{"version":"2.1.285","anchor":"sandbox-late-symlink-grants-are-re-screened-and-dropped","canonical_anchor":"sandbox-late-symlink-grants-are-re-screened-and-dropped","heading":"Sandbox drops read and write paths that were re-linked after setup","tier":"notice","area":"Sandbox","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285\/e\/sandbox-late-symlink-grants-are-re-screened-and-dropped","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285","markdown":"### Sandbox drops read and write paths that were re-linked after setup\n\nSandbox `allowRead` and `allowWrite` paths re-pointed by a link after setup are now checked again and dropped if unsafe or pointing into a denied path\n\n**Unclear.** How often this situation can arise in normal use is not settled.\n\n**What**\n\nThe sandbox limits which files commands run by Claude may read and write. A symbolic link is a file that points to another location. If an `allowRead` or `allowWrite` path is re-pointed through a symbolic link after the sandbox settings were put together, Claude Code now checks it again. The path is dropped when:\n\n- Unsafe: it no longer resolves safely.\n\n- Denied: it now leads into a path the sandbox is not allowed to read.\n\nEach dropped path is logged with \"[Sandbox] dropped\".\n\n**Why**\n\nSwapping a link after setup can no longer be used to reach files the sandbox is meant to keep unreadable.\n\n- Area: Sandbox\n- Names: `allowRead`, `allowWrite`\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5"}