{"version":"2.1.281","anchor":"sandbox-network-classifier-holds-a-deny-while-the-api-asks-i","canonical_anchor":"sandbox-network-classifier-holds-a-deny-while-the-api-asks-i","heading":"Sandbox network classifier holds a deny while the API asks it to wait","tier":"notice","area":"Sandbox","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281\/e\/sandbox-network-classifier-holds-a-deny-while-the-api-asks-i","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281","markdown":"### Sandbox network classifier holds a deny while the API asks it to wait\n\nWhen the sandbox network classifier is told to wait by the API, its deny is held for that time instead of rechecked on every request\n\n**What**\n\nThe sandbox is a restricted environment that limits what commands run by Claude Code can reach. Inside it, a network classifier decides whether each network request is allowed. Sometimes the classifier cannot be reached and the API replies with a positive `retryAfterMs`, meaning \"wait this many milliseconds before asking again\". In that case the resulting deny is now remembered for that long, up to a fixed maximum. A warning is logged: \"Sandbox network classifier was told to wait by the API; holding the deny\".\n\nBefore this change the deny was thrown away, and every following request was sent to the classifier again.\n\n**Why**\n\nNetwork requests from the sandbox stay blocked during the wait, just as before. The difference is that Claude Code stops asking the classifier again during the period the API asked it to wait. The warning in the log explains why requests are being refused.\n\n- Area: Sandbox\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 2\/5"}