Error reference changederrors
Upstream edited this page at 28 Sep 2026 00:01 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 28 Sep 2026 00:07 UTC.
Upstream edited
Recorded here
Lines+5added
Lines−1removed
From line
265
where the diff opens
First seen
14 Aug 2026
this site's first read of the page
Recorded edits110to this page, all time
The whole hunk
from line 265, old and new numbered
/
This page is larger than the 256 KiB this site keeps, so one side of the diff below stops where the stored text does.
from line 265
265265| `Refusing to read <path>: its symlink resolution changed after permission was checked (<reason>)` / `Refusing to search <path>: its symlink resolution changed after permission was checked` | [Tool errors](#refusing-after-a-symlink-changed) |
266266| `Refusing to write <path>: its parent-directory symlink resolution changed after permission was checked` / `Refusing to write <path>: it is a symbolic link. Write to the link's target path instead` | [Tool errors](#refusing-after-a-symlink-changed) |
267267| `Refusing to write through symlink: <path>` / `Refusing to write into symlinked directory: <path>` | [Tool errors](#refusing-after-a-symlink-changed) |
268| `Refusing to write <path>: where it leads on disk could not be determined` / `Refusing to read <path>: where it leads on disk could not be determined` | [Tool errors](#refusing-after-a-symlink-changed) |
268269| `Refusing to search <path>: a path one of its Read deny rules is written through changed while the search was being prepared` / `Refusing to search <path>: it could not be opened` | [Tool errors](#refusing-after-a-symlink-changed) |
269270| `its permission check expired before it ran (too many concurrent file operations)` / `ripgrep was found only by name on PATH` | [Tool errors](#refusing-after-a-symlink-changed) |
270271| `task output swap refused (tasks dir moved or linked)` | [Tool errors](#task-output-swap-refused) |
from line 1781
17801781
17811782* Export your organization's CA bundle and point Claude Code at it with `NODE_EXTRA_CA_CERTS=/path/to/ca-bundle.pem`
17821783* See [Network configuration](/docs/en/network-config#custom-ca-certificates) for full setup instructions
1783* Don't set `NODE_TLS_REJECT_UNAUTHORIZED=0`, which disables certificate validation entirely
1784
1785### Host not allowed in a cloud session
1786
1787An outbound HTTP request from a cloud session or routine was blocked by the environment's network policy.
1788
1789```text theme={null}
1790HTTP 403
1791x-deny-reason: host_not_allowed
1792```
1793
1794You may also see a TLS certificate that doesn't match the destination's real certificate. Cloud sessions route outbou
1784* Don't set `NODE_TLS_REJECT_UNAU
No line in this hunk matches that.