{"version":"2.1.288","anchor":"host-set-worktree-fence-env-vars-now-enforced-on-file-writes","canonical_anchor":"host-set-worktree-fence-env-vars-now-enforced-on-file-writes","heading":"Host apps can fence off folders so file tools write only to a worktree","tier":"use","area":"Worktrees","scope":"both","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.288\/e\/host-set-worktree-fence-env-vars-now-enforced-on-file-writes","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.288","markdown":"### Host apps can fence off folders so file tools write only to a worktree\n\nTwo new environment variables let an embedding app block file writes inside chosen paths, except inside one declared worktree\n\n**Unclear.** Which host application sets these variables is not shown.\n\n**What**\n\nClaude Code now reads two environment variables (settings passed in from whatever launches it):\n\n- `CLAUDE_CODE_HOST_WORKTREE` names a worktree, a separate working copy of a project.\n\n- `CLAUDE_CODE_HOST_WORKTREE_FENCE` names the fenced paths.\n\nWhen they are set, Claude Code's file tools (the tools it uses to create and edit files) refuse to write inside the fenced paths, except inside the declared worktree. The refusal tells Claude to edit the worktree copy instead. If the values cannot be read, they are ignored, a log entry says so, and no write is blocked.\n\nClaude Code removes both variables from the environment it hands to the programs it starts, so they do not leak further down.\n\n**Why**\n\nThis gives an app that embeds Claude Code a way to keep it writing only to a worktree. Ordinary terminal users who do not set these variables see no change.\n\n- Area: Worktrees\n- Names: `CLAUDE_CODE_HOST_WORKTREE`, `CLAUDE_CODE_HOST_WORKTREE_FENCE`\n- Tier: Use it now\n- Useful: 5\/5\n- Signal: 4\/5\n- Scope: both\n- Heads-up: no"}