Canary the deny, not merely the configuration
Use
when:
running
Claude
Code
with
the
sandbox
enabled
on
macOS,
especially
when
a
broad
allowRead
region
contains
.env
files,
nested
secret
directories,
or
credentials
that
a
command
can
move.
Also
use
after
changing
any
deny
glob:
a
valid
rule
may
still
lose
to
a
wider
allow
or
cover
only
one
tool
plane.
2.1.236
or
newer.
In
project
.claude/settings.json,
set
sandbox.enabled=true,
sandbox.failIfUnavailable=true,
sandbox.allowUnsandboxedCommands=false,
sandbox.filesystem.allowRead=["."],
and
sandbox.filesystem.denyRead=["**/.env","**/.env.*","**/secrets/**"].
Pair
that
with
permissions.deny
entries
Read(**/.env),
Read(**/.env.*),
and
Read(**/secrets/**)
so
the
built-in
file
plane
and
sandboxed
subprocess
plane
share
the
boundary.
Before
rollout,
create
a
disposable
fixture
containing
.env,
nested/.env.prod,
secrets/token.txt,
and
public.txt,
each
with
a
unique
sentinel.
Attempt
each
denied
read
through
the
Read
tool,
direct
cat,
a
small
Python
reader,
and
mv .env moved.txt && cat moved.txt;
read
public.txt
as
the
positive
control.
Acceptance
check:
pass
only
if
every
secret
route
returns
a
denial
or
Operation not permitted,
no
secret
sentinel
appears
in
the
transcript,
and
the
rename-and-read
chain
cannot
complete.
The
public.txt
control
must
remain
readable
through
both
Read
and
cat.
Repeat
after
changing
the
working
directory,
resuming
the
session,
and
upgrading
the
CLI.
Any
leaked
sentinel,
unavailable
sandbox,
or
control
failure
blocks
deployment;
a
clean
settings
parse
alone
does
not
pass.
2.1.236
release
explicitly
names
all
three
repairs.
The
current
sandbox
reference
defines
the
more-specific-path
precedence
and
shows
an
exact
deny
remaining
closed
inside
a
broader
allow.
Issue
#45570
provides
the
inspectable
macOS
counterexample:
a
parent
allow
overrode
a
credential-file
deny,
and
a
Bash-spawned
Python
reader
recovered
the
secret.
Caveat:
the
release
claim
is
macOS-specific,
and
Anthropic
publishes
no
regression
output.
Linux
uses
a
different
sandbox
implementation;
MCP
servers,
unsandboxed
fallbacks,
hooks,
and
other
native
helpers
need
separate
capability
tests.
Version
2.1.237
landed
minutes
before
this
scan;
retain
the
canary
rather
than
trusting
the
version
string.