{"version":"2.1.284","anchor":"macos-sandbox-masked-files-and-degraded-paths-become-read-d","canonical_anchor":"macos-sandbox-masked-files-and-degraded-paths-become-read-d","heading":"Sandbox read-deny rules now cover masked secret files and trim default writable paths","tier":"notice","area":"Sandbox","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284\/e\/macos-sandbox-masked-files-and-degraded-paths-become-read-d","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284","markdown":"### Sandbox read-deny rules now cover masked secret files and trim default writable paths\n\nMasked secret files that can't be masked fall back to a read deny, and denyRead now also shapes what sandboxed commands may write\n\n**Unclear.** Where the additional paths come from is not known.\n\n**What**\n\nThe sandbox limits which files commands run by Claude can read and write. How its read-deny rules are built has been reworked.\n\n- Masked secret files that cannot be masked with a bind, a way of hiding a file's contents, now fall back to being denied outright. The masking setup returns a new list, `degradeToDenyPaths`, which is added to the deny rules.\n\n- On macOS, the sandbox profile takes a new `libraryDenyEntries` list, built from the real paths of masked files plus `degradeToDenyPaths`. It now writes read restrictions even when you have not set any `denyRead`. Claude Code logs that a file mask on macOS degrades to a deny \"until the interposer lands\".\n\n- The write allowlist is now worked out from `denyRead`, `allowRead` and credential settings together. `denyRead` entries go through a helper that can turn them into deny paths and collects `unlistableDenyDirs`. Before, `denyRead` and `allowRead` were expanded separately and the write allowlist was only the defaults plus `allowWrite`.\n\n- The home paths the sandbox always made writable, `.npm\/_logs` and `.claude\/debug`, are now left out when a `filesystem.denyRead` entry or a credentials file set to deny covers them, unless `allowRead` allows them again.\n\n- Updating sandbox settings now also recomputes the network domain policy through the same path.\n\n**Why**\n\nSecret files are no longer left readable when masking them fails, and a `denyRead` covering your home directory no longer leaves those two default paths writable. Expect more paths to be blocked for sandboxed commands when `denyRead` or credential masking is configured, especially on macOS.\n\n- Area: Sandbox\n- Names: `denyRead`\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 1\/5"}