Follow Discord
Sweep 28 Sep 2026 · 18:16Z Build v2.1.284 505 read Stable v2.1.277 Latest v2.1.284 Next v2.1.284 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.284 ·

Linux sandbox warning now also flags broad read rules

On Linux, the sandbox glob warning now also checks filesystem.denyRead and filesystem.allowRead patterns that start at the root or have no fixed folder

You'll notice Improvements
JSON All of v2.1.284
You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
SandboxArea: what it touches
ImprovementsKind: in v2.1.284,
ImprovementsSection of the release
What

The sandbox limits which files commands can read or write. Its rules can use glob patterns, which are wildcards such as *. On Linux, Claude Code warns "Glob patterns in sandbox permission rules are not fully supported on Linux". That warning now also checks filesystem.denyRead and filesystem.allowRead. Before, it checked only filesystem.allowWrite and filesystem.denyWrite.

A pattern is flagged when the fixed part before its first wildcard is empty or just /, as in **/.env. The suggested fix says that on Linux, glob patterns in Edit and Read rules will be ignored.

Why

A read rule like **/.env cannot be expanded from a fixed folder on Linux. If you have one, you now get a warning instead of a rule that quietly protects less than you expect.

Read from
What the documentation says
filesystem.denyRead Deploy managed settings modified, high confidence * While `filesystem.denyRead`, `filesystem.denyWrite`, or any entry in either is invalid, Claude Code also withholds both `filesystem.allowRead` and `filesystem.allowWrite` until you fix the deny list. see the edit
filesystem.allowRead Deploy managed settings modified, high confidence * While `filesystem.denyRead`, `filesystem.denyWrite`, or any entry in either is invalid, Claude Code also withholds both `filesystem.allowRead` and `filesystem.allowWrite` until you fix the deny list. see the edit
How sure we are
One source agreesOne thing we can check says the same as this entry.
Anthropic's documentation agreesfilesystem.denyRead on Deploy managed settings

See this entry in the whole of v2.1.284 →

Feedback