Follow Discord
Sweep 08 Oct 2026 · 18:53Z Build v2.1.295 516 read Stable v2.1.286 Latest v2.1.295 Next v2.1.295 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.292 ·

File reads, search and attachments hardened against swapped paths

Attachments are re-checked when opened, Grep reads through an inherited file handle, and new directories are private to your user

Group of 3 You'll notice Improvements
JSON All of v2.1.292
You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
PermissionsArea: what it touches
ImprovementsKind: in v2.1.292,
ImprovementsSection of the release

What

Several changes tighten how Claude Code opens and reads files:

  • Attachments: in --restricted mode, or when blockReadsOutsideWorkingDirectories is set, the check on attached files now records which path it approved and the file's identity. When the file is opened, Claude Code compares the device and inode numbers (the file's identity on disk) and, on Linux, checks through /proc/self/fd that the open file really is at the approved path. If not, it refuses with errors such as "it opened at a different path than approved". Before, only the device and inode were compared. The documentation changelog lists a related fix: an @-mention under the read block or --restricted could read a file outside the working directories through a link changed mid-read.
  • Grep: the search program it runs, ripgrep, is now handed an already-open file through inheritFd instead of a /proc/<pid>/fd/N path, with extra checks on /proc/ paths.
  • Directories: a helper that creates directories now creates them with mode: 448, meaning 0700, so only your user can open them.
  • Bash: the tool result gains leftRunningPgid when a command leaves its process group (the command and anything it started) still running after a turn.

Why

These close gaps where a file or link could be swapped between the moment Claude Code checks it and the moment it reads it, which matters most in restricted setups. The Bash addition makes it visible when a command leaves processes running in the background.

Read from
Names in the bundle--restricted
What the documentation says
--restricted Claude Code changelog modified, high confidence * Fixed an `@`-mention under the read block or `--restricted` being able to read a file outside the working directories through a link changed mid-read see the edit
--restricted Choose a permission mode modified, high confidence * Markdown files in the project's [auto memory](/docs/en/memory#storage-location) directory, such as `~/.claude/projects/<project>/memory/`, in a session started without `--restricted` see the edit
Since it was published

The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.

Confirmed since Anthropic's documentation has since written up --restricted, on Claude Code changelog. * Fixed `--tools` and `--restricted` not applying to built-in tools that register after launch, and deprecated tool names reaching tools outside the caller's tool set changelog see the edit
How sure we are
One source agreesOne thing we can check says the same as this entry.
Anthropic's documentation agrees--restricted on Claude Code changelog

See this entry in the whole of v2.1.292 →

Feedback