{"version":"2.1.283","anchor":"sandbox-network-and-filesystem-grants-are-withheld-when-a-re","canonical_anchor":"sandbox-network-and-filesystem-grants-are-withheld-when-a-re","heading":"One invalid sandbox deny entry now withholds the matching allow rules","tier":"notice","area":"Sandbox","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.283\/e\/sandbox-network-and-filesystem-grants-are-withheld-when-a-re","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.283","markdown":"### One invalid sandbox deny entry now withholds the matching allow rules\n\nIf one entry in deniedDomains, denyWrite or denyRead is invalid, Claude Code now withholds the matching allow list instead of applying it\n\n**Unclear.** Which settings sources this applies to, such as managed or personal settings, is not clear.\n\n**What**\n\nThe sandbox limits which websites and files commands run by Claude can reach. Its `sandbox.network` and `sandbox.filesystem` settings now fail safe when a single deny entry is invalid and gets dropped:\n\n- An invalid entry in `deniedDomains` withholds `allowedDomains`.\n\n- An invalid entry in `denyWrite` withholds `allowWrite`.\n\n- An invalid entry in `denyRead` withholds `allowRead`.\n\nBefore, this happened only when a whole deny setting could not be read. `autoMode` already worked this way.\n\n**Why**\n\nA typo in one deny rule can no longer leave your allow rules fully in force while part of the restriction silently goes missing. If some access you allowed stops working, check your deny lists for an invalid entry.\n\n- Area: Sandbox\n- Names: `sandbox.network`, `sandbox.filesystem`\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 1\/5"}