{"version":"2.1.285","anchor":"sandbox-settings-schema-grant-fields-reported-as-enforced","canonical_anchor":"sandbox-settings-schema-grant-fields-reported-as-enforced","heading":"Sandbox status shown to host apps now describes the rules actually enforced","tier":"notice","area":"Sandbox","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285\/e\/sandbox-settings-schema-grant-fields-reported-as-enforced","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285","markdown":"### Sandbox status shown to host apps now describes the rules actually enforced\n\nThe sandbox status that Claude Code reports to host apps now describes the enforced rules and gains a field for allowing all Unix sockets\n\n**Unclear.** It is not clear whether the sandbox enforces anything differently or only reports it differently.\n\n**What**\n\nThe sandbox is a set of limits on what commands run by Claude can reach. Claude Code reports the sandbox's current state to host apps, meaning programs that embed Claude Code. That report has changed:\n\n- `fs_allow_read`, `fs_allow_write` and `unix_sockets` now say they report what is enforced. Project settings are left out while managed settings, set by an organization, require the sandbox.\n\n- A new field, `allow_all_unix_sockets`, says whether all Unix sockets are allowed. A Unix socket is a way for programs on the same machine to talk to each other.\n\n- The descriptions of `allowedDomains` and `strictAllowlist` are expanded to match, and note that `WebFetch(domain:\u2026)` allow rules are left out of the allowlist.\n\n**Why**\n\nA host app showing sandbox settings can now show the policy that is in force, not settings that are being overridden.\n\n- Area: Sandbox\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 1\/5"}