Understand Filesystem Controls

View as Markdown

NemoClaw restricts which paths the agent can read and write, protecting system binaries, configuration files, and gateway credentials.

OpenShell covers additional filesystem enforcement details, including hard_requirement compatibility mode for Landlock and policy path validation rules. Refer to the Filesystem Controls section of the OpenShell Security Best Practices.

Read-Only System Paths

The container mounts system directories read-only to prevent the agent from modifying binaries, libraries, or configuration files.

AspectDetail
Default/usr, /lib, /proc, /dev/urandom, /app, /etc, /var/log, and /var/lib/dpkg are read-only.
What you can changeAdd or remove paths in the filesystem_policy.read_only section of the policy file.
Risk if relaxedMaking /usr or /lib writable lets the agent replace system binaries (such as curl or node) with trojanized versions. Making /etc writable lets the agent modify DNS resolution, TLS trust stores, or user accounts.
RecommendationNever make system paths writable. If the agent needs a writable location for generated files, use a subdirectory of /sandbox.

Agent Config Directory

The /sandbox/.deepagents directory contains Deep Agents Code runtime state and NemoClaw-generated configuration. NemoClaw writes config.toml during onboarding and rebuilds. Direct edits to this file can be overwritten when NemoClaw regenerates the managed inference route.

The managed Deep Agents image deliberately omits raw provider and service credentials from generated configuration. Credential-bearing files such as .deepagents/.env and user-authored .deepagents/.mcp.json are treated as user-managed files and are not included in NemoClaw snapshots.

The managed .deepagents/.nemoclaw-mcp.json projection contains OpenShell placeholders and is reconstructed from host-side registry state.

The Shields workflow derives the Deep Agents lock plan from its agent manifest. The agent/skills declaration locks the top-level agent directory, and the skills declaration locks the top-level skills directory. The .state directory remains mutable.

AspectDetail
DefaultThe Deep Agents config tree contains NemoClaw-generated config.toml, managed MCP projection state, and mutable Deep Agents memory and skill state.
What you can changeUse host-side NemoClaw commands for durable model, provider, managed MCP, and policy changes; inspect or edit memory and skills through dcode or direct file access when appropriate.
Risk of direct editsDirect edits to generated config can drift from the host registry and may be lost on rebuild. Storing credentials in .deepagents/.env or user .mcp.json moves them outside the managed credential boundary.
RecommendationKeep generated config under NemoClaw control. Use OpenShell providers and NemoClaw MCP commands for credentials, and back up Deep Agents state before destructive operations.

Writable Paths

The agent has read-write access to /sandbox, /tmp, /dev/null, and /dev/pts.

AspectDetail
Default/sandbox (agent workspace), /tmp (temporary files), /dev/null, and /dev/pts (the devpts pseudo-terminal directory, required so PTY-based tools such as tmux, script, and interactive shells can allocate a terminal).
What you can changeAdd additional writable paths in filesystem_policy.read_write.
Risk if relaxedEach additional writable path expands the agent’s ability to persist data and potentially modify system behavior. Adding /var lets the agent write to log directories. Adding /home gives access to other user directories.
RecommendationKeep writable paths to /sandbox and /tmp. If the agent needs a persistent working directory, create a subdirectory under /sandbox.

Landlock LSM Enforcement

Landlock is a Linux Security Module that enforces filesystem access rules at the kernel level.

AspectDetail
Defaultcompatibility: strict. Deep Agents sandbox startup fails closed when OpenShell cannot enforce the managed filesystem policy.
What you can changeThis is a NemoClaw Deep Agents invariant, not a user-facing knob.
Risk if relaxedSilent Landlock degradation would leave the terminal coding harness with weaker filesystem isolation while still reporting a successful sandbox.
RecommendationRun Deep Agents on a kernel and runtime that support Landlock enforcement. Rebuild or move hosts if startup reports an enforcement failure.