{"version":"2.1.284","anchor":"linux-sandbox-long-bwrap-command-lines-are-passed-through-a","canonical_anchor":"linux-sandbox-long-bwrap-command-lines-are-passed-through-a","heading":"Sandboxed commands on Linux start even with very large sandbox settings","tier":"notice","area":"Sandbox","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284\/e\/linux-sandbox-long-bwrap-command-lines-are-passed-through-a","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284","markdown":"### Sandboxed commands on Linux start even with very large sandbox settings\n\nOn Linux, a sandbox setup too long for one command line is now passed to bubblewrap through a temporary file, with clear errors when it can't be\n\n**What**\n\nOn Linux, Claude Code can run Bash commands in a sandbox, a restricted environment that limits which files and settings a command can reach. It builds the sandbox with a program called bubblewrap (`bwrap`), passing every rule as a command-line argument. Claude Code now checks how long that command line gets:\n\n- Too long: the arguments are written to an unnamed temporary file, in the temp folder or `\/dev\/shm`, and handed to bubblewrap from there.\n\n- Too many arguments: it stops with a specific error.\n\n- A path containing a NUL byte (an invisible character that cannot appear in arguments): it stops with an error saying so.\n\n- No unnamed file can be opened: it stops with an error saying so.\n\n**Why**\n\nA sandbox with many allowed or denied paths or environment variables could exceed the operating system's limit on argument length and fail to start. Those setups should now start, and when one can't, the error says why.\n\n- Area: Sandbox\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 1\/5"}