Claude Code v2.1.285 ·
Sandbox can report its configured network and file permissions
The sandbox can now report its configured network allowances, file permissions and Unix socket setting, and cleans up more after a command
You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
SandboxArea: what it touches
ImprovementsKind: in v2.1.285,
ImprovementsSection of the release
What
The sandbox is the restricted area Claude Code can run commands in, limiting which files and network addresses they can reach. It can now report:
- which network allowances are configured
- which file system permissions are configured
- whether all Unix sockets (a way for programs on one machine to talk to each other) are allowed
- whether a trusted setting has closed off the option of running a command outside the sandbox
The cleanup that runs after each command now also runs an extra cleanup step.
Why
This suggests stricter handling of sandbox rules, where some configurations can stop commands from falling back to running unsandboxed.
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtWhether the check that blocks running outside the sandbox is actually used yet is not clear.
See this entry in the whole of v2.1.285 →