You'll notice
File-withheld explanations now also mention sandbox read-deny settings as a cause.
Messages explaining why files were withheld from git or context now mention a sandbox read-deny setting as a possible cause, in addition to a Read permission rule. This appears both in the credential-scrub explanation and the git-upload refusal message, and similarly in messages about files left out of a cloud/session upload.