{"version":"2.1.284","anchor":"linux-sandbox-read-only-binds-parent-directories-of-pinned-p","canonical_anchor":"linux-sandbox-read-only-binds-parent-directories-of-pinned-p","heading":"Linux sandbox also protects the parent folders of protected paths","tier":"notice","area":"Sandbox","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284\/e\/linux-sandbox-read-only-binds-parent-directories-of-pinned-p","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284","markdown":"### Linux sandbox also protects the parent folders of protected paths\n\nThe Linux sandbox now mounts the parent folders of protected paths inside writable areas as read-only\n\n**Unclear.** The exact problem this guards against, such as renaming a parent folder, is not stated.\n\n**What**\n\nThe sandbox limits what commands run by Claude can change. On Linux, when a protected or hidden path sits inside a folder that commands are allowed to write to, the sandbox now also covers each parent folder of that path, making it read-only. If the whole disk (`\/`) is writable, it covers the top-level parent folders instead and logs which ones. `\/proc`, `\/dev` and `\/sys` are skipped.\n\n**Why**\n\nThe folders that contain a protected path are now covered as well, not only the path itself.\n\n- Area: Sandbox\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5"}