{"version":"2.1.286","anchor":"sandbox-status-reports-seccompunavailable-and-ripgrepoverrid","canonical_anchor":"sandbox-status-reports-seccompunavailable-and-ripgrepoverrid","heading":"Sandbox status now reports two more ways Linux isolation can be weaker","tier":"notice","area":"Sandbox","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.286\/e\/sandbox-status-reports-seccompunavailable-and-ripgrepoverrid","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.286","markdown":"### Sandbox status now reports two more ways Linux isolation can be weaker\n\nThe sandbox status now says whether seccomp is unavailable and whether ripgrep has been overridden, on platforms other than macOS and Windows\n\n**Unclear.** Where this sandbox status is shown or used is not known.\n\n**What**\n\nThe sandbox is a restricted environment that limits what commands run by Claude can reach on your computer. Claude Code keeps a status summary of how the sandbox is set up. Besides whether it allows Unix sockets, whether it injects credentials and whether it weakens isolation, the summary now also includes:\n\n- `seccompUnavailable`: whether seccomp, a Linux kernel feature that limits what a program may ask the system to do, is unavailable.\n\n- `ripgrepOverridden`: whether ripgrep, the search tool Claude Code uses, has been overridden.\n\nBoth are only worked out on platforms other than macOS and Windows. The \"weakens isolation\" value is now worked out in a separate step.\n\n**Why**\n\nThis gives Claude Code more information on when sandboxing on Linux is running with weaker protection than usual.\n\n- Area: Sandbox\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 2\/5"}