You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
SandboxArea: what it touches
ImprovementsKind: in v2.1.284,
ImprovementsSection of the release
What
On Linux, the sandbox (the walled-off space Claude Code runs commands in) is built with a tool called bubblewrap. When Claude Code runs as root but lacks a Linux permission called CAP_SETFCAP, it now tests whether the sandbox can start. If the test fails, it reports a setup error saying every sandboxed command would fail, and logs a one-time warning.
When it runs as root and does have that permission, it now keeps it inside the sandbox in some setups.
Why
Root users in containers on newer Linux kernels now get a clear diagnosis instead of every Bash command failing.