In the previous chapter, Fallback Policy Manager, we defined the rules for when to use the sandbox and when to bypass it.
But rules are useless if the system physically cannot run the sandbox.
Imagine trying to drive a car. You have the keys (Settings) and you know the traffic laws (Policies), but if the car is missing its wheels, you aren't going anywhere.
Welcome to Environment Health Diagnostics.
This abstraction acts as the System Doctor. Before we try to run complex, isolated code, we need to ensure the computer actually has the necessary tools installed to do so.
Sandboxing isn't magic; it relies on specific Operating System tools to create walls around the code.
bubblewrap to create the container.seatbelt mechanism.ripgrep to scan files quickly.
If a user installs our project but forgets to install bubblewrap, the sandbox will crash silently or throw a confusing error code.
We build a diagnostic layer that:
apt install bubblewrap").Just like a pilot has a pre-flight checklist, our system has a list of requirements.
bubblewrap on Linux).seccomp filters).A Mac user shouldn't be told to install Linux tools. The Diagnostics system checks the OS first.
ripgrep.ripgrep, bubblewrap, and socat.The Diagnostics system runs a "Health Check" whenever the settings are opened.
Let's look at how we build the UI to report this health status. We will examine SandboxDoctorSection.tsx and SandboxDependenciesTab.tsx.
This component (SandboxDoctorSection) sits at the top of the settings menu. It gives a quick "Red Light / Green Light" status.
// Inside SandboxDoctorSection
const depCheck = SandboxManager.checkDependencies();
const hasErrors = depCheck.errors.length > 0;
// Choose the color: Red for errors, Yellow for warnings
const statusColor = hasErrors ? "error" : "warning";
// Choose the text
const statusText = hasErrors
? "Missing dependencies"
: "Available (with warnings)";
errors has items, we flag the whole system as "Error" (Red). This gives the user immediate feedback that something is wrong.If the status is bad, we switch to the "Dependencies" tab to show details. We look for specific keywords in the error list to identify which tool is missing.
// Inside SandboxDependenciesTab
// Check if specific tools are mentioned in the error list
const rgMissing = depCheck.errors.some(
e => e.includes('ripgrep')
);
const bwrapMissing = depCheck.errors.some(
e => e.includes('bwrap')
);
.includes() to figure out exactly which tool caused the error so we can show the right icon.It is not enough to say "Error." We must tell the user how to fix it.
// If ripgrep is missing, show the install command
<Text>
ripgrep (rg):
{rgMissing ? <Text color="error">not found</Text> : <Text color="success">found</Text>}
</Text>
{rgMissing && (
<Text dimColor>
ยท {isMac ? 'brew install ripgrep' : 'apt install ripgrep'}
</Text>
)}
1. We display the tool name.
2. We show "not found" in red if it's missing.
3. Crucially, we conditionally render the install command based on the user's OS (brew for Mac, apt for Linux).
We ensure we don't confuse users by showing irrelevant tools.
const isMac = platform === 'macos';
// Only show Linux tools if we are NOT on a Mac
{!isMac && (
<Box flexDirection="column">
<Text>bubblewrap (bwrap): ...</Text>
<Text>socat: ...</Text>
</Box>
)}
!isMac check, we hide bubblewrap and socat from macOS users. This keeps the interface clean and relevant.The Environment Health Diagnostics ensures our foundation is solid.
Now that we know the settings are correct, the policies are defined, and the tools are installed, we are ready to actually run code.
How does the system take a user's command and send it to these tools?
Next Step: Let's look at the engine room in the Sandbox Data Adapter.
Generated by Code IQ