You'll notice
Sync failure messages now also mention sandbox settings as a possible cause, not just Read rules.
Session-sync "unreadable" refusal messages, which previously only cited Read-permission rules as the reason files couldn't sync, now also mention sandbox read-deny settings as a possible cause and list which settings files were unreadable.