What
The sandbox limits which files commands run by Claude Code can touch. Part of its setup is a list of files it may not read, plus exceptions that open some of them again. This release changes how that list is put together.
- The function that collects read rules now accepts an optional settings object. It merges deny and ask rules from user settings, plus sandbox re-opens, from that object and removes duplicates. Before, rules came only from settings already loaded from their usual places.
- Sandbox
allowReadentries, called re-opens because they open up paths that were otherwise blocked, are now collected as well. - Sandbox credential files (
credentials?.files) are now worked out once across every settings level up front, instead of inside the loop over each level. Their deny forms feed the check that decides whether anallowReadentry re-opens a path.
Why
User-settings edits that have not been saved yet are now taken into account when deciding which files the sandbox blocks. Credential files are checked against allowRead re-opens, which affects whether an exception can open them up.
Names in the bundleallowRead
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
What part of Claude Code passes these settings in is not known.