The sandbox limits which files commands can read or write. Its rules can use glob patterns, which are wildcards such as *. On Linux, Claude Code warns "Glob patterns in sandbox permission rules are not fully supported on Linux". That warning now also checks filesystem.denyRead and filesystem.allowRead. Before, it checked only filesystem.allowWrite and filesystem.denyWrite.
A pattern is flagged when the fixed part before its first wildcard is empty or just /, as in **/.env. The suggested fix says that on Linux, glob patterns in Edit and Read rules will be ignored.
A read rule like **/.env cannot be expanded from a fixed folder on Linux. If you have one, you now get a warning instead of a rule that quietly protects less than you expect.
* While `filesystem.denyRead`, `filesystem.denyWrite`, or any entry in either is invalid, Claude Code also withholds both `filesystem.allowRead` and `filesystem.allowWrite` until you fix the deny list.see the edit
* While `filesystem.denyRead`, `filesystem.denyWrite`, or any entry in either is invalid, Claude Code also withholds both `filesystem.allowRead` and `filesystem.allowWrite` until you fix the deny list.see the edit
filesystem.denyRead on Deploy managed settings