Follow Discord
Sweep 01 Oct 2026 · 17:27Z Build v2.1.287 508 read Stable v2.1.285 Latest v2.1.287 Next v2.1.287 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.286 ·

Cloud sessions running commands on your computer get a hook sandbox, auto-mode notices and hook-rewrite rules

Remote tools gains a bubblewrap sandbox for project hooks, reasons for auto mode being off, and finer handling of hook input rewrites

Group of 3 You'll notice Notable Nothing to try yet In Development
JSON All of v2.1.286
You'll noticeTier: how much it should matter to you
5Useful: my rating, 1 to 5
5Signal: worth watching, 1 to 5
SandboxArea: what it touches
In DevelopmentKind: in v2.1.286,
What probably matters to youSection of the release

What

Remote tools let a Claude Code cloud session run commands on your own computer. This release changes how such commands are approved and how project hooks run. A hook is a command your project sets up to run automatically at certain points.

  • Project hooks can run inside a bubblewrap (bwrap) sandbox, a walled-off area that limits what a program can see or do. It cuts the hook off from the network and other processes, gives read-only access to system folders, hides home folders, and applies extra limits through /run/claude-hook/apply-seccomp.
  • The sandbox is tried once first. If it cannot be used, Claude Code logs "[remote-tools] a project hook cannot be run in a sandbox on this machine" with a reason such as bubblewrap_too_old (version 0.10.0 or later needed), no_bubblewrap, no_seccomp_stage, bubblewrap_failed, home_in_view or credentials_in_view.
  • On Linux this requires the server-controlled switch tengu_violin_heel to be true, not set as a local override, plus a further check. macOS does not use that switch. A second switch, tengu_violin_saddle, guards the path used when sandboxing or a proxy is active.
  • New messages explain why auto mode (Claude acting without asking each time) is off for unattended commands from cloud sessions: consent not given, declined or unreadable; turned off by remoteTools.allowUnattendedServing or disableAutoMode; or a built-in safety cut-off.
  • When a hook rewrites the input of a request that asked for approval, the rewrite is now classed as none, own_hooks_alone or unvouched. The message says the classifier answer was set aside only for unvouched rewrites. Before, it always said both the earlier answer and the classifier were set aside.

Why

You now see why a cloud session is asking for approval on your machine. The most recent reading of tengu_violin_heel, taken before this release, was on for this site's account and the anonymous baseline. If the sandbox is in use, a Linux project hook that needs the network may fail.

Read from
Names in the bundlebwrap
Feature flag
tengu_violin_heel Off by default, switched on for this account

The shipped code defaults this off, and the flag server returned on for the one account this site reads on this version. That is the reading that makes the entry above worth a second look, and it still says nothing about your account.

This account: on · anonymous baseline: on · compiled default in v2.1.286: off

These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.

tengu_violin_saddle Off by default, switched on for this account

The shipped code defaults this off, and the flag server returned on for the one account this site reads on this version. That is the reading that makes the entry above worth a second look, and it still says nothing about your account.

This account: on · anonymous baseline: on · compiled default in v2.1.286: off

These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.

Read once, for one account on one subscription tier, against v2.1.286. It isn't a statement about your account. What a flag value here can and cannot tell you

Since it was published

The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.

Confirmed since Anthropic's documentation has since written up bwrap, on Configure the sandboxed Bash tool. In an unprivileged container, [bubblewrap](#os-level-enforcement) can't mount a fresh `/proc` filesystem, so sandboxed commands fail with a `bwrap` error such as `Can't mount proc on /newroot/proc: Operation not permitted`. Set [`enableWea… sandboxing see the edit
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtWhat the further check requires, and exactly which hook runs take the Linux sandbox path.
Anthropic's documentation agreesAnthropic's documentation has since written up bwrap, on Configure the sandboxed Bash tool.

See this entry in the whole of v2.1.286 →

Feedback