What
The sandbox is the restricted space Claude Code runs commands in. Its settings can deny access to files. Claude Code now checks deny entries in these places:
filesystem.denyReadfilesystem.denyWritecredentials.filesentries whose mode is "deny"
An absolute path, or a path starting with ~, that ends in a separator such as / is now reported, because such a pattern can match no path. The message suggests removing the trailing slash or adding ** at the end. The check only runs when filesystem sandboxing is not turned off.
Why
Before this, a deny rule written with a trailing slash silently protected nothing. It is now reported, so you can fix it.
filesystem.denyRead
Deploy managed settings modified, high confidence
* While `filesystem.denyRead`, `filesystem.denyWrite`, or any entry in either is invalid, Claude Code also withholds both `filesystem.allowRead` and `filesystem.allowWrite` until you fix the deny list.see the edit
filesystem.denyWrite
Deploy managed settings modified, high confidence
* While `filesystem.denyRead`, `filesystem.denyWrite`, or any entry in either is invalid, Claude Code also withholds both `filesystem.allowRead` and `filesystem.allowWrite` until you fix the deny list.see the edit
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
It is not clear whether this error stops the settings from loading or is only reported.
Anthropic's documentation agrees
filesystem.denyRead on Deploy managed settings