File System Access

Read and write files from guest code and restrict access with the sandbox

Guest programs can access the host filesystem by default. Relative paths are resolved from the process working directory.

For example, JavaScript can use node:fs:

const { readFileSync, writeFileSync } = require("node:fs");

const text = readFileSync("hello.txt", "utf8");
writeFileSync("out.txt", text.toUpperCase());

This page describes access policy, not the functions implemented by node:fs. See the Node Filesystem API for that surface.

Restrict access

Sandbox flags switch filesystem access to deny-by-default. Grant only the paths the program needs:

elide --allow-read=. --allow-write=./out run app.js

--allow-read and --allow-write imply --sandbox. The bare form grants all paths; attach =PATH[,PATH] to scope a grant. Use --fs-audit to print access decisions to stderr.

Continue with Filesystem Sandbox for subprocess and network grants.