildBwrapArgs, as these are now provided by the shared resolution service.
  • Robust Path Mounting: Ensures both the original path and its realpath are bound in the sandbox for critical areas like the workspace and governance files.
  • No-Op Implementation: Maintained exact behavioral parity with the previous implementation, including Linux-specific features like Git worktree resolution and parent-directory binding for non-existent paths.
  • Refined Testing: Updated the test suite to use the new structured path interface, while improving test readability and focus.

Related Issues

Internal refactor.

How to Validate

  1. Run core unit tests: npm test -w @google/gemini-cli-core -- src/sandbox/linux/bwrapArgsBuilder.test.ts
  2. Run Linux sandbox manager tests: npm test -w @google/gemini-cli-core -- src/sandbox/linux/LinuxSandboxManager.test.ts

Pre-Merge Checklist

  • Updated relevant documentation and README (if needed)
  • Added/updated tests (if needed)
  • Noted breaking changes (if any)
  • Validated on required platforms/methods:
    • MacOS
      • npm run
      • npx
      • Docker
      • Podman
      • Seatbelt
    • Windows
      • npm run
      • npx
      • Docker
    • Linux
      • npm run
      • npx
      • Docker

@ehedlund ehedlund requested a review from a team as a code owner April 8, 2026 23:44
@gemini-cli
Copy link
Copy Markdown
Contributor

gemini-cli bot commented Apr 8, 2026

Hi @ehedlund, thank you so much for your contribution to Gemini CLI! We really appreciate the time and effort you've put into this.

We're making some updates to our contribution process to improve how we track and review changes. Please take a moment to review our recent discussion post: Improving Our Contribution Process & Introducing New Guidelines.

Key Update: Starting January 26, 2026, the Gemini CLI project will require all pull requests to be associated with an existing issue. Any pull requests not linked to an issue by that date will be automatically closed.

Thank you for your understanding and for being a part of our community!

@gemini-code-assist
Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request refactors the Linux sandbox management by integrating a centralized path resolution mechanism. This change significantly simplifies the bwrapArgsBuilder module by offloading complex path handling, such as symlink expansion and sanitization, to a shared service. The refactor ensures consistent and robust path management across the sandbox, mirroring the architecture used in the Windows sandbox, while maintaining existing behavioral parity.

Highlights

  • Centralized Linux sandbox path resolution: The Linux sandbox now uses a unified ResolvedSandboxPaths object, streamlining how file system paths are handled.
  • Simplified bwrapArgsBuilder interface: The BwrapArgsOptions interface was refactored to accept the ResolvedSandboxPaths object, removing redundant individual path arrays and permission objects.
  • Removed manual path handling: Manual tryRealpath and sanitizePaths calls have been eliminated from buildBwrapArgs, as these concerns are now managed by the centralized resolution service.
  • Enhanced path binding for workspace and governance files: The system now explicitly binds both the original and resolved (real) paths for critical workspace and governance files, improving robustness.
  • Refactored test suite: Unit tests for bwrapArgsBuilder have been updated to align with the new ResolvedSandboxPaths interface, making them clearer and more focused.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution.

@ehedlund ehedlund enabled auto-merge April 8, 2026 23:47
@gemini-cli gemini-cli bot added the status/need-issue Pull requests that need to have an associated issue. label Apr 8, 2026
@github-actions
Copy link
Copy Markdown

github-actions bot commented Apr 8, 2026

Size Change: -1.62 kB (0%)

Total Size: 34 MB

Filename Size Change
./bundle/chunk-EJGOQX7U.js 0 B -14.8 MB (removed) 🏆
./bundle/chunk-EPKIH4MP.js 0 B -3.47 kB (removed) 🏆
./bundle/chunk-YPX4U6RM.js 0 B -3.16 MB (removed) 🏆
./bundle/core-RLZG6MBF.js 0 B -45.4 kB (removed) 🏆
./bundle/devtoolsService-F46T5ET6.js 0 B -28.4 kB (removed) 🏆
./bundle/gemini-RQTWB7R2.js 0 B -552 kB (removed) 🏆
./bundle/interactiveCli-FGBRC3AQ.js 0 B -1.65 MB (removed) 🏆
./bundle/oauth2-provider-GGXS7P2Q.js 0 B -9.16 kB (removed) 🏆
./bundle/chunk-2TZ4QJJ2.js 3.47 kB +3.47 kB (new file) 🆕
./bundle/chunk-A3GQZDUZ.js 3.16 MB +3.16 MB (new file) 🆕
./bundle/chunk-OWLPIHK6.js 14.8 MB +14.8 MB (new file) 🆕
./bundle/core-FFHWDNBN.js 45.4 kB +45.4 kB (new file) 🆕
./bundle/devtoolsService-ERBBWJ3X.js 28.4 kB +28.4 kB (new file) 🆕
./bundle/gemini-DOZYM4PW.js 552 kB +552 kB (new file) 🆕
./bundle/interactiveCli-QWNMCCEI.js 1.65 MB +1.65 MB (new file) 🆕
./bundle/oauth2-provider-GR7545FD.js 9.16 kB +9.16 kB (new file) 🆕
ℹ️ View Unchanged
Filename Size Change
./bundle/bundled/third_party/index.js 8 MB 0 B
./bundle/chunk-34MYV7JD.js 2.45 kB 0 B
./bundle/chunk-5AUYMPVF.js 858 B 0 B
./bundle/chunk-5PS3AYFU.js 1.18 kB 0 B
./bundle/chunk-664ZODQF.js 124 kB 0 B
./bundle/chunk-DAHVX5MI.js 206 kB 0 B
./bundle/chunk-IUUIT4SU.js 56.5 kB 0 B
./bundle/chunk-OGWWODAT.js 1.96 MB 0 B
./bundle/chunk-RJTRUG2J.js 39.8 kB 0 B
./bundle/cleanup-MNV4U33B.js 0 B -856 B (removed) 🏆
./bundle/devtools-36NN55EP.js 696 kB 0 B
./bundle/dist-T73EYRDX.js 356 B 0 B
./bundle/events-XB7DADIJ.js 418 B 0 B
./bundle/gemini.js 4.97 kB 0 B
./bundle/getMachineId-bsd-TXG52NKR.js 1.55 kB 0 B
./bundle/getMachineId-darwin-7OE4DDZ6.js 1.55 kB 0 B
./bundle/getMachineId-linux-SHIFKOOX.js 1.34 kB 0 B
./bundle/getMachineId-unsupported-5U5DOEYY.js 1.06 kB 0 B
./bundle/getMachineId-win-6KLLGOI4.js 1.72 kB 0 B
./bundle/memoryDiscovery-JNNGTYL3.js 980 B 0 B
./bundle/multipart-parser-KPBZEGQU.js 11.7 kB 0 B
./bundle/node_modules/@google/gemini-cli-devtools/dist/client/main.js 222 kB 0 B
./bundle/node_modules/@google/gemini-cli-devtools/dist/src/_client-assets.js 229 kB 0 B
./bundle/node_modules/@google/gemini-cli-devtools/dist/src/index.js 13.4 kB 0 B
./bundle/node_modules/@google/gemini-cli-devtools/dist/src/types.js 132 B 0 B
./bundle/sandbox-macos-permissive-open.sb 890 B 0 B
./bundle/sandbox-macos-permissive-proxied.sb 1.31 kB 0 B
./bundle/sandbox-macos-restrictive-open.sb 3.36 kB 0 B
./bundle/sandbox-macos-restrictive-proxied.sb 3.56 kB 0 B
./bundle/sandbox-macos-strict-open.sb 4.82 kB 0 B
./bundle/sandbox-macos-strict-proxied.sb 5.02 kB 0 B
./bundle/src-QVCVGIUX.js 47 kB 0 B
./bundle/tree-sitter-7U6MW5PS.js 274 kB 0 B
./bundle/tree-sitter-bash-34ZGLXVX.js 1.84 MB 0 B
./bundle/cleanup-VENWLB7T.js 856 B +856 B (new file) 🆕

compressed-size-action

Copy link
Copy Markdown
Contributor

@gemini-code-assist gemini-code-assist bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request refactors the bwrapArgsBuilder to use a resolvedPaths object, streamlining path handling within the sandbox. This change simplifies the BwrapArgsOptions interface and the buildBwrapArgs function by centralizing path resolution. Corresponding test files have been updated to reflect these new path management strategies, including the introduction of a createResolvedPaths helper. A review comment highlighted a potential regression in secret masking for symlinked workspaces, noting that the getSecretFilesArgs function should include both the original and resolved workspace paths to ensure comprehensive secret detection.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

status/need-issue Pull requests that need to have an associated issue.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant