{"version":"2.1.284","anchor":"macos-sandbox-check-can-now-return-a-person-mode-instead-o","canonical_anchor":"macos-sandbox-check-can-now-return-a-person-mode-instead-o","heading":"macOS sandbox check gives more detailed answers when a sandbox is already on","tier":"internal","area":"Sandbox","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284\/e\/macos-sandbox-check-can-now-return-a-person-mode-instead-o","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284","markdown":"### macOS sandbox check gives more detailed answers when a sandbox is already on\n\nOn macOS, the check for whether a sandboxed feature can run now returns one of several modes instead of always refusing when a sandbox is already active\n\n**Unclear.** It is not clear which feature relies on this check, or what the new capability check behind the `person` mode tests.\n\n**What**\n\nA sandbox is a restricted environment that limits what commands can reach. On macOS, Claude Code runs a check to decide whether a sandboxed feature can be used. That check now returns more detailed results:\n\n- `person`: returned when sandboxing or a network proxy is already on and a newer capability check passes. Before, this case always returned `person_sandbox`.\n\n- `person_read_rules`: returned when read rules conflict.\n\n- `locked`: returned on the normal success path.\n\nThe check can also report that the feature is unavailable.\n\n**Why**\n\nA sandboxed feature on macOS may now work inside a session that is already sandboxed, where before it was always turned away.\n\n- Area: Sandbox\n- Tier: Under the hood\n- Useful: 1\/5\n- Signal: 1\/5"}