{"version":"2.1.290","anchor":"sandbox-re-checks-trusted-read-deny-paths-for-symlink-change","canonical_anchor":"sandbox-re-checks-trusted-read-deny-paths-for-symlink-change","heading":"Sandbox re-checks protected paths for moved symlinks before the first command","tier":"notice","area":"Sandbox","scope":"individual","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290\/e\/sandbox-re-checks-trusted-read-deny-paths-for-symlink-change","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290","markdown":"### Sandbox re-checks protected paths for moved symlinks before the first command\n\nBefore its first sandboxed command, Claude Code re-checks where blocked and credential paths point and rebuilds the sandbox if they moved\n\n**Unclear.** What triggers the re-check, and whether it only happens when sandboxing is turned on, is not settled.\n\n**What**\n\nThe sandbox is the set of limits Claude Code puts around commands Claude runs, including paths those commands may not read and credential files that are masked. Before the first sandboxed command runs, Claude Code now looks up again where each of those protected paths really points. If one now leads somewhere else, for example because a symbolic link (a shortcut to another location) was changed, it rebuilds the sandbox configuration and says that a read-deny or credential-mask path now resolves somewhere other than where it did when the configuration was built.\n\nIf the rebuilt configuration can't be put in place, Claude Code falls back to a stricter setup:\n\n- extra access granted by the repository is dropped\n\n- masked credential files are replaced as a whole by a placeholder\n\n**Why**\n\nWithout this check, swapping a symbolic link after the sandbox was set up could let a command read a path that was meant to be blocked.\n\n- Area: Sandbox\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5\n- Scope: individual\n- Heads-up: no"}