{"version":"2.1.281","anchor":"sandbox-permission-projection-refuses-entries-it-cannot-reso","canonical_anchor":"sandbox-permission-projection-refuses-entries-it-cannot-reso","heading":"Sandbox permission projection refuses entries it cannot resolve","tier":"notice","area":"Sandbox","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281\/e\/sandbox-permission-projection-refuses-entries-it-cannot-reso","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281","markdown":"### Sandbox permission projection refuses entries it cannot resolve\n\nA permissions.allow entry the sandbox cannot resolve now stops with a config error naming it, instead of an unhandled failure\n\n**What**\n\nThe sandbox is a restricted environment that limits what commands can reach. Entries in `permissions.allow` (actions you have approved to run without asking) are converted into sandbox rules. If an entry cannot be worked out during that conversion, Claude Code now reports a configuration error that names the entry. Before, the failure was not handled.\n\n**Why**\n\nA bad entry is now refused instead of being trusted. The error tells you which entry to fix.\n\n- Area: Sandbox\n- Names: `permissions.allow`\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 1\/5"}