{"version":"2.1.284","anchor":"linux-sandbox-handles-running-as-root-without-cap-setfcap","canonical_anchor":"linux-sandbox-handles-running-as-root-without-cap-setfcap","heading":"Linux sandbox explains why it fails for root without a needed permission","tier":"notice","area":"Sandbox","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284\/e\/linux-sandbox-handles-running-as-root-without-cap-setfcap","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284","markdown":"### Linux sandbox explains why it fails for root without a needed permission\n\nRunning as root on Linux without the CAP_SETFCAP permission, the sandbox now reports a clear error instead of every command failing\n\n**What**\n\nOn Linux, the sandbox (the walled-off space Claude Code runs commands in) is built with a tool called bubblewrap. When Claude Code runs as root but lacks a Linux permission called CAP_SETFCAP, it now tests whether the sandbox can start. If the test fails, it reports a setup error saying every sandboxed command would fail, and logs a one-time warning.\n\nWhen it runs as root and does have that permission, it now keeps it inside the sandbox in some setups.\n\n**Why**\n\nRoot users in containers on newer Linux kernels now get a clear diagnosis instead of every Bash command failing.\n\n- Area: Sandbox\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 1\/5"}