{"name":"filesystem.allowRead","slug":"filesystem-allowread","family":"setting","title":"Settings keys","noun":"settings key","description":"On Linux, the sandbox glob warning now also checks `filesystem.denyRead` and `filesystem.allowRead` patterns that start at the root or have no fixed folder","description_source":"entry","described_by":{"version":"2.1.284","anchor":"linux-sandbox-warning-now-also-covers-read-globs-anchored-at"},"presence":{"first_seen":null,"removed_in":null,"in_current_build":false,"newest_mined":"2.1.284","builds":0,"mined_builds":127,"first_cited":{"version":"2.1.198","released_at":"2026-07-01 16:50:16","spans":1}},"aliases":[],"entries":[{"version":"2.1.284","anchor":"linux-sandbox-warning-now-also-covers-read-globs-anchored-at","heading":"Linux sandbox warning now also flags broad read rules","line":"On Linux, the sandbox glob warning now also checks `filesystem.denyRead` and `filesystem.allowRead` patterns that start at the root or have no fixed folder","released_at":"2026-09-28 17:11:59","reason":"named in this entry, found in this entry's text"},{"version":"2.1.198","anchor":"windows-sandbox-per-exec-deny-flags","heading":"Windows Sandbox: Per-Exec Deny Flags","line":null,"released_at":"2026-07-01 16:50:16","reason":"found in this entry's text"}],"entries_total":2,"docs":[{"source":"claude-code","path":"managed-settings","title":"Deploy managed settings","documented":false},{"source":"claude-code","path":"sandboxing","title":"Configure the sandboxed Bash tool","documented":false},{"source":"claude-code","path":"settings","title":"Claude Code settings","documented":false},{"source":"claude-code","path":"settings-reference","title":"All settings","documented":false},{"source":"claude-docs","path":"third-party\/claude-desktop\/code","title":"Code in Claude Desktop on 3P","documented":false},{"source":"claude-docs","path":"third-party\/claude-desktop\/configuration","title":"Configuration reference","documented":false}],"docs_total":6,"gates":[],"related":[{"name":"filesystem.denyRead","slug":"filesystem-denyread","description":"Your sandbox `filesystem.denyWrite` paths are now enforced in the sandbox mode used when a proxy port is configured, where they were ignored"},{"name":"filesystem.denyWrite","slug":"filesystem-denywrite","description":"Your sandbox `filesystem.denyWrite` paths are now enforced in the sandbox mode used when a proxy port is configured, where they were ignored"},{"name":"filesystem.disabled","slug":"filesystem-disabled","description":"Settings docs now explain that masked credential files survive a relaxed sandbox filesystem policy while denied ones do not."}],"url":"https:\/\/changelogs.core-directive.com\/reference\/setting\/filesystem-allowread","family_url":"https:\/\/changelogs.core-directive.com\/reference\/setting.json"}