{"version":"2.1.292","anchor":"sandbox-read-deny-fallback-reworked","canonical_anchor":"sandbox-read-deny-fallback-reworked","heading":"Sandbox fallback explains its cause and limits credential injection","tier":"notice","area":"Sandbox","scope":"individual","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.292\/e\/sandbox-read-deny-fallback-reworked","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.292","markdown":"### Sandbox fallback explains its cause and limits credential injection\n\nWhen Claude Code falls back to a backup sandbox setup, it now logs the specific cause and reduces credential masks a moved path may cover\n\n**What**\n\nThe sandbox is the walled-off space Claude Code runs commands in, so they can only reach what they are allowed to. Sometimes Claude Code has to install a backup sandbox setup. When that happens:\n\n- The log message names the specific cause. Before, it was a fixed message saying a rebuilt setup could not be put in place.\n\n- Claude Code records how many access grants were dropped and how many masks were reduced.\n\n- A credential mask is a rule that hides a secret inside a file and puts the real value in only when needed. If a moved path may now cover such a mask, Claude Code reduces it to a placeholder for the whole file and does not put the credential in.\n\n**Why**\n\nThe backup setup now handles paths that have moved without passing credentials through by mistake, and its log says why the backup was needed.\n\n- Area: Sandbox\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 2\/5\n- Scope: individual\n- Heads-up: no"}