Source Intelligence

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

All of v2.1.224 Home All releases olderv2.1.223 v2.1.225newer

Invalid sandbox credential settings now fail closed instead of being ignored

You'll notice
Useful4 Signal3
Sandbox

A malformed sandbox.credentials block now denies everything instead of quietly disabling protection.

sandbox.credentials
What

A malformed sandbox.credentials block used to be dropped entirely, leaving no credential protection in place. It now degrades to a deny-everything skeleton: all sigv4 signing modes deny, and implicit AWS credential pairing is suppressed rather than left open.

Details
  • Invalid awsPairs entries become non-functional suppressors built from the conventional AWS environment variable names, with a deterministic suffix so the result is stable across runs.
  • The sigv4 sub-keys streaming, presigned and sigv4a each degrade individually to "deny".
  • allowPlaintextInject degrades to an explicit false, so a lower-precedence settings file cannot turn it back on.
  • A single object where a list is expected is accepted as a one-element list with a warning.
  • A valid credentials block is salvaged out of an otherwise invalid sandbox value, with every other sandbox field ignored.
Evidence

The credentials block was salvaged from the invalid sandbox value and stays enforced; every other sandbox field was ignored.

Strings lifted out of the shipped bundle, so the claim above can be checked against them.

Related

Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.

See this entry in the whole of v2.1.224 →