Claude Code now reads two environment variables (settings passed in from whatever launches it):
CLAUDE_CODE_HOST_WORKTREEnames a worktree, a separate working copy of a project.CLAUDE_CODE_HOST_WORKTREE_FENCEnames the fenced paths.
When they are set, Claude Code's file tools (the tools it uses to create and edit files) refuse to write inside the fenced paths, except inside the declared worktree. The refusal tells Claude to edit the worktree copy instead. If the values cannot be read, they are ignored, a log entry says so, and no write is blocked.
Claude Code removes both variables from the environment it hands to the programs it starts, so they do not leak further down.
This gives an app that embeds Claude Code a way to keep it writing only to a worktree. Ordinary terminal users who do not set these variables see no change.
Which host application sets these variables is not shown.