What
The sandbox limits what commands run by Claude can change. On Linux, when a protected or hidden path sits inside a folder that commands are allowed to write to, the sandbox now also covers each parent folder of that path, making it read-only. If the whole disk (/) is writable, it covers the top-level parent folders instead and logs which ones. /proc, /dev and /sys are skipped.
Why
The folders that contain a protected path are now covered as well, not only the path itself.
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
The exact problem this guards against, such as renaming a parent folder, is not stated.