You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
Remote DevicesArea: what it touches
ImprovementsKind: in v2.1.281,
ImprovementsSection of the release
What
When Claude Code sends a tool call to another computer (a remote host), it first checks the call against your permission rules, including rules about which file paths are allowed. It now also checks alternative ways of writing the same path. If a path is written in a form your session's path rules cannot match, the call is refused with the code declined_spelling and the remote host is never contacted. The model is told to use the file's full path as the tool shows it.
The path filling-in that used to apply only to a file_path field now applies to whichever field holds the path for any tool. The permission check runs over the original input, the alternative spellings and the rewritten input, and stops at the first refusal.
Why
A path rule only protects you if it can recognise the path. Writing a path in an unusual way could otherwise let a call reach a remote machine without your rules ever applying to it.