You'll noticeTier: how much it should matter to you
3Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
PermissionsArea: what it touches
ImprovementsKind: in v2.1.280,
ImprovementsSection of the release
What
When a read or write target's real path, after resolving symlinks, lands outside the allowed working directories, the permission-ask message now explicitly says the path "resolves through a symlink to" the outside location. If the symlink chain can't be resolved at all, the operation is denied outright.
A new helper (r2e) is consulted after a write is otherwise allowed or denied, to catch cases where the operation would actually land outside the intended location via a symlink, adding a dedicated safety-check reason and message for that case.
Why
This closes a gap where a symlink could quietly redirect a read or write outside the intended working directory, and makes the resulting permission prompt clearer about what's actually happening.