Turning off sandboxing mid-session now tells Claude the old restrictions no longer apply.
What's wrong with this entry?
When sandboxing is disabled, the model is now told directly that commands run without sandbox restrictions and that earlier sandbox instructions no longer apply, so it does not keep working around limits that are gone.
- Two new lists of refusal reasons ship alongside it: write refusals (
compliance_restricted,org_mismatch,org_toggle_disabled,summon_foreign_sender,user_entitlement_denied,write_gate_disabled) and device-binding refusals (bind_attestation_stale,bound_session_unattested_write,untrusted_device).
Commands now run without sandbox restrictions; the earlier sandbox instructions no longer apply.
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.236
macOS sandbox re-applies read and delete denials inside writable folders
Both mention sandbox
-
v2.1.236
Sandbox proxy no longer writes to sockets that have gone away
Both mention sandbox
-
v2.1.236
IPv6 hosts through the proxy
Both mention sandbox