{"version":"2.1.281","anchor":"background-session-spawn-drops-unsafe-claude-config-dir-from","canonical_anchor":"background-session-spawn-drops-unsafe-claude-config-dir-from","heading":"Background-session spawn drops unsafe CLAUDE_CONFIG_DIR from dispatch env","tier":"notice","area":"Elsewhere","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281\/e\/background-session-spawn-drops-unsafe-claude-config-dir-from","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281","markdown":"### Background-session spawn drops unsafe CLAUDE_CONFIG_DIR from dispatch env\n\nBackground jobs now drop an unsafe CLAUDE_CONFIG_DIR passed in by a dispatch, with a warning\n\n**What**\n\nThe daemon is a background process that starts and manages background jobs. When it starts a job, the request (the dispatch) can pass environment settings along. If `CLAUDE_CONFIG_DIR` is not set in the daemon's own environment, a `CLAUDE_CONFIG_DIR` supplied by the dispatch is now dropped with a warning unless all of these are true:\n\n- It is an absolute path\n\n- It contains no `..`\n\n- It is this daemon's own config home\n\nAdopting and reattaching to background sessions now also clean the dispatch's environment through the same kind of check, and `reattachEnv` is discarded.\n\n**Why**\n\nA background job cannot be pointed at an unexpected configuration folder through the dispatch. If a job ignores a config directory you passed, the warning \"dropped dispatch CLAUDE_CONFIG_DIR\" is the place to look.\n\n- Area: Elsewhere\n- Names: `CLAUDE_CONFIG_DIR`\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5"}