{"version":"2.1.285","anchor":"sandbox-and-git-seed-hardening","canonical_anchor":"sandbox-and-git-seed-hardening","heading":"Cloud session seeding refuses a symbolic git HEAD; sandbox and device checks tightened","tier":"notice","area":"Sandbox","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285\/e\/sandbox-and-git-seed-hardening","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285","markdown":"### Cloud session seeding refuses a symbolic git HEAD; sandbox and device checks tightened\n\nCloud sessions reject a git HEAD on a symbolic ref and suggest git switch, alongside sandbox config and untrusted-device enrollment tweaks\n\n**Unclear.** It is not clear what condition decides when the administrator-managed merging applies.\n\n**What**\n\nWhen you start a cloud session, Claude Code copies ('seeds') your git repository into it. Seeding now refuses a repository whose current position (HEAD) is checked out under a symbolic ref, meaning a second name that points at another branch. The error is `symbolic_head`, and it comes with a hint to use `git switch` to move to the branch by its own name. Seeding also now checks the working files before it rebuilds its cached copy of the repository.\n\nOther changes in the same area:\n\n- Sandbox settings now keep track of symlink permissions granted later and of blocked folders. The sandbox is a walled-off area that limits what commands can touch. A symlink is a shortcut that points to another file or folder.\n\n- In managed mode, `ignoreViolations` and the options that allow a weaker nested sandbox or weaker network isolation are now combined through a shared merge step.\n\n- When a request is refused with a 403 error because the device is not trusted, Claude Code now checks whether cloud sessions or Remote Control should enroll the device before trying to recover. Before, it always tried to recover.\n\n**Why**\n\nIf a cloud session will not start and mentions a symbolic ref, switch to your branch by name with `git switch` and try again. The other changes tighten how the sandbox and device trust are handled.\n\n- Area: Sandbox\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 2\/5"}