Source Intelligence

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

All of v2.1.223 Home All releases olderv2.1.222 v2.1.224newer

Linux sandbox skips redundant blocking mounts inside read-only denied directories

You'll notice
Useful2 Signal0
Sandbox

The Linux sandbox skips pointless blocking mounts, so sandboxed runs start with less overhead.

What

The bubblewrap argument builder now recognises when a non-existent deny path already sits inside a read-only denied directory and stops adding a mount to block it.

Details
  • new bookkeeping tracks write roots and their realpaths, deny directories and their realpaths, and a map of deny paths per allowed root
  • in the redundant case it no longer mounts /dev/null or an empty temp dir to prevent creation, and logs that the path is already uncreatable
  • Linux sandbox only
Evidence

Skipping non-existent deny path inside a read-only denied directory (already uncreatable)

Strings lifted out of the shipped bundle, so the claim above can be checked against them.

Related

Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.

See this entry in the whole of v2.1.223 →