Follow Discord
Sweep 28 Sep 2026 · 18:16Z Build v2.1.284 505 read Stable v2.1.277 Latest v2.1.284 Next v2.1.284 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.284 ·

Linux sandbox also protects the parent folders of protected paths

The Linux sandbox now mounts the parent folders of protected paths inside writable areas as read-only

You'll notice Improvements
JSON All of v2.1.284
You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
SandboxArea: what it touches
ImprovementsKind: in v2.1.284,
ImprovementsSection of the release
What

The sandbox limits what commands run by Claude can change. On Linux, when a protected or hidden path sits inside a folder that commands are allowed to write to, the sandbox now also covers each parent folder of that path, making it read-only. If the whole disk (/) is writable, it covers the top-level parent folders instead and logs which ones. /proc, /dev and /sys are skipped.

Why

The folders that contain a protected path are now covered as well, not only the path itself.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtThe exact problem this guards against, such as renaming a parent folder, is not stated.

See this entry in the whole of v2.1.284 →

Feedback