What
Before read_file touches the filesystem, it runs a check for suspicious Windows-style path spellings meant to spoof or bypass path checks. This check used to return one generic rejection reason; it now distinguishes seven specific tricks, each with its own message: NT device namespace, a colon appearing past the drive-letter position, tilde+digit short names, device-path prefixes, trailing dot or whitespace, DOS device-name suffixes, dot-run segments, and UNC/WebDAV-like forms.
The same change applies to permission checking for reading files under a trusted network directory: it now reports a suspicious_windows_spelling reason carrying the specific variant that triggered it, instead of one generic reason code.
Why
Knowing exactly which spelling trick tripped the check makes it much easier to understand why a file path was blocked, whether that's confirming a real security concern or diagnosing a false positive.