What
Several changes tighten how Claude Code opens and reads files:
- Attachments: in
--restrictedmode, or whenblockReadsOutsideWorkingDirectoriesis set, the check on attached files now records which path it approved and the file's identity. When the file is opened, Claude Code compares the device and inode numbers (the file's identity on disk) and, on Linux, checks through/proc/self/fdthat the open file really is at the approved path. If not, it refuses with errors such as "it opened at a different path than approved". Before, only the device and inode were compared. The documentation changelog lists a related fix: an@-mention under the read block or--restrictedcould read a file outside the working directories through a link changed mid-read. - Grep: the search program it runs, ripgrep, is now handed an already-open file through
inheritFdinstead of a/proc/<pid>/fd/Npath, with extra checks on/proc/paths. - Directories: a helper that creates directories now creates them with
mode: 448, meaning 0700, so only your user can open them. - Bash: the tool result gains
leftRunningPgidwhen a command leaves its process group (the command and anything it started) still running after a turn.
Why
These close gaps where a file or link could be swapped between the moment Claude Code checks it and the moment it reads it, which matters most in restricted setups. The Bash addition makes it visible when a command leaves processes running in the background.
Names in the bundle--restricted
--restricted
Claude Code changelog modified, high confidence
* Fixed an `@`-mention under the read block or `--restricted` being able to read a file outside the working directories through a link changed mid-readsee the edit
--restricted
Choose a permission mode modified, high confidence
* Markdown files in the project's [auto memory](/docs/en/memory#storage-location) directory, such as `~/.claude/projects/<project>/memory/`, in a session started without `--restricted`see the edit
The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.
Confirmed since
Anthropic's documentation has since written up --restricted, on Claude Code changelog.
* Fixed `--tools` and `--restricted` not applying to built-in tools that register after launch, and deprecated tool names reaching tools outside the caller's tool setchangelog see the edit
One source agreesOne thing we can check says the same as this entry.
Anthropic's documentation agrees
--restricted on Claude Code changelog