{"version":"2.1.284","anchor":"sandbox-filesystemdenywrite-now-applies-in-the-person-san","canonical_anchor":"sandbox-filesystemdenywrite-now-applies-in-the-person-san","heading":"Sandbox write-deny paths now apply in one more sandbox mode","tier":"notice","area":"Sandbox","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284\/e\/sandbox-filesystemdenywrite-now-applies-in-the-person-san","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284","markdown":"### Sandbox write-deny paths now apply in one more sandbox mode\n\nYour sandbox `filesystem.denyWrite` paths are now enforced in the sandbox mode used when a proxy port is configured, where they were ignored\n\n**Unclear.** What this particular sandbox mode is used for is not clear; it may be a sandbox for scripts or checks.\n\n**What**\n\nThe sandbox is the walled-off environment Claude Code can run commands in, with rules about which files they may read or write. One of its modes, chosen when a proxy port is configured and that mode is available, used only your `filesystem.denyRead` setting from the sandbox configuration. It now also adds the paths in your `filesystem.denyWrite` setting to the list of places commands are not allowed to write.\n\nBefore, that mode blocked writes only to a fixed set of places such as project roots, your home folder, device files and temporary folders.\n\n**Why**\n\nA write rule you set could be silently ignored in this mode. It now takes effect there too, so stricter write limits you configure are actually enforced.\n\n- Area: Sandbox\n- Names: `filesystem.denyWrite`\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 1\/5"}