You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
File AccessArea: what it touches
ImprovementsKind: in v2.1.281,
ImprovementsSection of the release
What
Claude Code checks file paths before it touches them, to catch paths that could point somewhere unexpected. It now flags any absolute path whose first part is one of these macOS special mount paths:
/.vol
/.file
/.nofollow
/.resolve
The check runs after .. segments (which mean "go up one folder") are worked out, so a path cannot slip past by taking a detour. It was added to several path checks, including the macOS check that already flags /network/ paths and /home/ folders other than your own, and the check that flags /network/servers. On systems other than Windows, a path matching one of these prefixes is now classified as "opaque". Before, it could only be classified as foreign or plain.
When managed settings are delivered remotely (settings pushed by an organisation's administrator), the error for a rejected path now lists these macOS special paths next to /net and /Network/Servers.
Why
On macOS these prefixes can reach files by an indirect route rather than by their normal location. Treating them as special closes a gap where such a path could have been handled like an ordinary one.
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtThe finding does not say what an "opaque" classification leads to in practice, for example whether it triggers a permission prompt or a…
Anthropic's release notes agreeFixed permission dialogs and attachment checks reading a path under macOS's /.vol, /.nofollow or /.resolve (which can reach a network mount)…