{"version":"2.1.284","anchor":"sandbox-glob-expansion-rewritten-to-follow-symlinks-plus-de","canonical_anchor":"sandbox-glob-expansion-rewritten-to-follow-symlinks-plus-de","heading":"Sandbox path rules now follow symbolic links and respect read-deny rules","tier":"notice","area":"Sandbox","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284\/e\/sandbox-glob-expansion-rewritten-to-follow-symlinks-plus-de","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284","markdown":"### Sandbox path rules now follow symbolic links and respect read-deny rules\n\nSandbox path patterns now match through linked folders, and `denyRead` rules are no longer undercut by default writable folders\n\n**Unclear.** Where the new IP address range handling is used is not confirmed.\n\n**What**\n\nThe sandbox limits which files and addresses commands can reach, using rules that can contain wildcard patterns. Matching those patterns has been rewritten:\n\n- Patterns are followed one folder at a time instead of listing the whole starting folder.\n\n- Symbolic links to folders (shortcuts that point to another folder) are followed, without looping forever.\n\n- Folders that could not be listed are recorded.\n\n- Warnings appear for rules that still contain `..` and for patterns with no fixed folder to start from.\n\nThe default writable folders `.npm\/_logs` and `.claude\/debug` in your home folder are now left out when a `denyRead` rule covers them and no `allowRead` rule allows them again. Claude Code can also now read IP address ranges in IPv4 and IPv6 form and recognise localhost addresses.\n\n**Why**\n\nWhen sandboxing is on, path rules now match correctly through linked folders, and a rule blocking reads can no longer be quietly weakened by the default write exceptions.\n\n- Area: Sandbox\n- Tier: You'll notice\n- Useful: 3\/5\n- Signal: 2\/5"}