You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
SandboxArea: what it touches
ImprovementsKind: in v2.1.290,
ImprovementsSection of the release
Unclear What triggers the re-check, and whether it only happens when sandboxing is turned on, is not settled.
What
The sandbox is the set of limits Claude Code puts around commands Claude runs, including paths those commands may not read and credential files that are masked. Before the first sandboxed command runs, Claude Code now looks up again where each of those protected paths really points. If one now leads somewhere else, for example because a symbolic link (a shortcut to another location) was changed, it rebuilds the sandbox configuration and says that a read-deny or credential-mask path now resolves somewhere other than where it did when the configuration was built.
If the rebuilt configuration can't be put in place, Claude Code falls back to a stricter setup:
extra access granted by the repository is dropped
masked credential files are replaced as a whole by a placeholder
Why
Without this check, swapping a symbolic link after the sandbox was set up could let a command read a path that was meant to be blocked.
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtWhat triggers the re-check, and whether it only happens when sandboxing is turned on, is not settled.