{"version":"2.1.281","anchor":"path-screening-adds-screened-unvettable-chain","canonical_anchor":"path-screening-adds-screened-unvettable-chain","heading":"read_file and register_repo_root refuse paths whose parent chain cannot be checked","tier":"notice","area":"File Access","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281\/e\/path-screening-adds-screened-unvettable-chain","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281","markdown":"### read_file and register_repo_root refuse paths whose parent chain cannot be checked\n\nread_file and register_repo_root now refuse, before touching disk, any path whose parent folders and links cannot all be examined\n\n**Unclear.** The finding does not say which paths are screened or what happens after one is reported.\n\n**What**\n\nClaude Code screens paths before reading or registering them. Screening has a new outcome, `screened_unvettable_chain`: a path whose chain of parent folders and symbolic links (shortcuts that point to another location) cannot all be resolved is rejected before the file system is touched, and reported as bad.\n\n- `read_file` refuses such paths.\n\n- `register_repo_root`, which adds a working folder to a session, refuses them with the reason `unvettable_chain`. Its error now reads \"target is a network path, an obfuscated spelling, or a path whose directories and symbolic links could not all be examined, which cannot be registered\". Before, it named only network paths and obfuscated spellings.\n\n**Why**\n\nThis is a safety hardening step. Some unusual paths, for example chains through symbolic links or network (UNC) paths, that used to be read or registered will now be refused, so programs using the SDK to register folders may get an error on paths that worked before.\n\n- Area: File Access\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5"}