Unclear It is not clear what switches the handling of relative names on, or whether it applies in every session.
What
Before Claude reads or uses a file path, Claude Code checks whether that path is safe and may ask you first or refuse. This release widens that check.
- MCP tools are tools that outside servers add to Claude Code. File names in their input that look relative, such as
dir/file, are now resolved against the working directory, the folder Claude Code is running in. They are then checked like any other path. The check can return a newrelative_pathresult and attach awhyexplanation when it decides to ask you. Before, it returned onlyask,web_addressor deny. - Mount points, places where another drive or volume is attached, are now taken into account, so paths on mounted volumes are checked. On macOS,
/volumesis now guarded. - The list of path descriptions gains three new kinds: magic links, which are paths through an open file descriptor or a process's
/proclink; paths too long to open; and paths in a home folder the session does not know about.
Why
More kinds of paths can now lead to a permission prompt or a refusal, including relative names passed to MCP tools and /proc or file-descriptor paths. Expect prompts in some cases that went through before.
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
It is not clear what switches the handling of relative names on, or whether it applies in every session.