{"version":"2.1.286","anchor":"sandbox-requirement-for-remote-tool-calls-with-explicit-refu","canonical_anchor":"sandbox-requirement-for-remote-tool-calls-with-explicit-refu","heading":"Remote tool calls can be refused when a required sandbox is unavailable","tier":"notice","area":"Sandbox","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.286\/e\/sandbox-requirement-for-remote-tool-calls-with-explicit-refu","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.286","markdown":"### Remote tool calls can be refused when a required sandbox is unavailable\n\nA remote machine set to run calls only inside a sandbox now refuses a call when no sandbox is available, and tells Claude why\n\n**Unclear.** It is not clear who is affected by this or whether it is active yet.\n\n**What**\n\nA sandbox is an isolated space that limits what a command can touch. When Claude asks another machine to run a tool, that machine now picks how to run the call: inside its own process, or inside a virtual machine. If the call would run inside its own process and the machine's settings require a sandbox, the call is refused. It is also refused if the machine could not read all of its settings when the call arrived.\n\nClaude is told about the refusal with one of two messages:\n\n- the machine is set to run this session's calls only inside a sandbox, and the sandbox is not available\n\n- the machine could not read all of its settings when the call arrived, and the call can be tried again\n\nWhen the session is running unattended in a particular mode, a wait that used to always happen before the call is now skipped.\n\n**Why**\n\nA machine that is meant to run calls only in a sandbox no longer runs them without one, and Claude learns why a call failed and whether trying again may help.\n\n- Area: Sandbox\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 3\/5"}