What
The sandbox limits which files and addresses commands can reach, using rules that can contain wildcard patterns. Matching those patterns has been rewritten:
- Patterns are followed one folder at a time instead of listing the whole starting folder.
- Symbolic links to folders (shortcuts that point to another folder) are followed, without looping forever.
- Folders that could not be listed are recorded.
- Warnings appear for rules that still contain
..and for patterns with no fixed folder to start from.
The default writable folders .npm/_logs and .claude/debug in your home folder are now left out when a denyRead rule covers them and no allowRead rule allows them again. Claude Code can also now read IP address ranges in IPv4 and IPv6 form and recognise localhost addresses.
Why
When sandboxing is on, path rules now match correctly through linked folders, and a rule blocking reads can no longer be quietly weakened by the default write exceptions.
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
Where the new IP address range handling is used is not confirmed.