Daily harness signal

Make secret-file denies survive broad access

August 20, 2026 · JST One fresh finding Claude Code · macOS · sandbox
A fresh macOS sandbox repair closes three secret-file leaks: wildcard denies now outrank broad allows, cover directory contents, and survive renames. Treat every path-policy update as a multi-route release test.
01 · Fresh · source date 2026-08-19

Canary the deny, not merely the configuration

Use when: running Claude Code with the sandbox enabled on macOS, especially when a broad allowRead region contains .env files, nested secret directories, or credentials that a command can move. Also use after changing any deny glob: a valid rule may still lose to a wider allow or cover only one tool plane.

Action: require Claude Code 2.1.236 or newer. In project .claude/settings.json, set sandbox.enabled=true, sandbox.failIfUnavailable=true, sandbox.allowUnsandboxedCommands=false, sandbox.filesystem.allowRead=["."], and sandbox.filesystem.denyRead=["**/.env","**/.env.*","**/secrets/**"]. Pair that with permissions.deny entries Read(**/.env), Read(**/.env.*), and Read(**/secrets/**) so the built-in file plane and sandboxed subprocess plane share the boundary. Before rollout, create a disposable fixture containing .env, nested/.env.prod, secrets/token.txt, and public.txt, each with a unique sentinel. Attempt each denied read through the Read tool, direct cat, a small Python reader, and mv .env moved.txt && cat moved.txt; read public.txt as the positive control.

Acceptance check: pass only if every secret route returns a denial or Operation not permitted, no secret sentinel appears in the transcript, and the rename-and-read chain cannot complete. The public.txt control must remain readable through both Read and cat. Repeat after changing the working directory, resuming the session, and upgrading the CLI. Any leaked sentinel, unavailable sandbox, or control failure blocks deployment; a clean settings parse alone does not pass.

Evidence: Anthropic’s signed 2.1.236 release explicitly names all three repairs. The current sandbox reference defines the more-specific-path precedence and shows an exact deny remaining closed inside a broader allow. Issue #45570 provides the inspectable macOS counterexample: a parent allow overrode a credential-file deny, and a Bash-spawned Python reader recovered the secret.

Caveat: the release claim is macOS-specific, and Anthropic publishes no regression output. Linux uses a different sandbox implementation; MCP servers, unsandboxed fallbacks, hooks, and other native helpers need separate capability tests. Version 2.1.237 landed minutes before this scan; retain the canary rather than trusting the version string.

Compact source notes

  1. Anthropic, Claude Code v2.1.236 (published 2026-08-19 20:02 UTC). Official release: macOS wildcard read-deny precedence, directory coverage, and rename-bypass repair.
  2. Claude Code sandbox reference (retrieved 2026-08-20). Current rule-overlap examples and fail-closed sandbox settings.
  3. Claude Code permissions reference (retrieved 2026-08-20). Current Read(**/.env) semantics and tool-level deny syntax.
  4. anthropics/claude-code issue #45570 (retrieved 2026-08-20). Artifact-backed macOS reproduction for broad-allow precedence and subprocess leakage.
  5. Method: primary release/docs first; contradiction check against a versioned field reproduction. Confidence: Confirmed for the shipped release statement and documented rule contract; runtime benefit remains unverified locally.