یک سندباکس تنها زمانی مفید است که واقعاً عامل (agent) را درون حصار نگه دارد. Claude Code 2.1.216 چندین شکاف را که می‌توانست باعث شود یک وظیفه پس‌زمینه، زیر-عامل (subagent) یا یک نشستِ از سر گرفته شده (resumed session) از دایرکتوری تعیین‌شده خود خارج شود، مسدود کند. این نسخه یک سوئیچ پیکربندی جدید معرفی می‌کند، اما کار مهم‌تر در لایه‌های زیرین انجام شده است: مدیریت هوشمندتر Git worktrees، سم‌لینک‌ها (symlinks) و ری‌استارت‌های عامل. اگر Claude Code را به صورت محلی یا در CI اجرا می‌کنید، این تغییرات ارزش بیشتری نسبت به یک نگاه گذرا به لیست تغییرات (changelog) دارند.

سوئیچ سیستم‌فایل که نباید با آن سهل‌انگاری کنید

نسخه 2.1.216 گزینه sandbox.filesystem.disabled را اضافه می‌کند. وقتی این گزینه تنظیم شود، Claude Code ایزولاسیون سیستم‌فایل خود را نادیده می‌گیرد اما همچنان سندباکس شبکه را اعمال می‌کند. در نگاه اول، این به نظر راهی برای متوقف کردن خطاهای مجوز (permission errors) یا افزایش سرعت عملیات فایل می‌رسد. اما این‌طور نیست. شما باید این تنظیم را تنها زمانی فعال کنید که لایه دیگری از قبل در حال محافظت از دیسک شما باشد.

این یعنی یک کانتینر یک‌بارمصرف که پس از هر اجرا حذف می‌شود، یا یک ماشین مجازی اختصاصی که هیچ دسترسی به دایرکتوری Home یا حجم‌های (volumes) تولید (production) شما ندارد. اگر Claude Code را مستقیماً روی macOS، Windows یا یک میزبان لینوکس خام اجرا می‌کنید، ایزولاسیون سیستم‌فایل را روشن بگذارید. سندباکس شبکه جایگزینی برای کنترل‌های سیستم‌فایل نیست، و اصطکاک جزئی در دسترسی به فایل‌های سندباکس‌شده بسیار ارزان‌تر از بازیابی از یک بازنویسی تصادفی یا یک تزریق پرامپت (prompt injection) مخرب است که از پوشه پروژه خارج شود.

این سوئیچ را به عنوان یک لایه سازگاری (compatibility shim) در نظر بگیرید، نه یک پیچ تنظیم عملکرد. این گزینه برای محیط‌هایی وجود دارد که سیستم‌عامل یا ارکستراتور از قبل ایزولاسیون را مدیریت می‌کنند و سندباکس خودِ Claude پیچیدگی غیرضروری اضافه می‌کند.

این به‌روزرسانی واقعاً چه چیزی را اصلاح می‌کند

فراتر از تنظیمات جدید، نسخه 2.1.216 چندین حفره عملیاتی را که می‌توانست به یک عامل اجازه دسترسی به مکان‌های غیرمجاز را بدهد، می‌بندد.

ایزولاسیون Worktree. زیر-عامل‌ها دیگر نمی‌توانند دستورات Git را به یک دایرکتوری والد یا هم‌سطح خارج از ورک‌تری خود هدایت کنند. پیش از این، یک زیر-عامل که در داخل پروژه شما اجرا می‌شد، می‌توانست عملیات Git را به سمت چک‌اوت‌های مشترک یا مخازن مجاور شما هدف قرار دهد. این موضوع اهمیت دارد زیرا بسیاری از توسعه‌دهندگان چندین پروژه را در یک پوشه والد مشترک نگه می‌دارند. اکنون آن دستوراتِ فراتر از مرز با شکست مواجه می‌شوند.

مقاوم‌سازی سم‌لینک در مسیر .claude. تعریف‌های گردش کار (workflow) و وظایف زمان‌بندی‌شده قبلاً هنگام نوشتن پیکربندی، از سم‌لینک‌ها پیروی می‌کردند. یک مهاجم که می‌توانست یک سم‌لینک از .claude به، مثلاً پروفایل شل یا دایرکتوری SSH شما ایجاد کند، پتانسیل این را داشت که عامل را وادار کند خارج از پروژه چیزی بنویسد. این به‌روزرسانی با امتناع از دنبال کردن سم‌لینک‌ها در آن مسیر، جلوی این کار را می‌گیرد.

بازگشت‌های (rewinds) ایمن‌تر. دستور /rewind که به شما اجازه می‌دهد تغییرات اخیر را به عقب برگردانید، اکنون مسیرهای سم‌لینک‌شده و هارد-لینک‌شده را نادیده می‌گیرد. بدون این محافظ، یک عملیات بازگشت می‌توانست یک سم‌لینک را دنبال کرده و فایلی را در فاصله‌ای دور از مخزن شما بازنویسی کند. Claude اکنون آن مسیرهای نادیده گرفته شده را به طور صریح گزارش می‌دهد تا بدانید مرزها حفظ شده‌اند.

حفظ محدودیت‌ها در عامل‌های از سر گرفته شده. نشست‌های پس‌زمینه که متوقف شده و بعداً از سر گرفته می‌شوند، قبلاً به مجوزهای پیش‌فرض ابزار بازمی‌گشتند. اگر شما عمداً یک عامل را محدود کرده بودید تا فقط بتواند بخواند و نتواند بنویسد، یک ری‌استارت می‌توانست به طور بی‌صدا دسترسی‌های گسترده‌تری را بازیابی کند. اکنون محدودیت‌های اصلی حفظ شده و همراه با نشست بازیابی می‌شوند.

انتخاب یک پروفایل امنیتی

Claude Code 2.1.216 این کنترل‌ها را در سه پروفایل سازماندهی می‌کند. بر اساس محل اجرای ابزار انتخاب کنید، نه بر اساس اینکه کدام احساس سرعت بیشتری دارد.

Default. هر دو سندباکس سیستم‌فایل و شبکه فعال می‌مانند. این انتخاب درستی برای توسعه محلی روی لپ‌تاپ یا ایستگاه کاری شماست. این حالت بدون نیاز به مدیریت کانتینرها، از دایرکتوری Home، فایل‌های سیستم و پروژه‌های مجاور شما محافظت می‌کند.

Compatibility. ایزولاسیون سیستم‌فایل خاموش است، اما سندباکس شبکه باقی می‌ماند. این پروفایل را فقط به کانتینرهای یک‌بارمصرف یا ماشین‌های مجازی محدود کنید که سیستم‌فایل در آن‌ها از قبل موقت (ephemeral) یا با محدوده بسیار دقیق است. از این حالت به این دلیل که از تایپ کردن رمز عبور برای اجازه دادن به عامل جهت دسترسی به یک پوشه محافظت‌شده خسته شده‌اید، استفاده نکنید.

Managed Hard Gate. هر دو لایه سندباکس روشن می‌مانند و این پروفایل انتظار سیاست‌های کانتینری اضافی را دارد که توسط ارکستراتور یا تیم امنیتی شما اعمال می‌شود. این پروفایل برای خط لوله‌های CI، محیط‌های توسعه از راه دور و تنظیمات سازمانی ساخته شده است که در آن‌ها «دفاع در عمق» (defense in depth) الزامی است.

اگر مطمئن نیستید کدام یک مناسب است، با Default شروع کنید. شما تنها پس از اینکه تأیید کردید محیط زمان اجرای شما (runtime environment) واقعاً خودش سیستم‌فایل را ایزوله می‌کند، می‌توانید بعداً سطح محافظت را کاهش دهید.

ارتقا بدون مختل کردن گردش کار شما

Do not treat this as a routine patch you install on a Friday afternoon. The upgrade path in 2.1.216 is straightforward, but the consequences of misconfiguration are not.

First, upgrade to 2.1.216 through your normal package manager or installer. Then pick one of the three isolation profiles before starting any agent tasks. Do not mix profiles across running sessions without understanding which one takes precedence.

Next, run the five non-destructive boundary tests described below. These are quick, scripted checks that prove the sandbox behaves the way the profile promises. During testing, generate sentinel hashes for files outside your disposable test repository. A sentinel hash is simply a checksum of a sensitive file or directory you want to protect. After running the tests, compare the hashes. If anything changed, your isolation is leaking.

Compare your logs as well. Claude Code writes denials and sandbox events to its local logs. Look for explicit rejections when a blocked host is reached or when a subagent steps out of its worktree. Silent failures are worse than loud ones, so verify that the logs show the guardrails kicking in.

Finally, roll the change out gradually. Start with a single project or a non-production branch. Let the new version run for a day or two before you deploy it across your entire team or CI fleet.

Five Boundary Tests That Prove Your Sandbox Works

Always run these tests inside a disposable repository stuffed with fake data. Never point them at production code, real credentials, or live infrastructure.

Network boundary. Attempt to reach two endpoints: one you have explicitly allowed and one you have blocked. A simple HTTP request against a public test service like httpbin.org can serve as the allowed target, while a request to a local metadata endpoint or an internal IP should fail. If the blocked request succeeds, your network sandbox is misconfigured.

Worktree isolation. From inside a subagent, run a Git command aimed at the parent directory. For example, try git -C .. status or have the agent describe files outside its checkout. With the fix in 2.1.216, this must fail. The subagent should see only its own worktree.

Symlink trap. Create a symlink inside your project that points to a directory outside the repository, such as /tmp/sentinel-target. Then try to save a task or workflow under the .claude path that would write through that link. After the save, check the outside directory. If it is still empty, the symlink hardening is working.

Rewind skip. Set up a folder inside your repo that contains a symlink to a system file or another directory. Run /rewind on that folder. Claude should list the skipped symlinked or hard-linked paths rather than chasing them. Confirm that the target outside the repo remains untouched.

Session resurrection. Launch a background agent with a strict restriction, such as disabling file-write tools. Pause or stop the session, then resume it. Immediately try to make the agent write a file. If the restriction is still active, the fix for resumed agents is working. If the agent suddenly has full tool access again, you are still exposed.

Final Word

Claude Code 2.1.216 gives you more flexibility than previous versions, but that flexibility comes with a clear mandate: verify before you trust. The new filesystem toggle is not there to make your life easier at the expense of safety. It is there for engineers who already built a hardened floor underneath the tool. The real improvements in this release are the silent guardrails that stop subagents from creeping into parent directories, that refuse to follow symlinks during configuration writes, and that remember the rules even after a long pause.

Run the five tests. Check your sentinel hashes. Read the logs. Then, and only then, let the new version handle real work.

Source: Claude Code v2.1.216 Release Notes

Optional learning community: GyaanSetu on Telegram