{"version":"2.1.280","anchor":"new-withheld-file-reason-file-linked-from-claude-code-confi","canonical_anchor":"new-withheld-file-reason-file-linked-from-claude-code-confi","heading":"Files that are really your Claude Code config get their own handling","tier":"notice","area":"Cloud Sessions","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.280\/e\/new-withheld-file-reason-file-linked-from-claude-code-confi","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.280","markdown":"### Files that are really your Claude Code config get their own handling\n\nReads, writes, and file scans now recognize when a path is really the machine's own Claude Code configuration reached under another name\n\n**What**\n\n- File reads: a new denial reason explains when a read is withheld because the file is linked from your Claude Code configuration, instead of falling into a generic \"sensitive\" bucket.\n\n- The sandbox readability check gained a `host_config` classification (via a new `hostConfig` parameter) alongside its existing `read_denied`\/`sensitive`\/`sensitive_tracked` outcomes, and can report `rules_unreadable` when the host config itself can't be read.\n\n- Repo-sync\/diff logic (used for things like merges and worktree checks) now detects files that are actually the machine's own Claude Code configuration linked in under another name, and withholds them with two new reasons: `withheld_host_config` (configuration linked under another name) and `withheld_config_unexamined` (the configuration couldn't be fully examined).\n\n- File-scan summaries gained a `skipped_host_config` counter, alongside existing counters like `skipped_sensitive_tracked` and `skipped_read_denied`.\n\n- Write protection recognizes the same two cases for writes: the target is the machine's own configuration under another name, or the configuration couldn't be fully examined (unreadable link\/directory, or too many entries).\n\n- File-refusal classification for restricted reads gained its own `host_config` reason, previously lumped in with `read_denied`\/`not_regular_file`, and it's now counted among refusal reasons treated as sensitive\/blocked.\n\n**Why**\n\nThis stops Claude Code from treating your own configuration files as generic unreadable or sensitive files when they're reached through a symlink or alias, giving clearer, more specific explanations across reads, writes, and file scans.\n\n- Area: Cloud Sessions\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 2\/5"}