{"version":"2.1.285","anchor":"sandbox-read-deny-setting-text-globsunc-values-ignored","canonical_anchor":"sandbox-read-deny-setting-text-globsunc-values-ignored","heading":"Sandbox text explains when read-deny values are ignored or dropped","tier":"notice","area":"Sandbox","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285\/e\/sandbox-read-deny-setting-text-globsunc-values-ignored","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285","markdown":"### Sandbox text explains when read-deny values are ignored or dropped\n\nNew sandbox text says glob, UNC and automount values are ignored, and values re-pointed into a denied read path are dropped\n\n**Unclear.** It is not clear where this text appears or which setting it describes.\n\n**What**\n\nThe sandbox is the protected area Claude Code runs commands in, which limits what files they can read and write. Claude Code now includes text describing how the sandbox treats certain values:\n\n- A value that sits under a path you have denied for reading is ignored.\n\n- A value written as a glob (a wildcard pattern such as `*.txt`) is ignored.\n\n- A value written as a UNC path (a Windows network path starting with `\\\\`) or an automount path is ignored.\n\n- A value inside a writable directory is checked again before every command, and dropped once it has been re-pointed into a denied read path.\n\n**Why**\n\nThe text describes a tightening of the sandbox. A value cannot be quietly redirected into a folder you blocked from reading, because it is checked again before each command runs.\n\n- Area: Sandbox\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5"}