सँडबॉक्स (sandbox) तेव्हाच उपयुक्त ठरतो जेव्हा तो एजंटला खरोखरच मर्यादेत ठेवतो. Claude Code 2.1.216 ने अशा अनेक त्रुटी दूर केल्या आहेत ज्यांमुळे बॅकग्राउंड टास्क, सब-एजंट किंवा पुन्हा सुरू झालेला सेशन त्यांच्या नियुक्त केलेल्या डिरेक्टरीच्या बाहेर जाऊ शकत होते. या रिलीजमध्ये एक नवीन कॉन्फिगरेशन स्विच आणला आहे, परंतु अधिक महत्त्वाचे काम अंतर्गत (under the hood) झाले आहे: Git worktrees, symlinks आणि एजंट रिस्टार्ट्सचे अधिक स्मार्ट हँडलिंग. जर तुम्ही Claude Code स्थानिक पातळीवर (locally) किंवा CI मध्ये चालवत असाल, तर या बदलांकडे केवळ चँजलॉगचा एक भाग म्हणून न पाहता त्यांचे गांभीर्य समजून घेणे आवश्यक आहे.

फाईलसिस्टम टॉगल (Filesystem Toggle) ज्याला तुम्ही हलक्यात घेऊ नये

व्हर्जन 2.1.216 मध्ये sandbox.filesystem.disabled जोडले आहे. जेव्हा हे सेट केले जाते, तेव्हा Claude Code नेटवर्क सँडबॉक्स लागू ठेवत असताना स्वतःचे फाईलसिस्टम आयसोलेशन (filesystem isolation) वगळते. पहिल्या दृष्टीक्षेपात हे परमिशन एरर्स थांबवण्यासाठी किंवा फाईल ऑपरेशन्सचा वेग वाढवण्यासाठी एक मार्ग वाटू शकतो. पण तसे नाही. जर तुमच्या डिस्कचे संरक्षण करण्यासाठी आधीच दुसरी एखादी लेयर (layer) असेल, तरच तुम्ही हे सेटिंग इनेबल केले पाहिजे.

याचा अर्थ असा की, प्रत्येक रननंतर डिलीट होणारा डिस्पोजेबल कंटेनर (disposable container), किंवा तुमच्या होम डिरेक्टरी किंवा प्रोडक्शन व्हॉल्युम्सना प्रवेश नसलेला एखादा समर्पित व्हर्च्युअल मशीन (virtual machine). जर तुम्ही Claude Code थेट macOS, Windows किंवा बॅर लिनक्स (bare Linux) होस्टवर चालवत असाल, तर फाईलसिस्टम आयसोलेशन चालूच ठेवा. नेटवर्क सँडबॉक्स हा फाईलसिस्टम नियंत्रणांचा पर्याय नाही, आणि सँडबॉक्स केलेल्या फाईल ॲक्सेसमधील थोडासा अडथळा हा चुकून फाईल ओव्हरराईट होणे किंवा प्रोजेक्ट फोल्डरच्या बाहेर पडणाऱ्या घातक प्रॉम्प्ट इंजेक्शनमुळे (malicious prompt injection) होणाऱ्या नुकसानीपेक्षा खूपच स्वस्त आहे.

या टॉगलला परफॉर्मन्स वाढवण्याचे साधन (performance knob) न समजता, एक सुसंगतता शिम (compatibility shim) म्हणून पहा. हे अशा वातावरणासाठी आहे जिथे ऑपरेटिंग सिस्टम किंवा ऑर्केस्ट्रेटर आधीच आयसोलेशन हाताळते आणि Claude चा स्वतःचा सँडबॉक्स अनावश्यक गुंतागुंत निर्माण करतो.

अपडेट नेमके काय सुधारते

नवीन सेटिंग व्यतिरिक्त, 2.1.216 ने अशा अनेक व्यावहारिक त्रुटी (holes) बंद केल्या आहेत ज्यामुळे एजंटला नको असलेल्या ठिकाणी पोहोचता येऊ शकले असते.

Worktree isolation. सब-एजंट्स आता त्यांच्या स्वतःच्या वर्कट्रीच्या बाहेर असलेल्या पैरेंट किंवा सिबलिंग डिरेक्टरीमध्ये Git कमांड्स रिडायरेक्ट करू शकत नाहीत. पूर्वी, तुमच्या प्रोजेक्टमध्ये चालणारा सब-एजंट तुमच्या शेअर केलेल्या चेकआउट किंवा शेजारील रिपॉझिटरीजवर Git ऑपरेशन्स लक्ष्य करू शकत होता. हे महत्त्वाचे आहे कारण अनेक डेव्हलपर्स अनेक प्रोजेक्ट्स एका सामायिक पैरेंट फोल्डरखाली ठेवतात. आता अशा सीमा ओलांडणाऱ्या कमांड्स फेल होतील.

.claude पाथवर Symlink हार्डनिंग. वर्कफ्लो डेफिनिशन्स आणि शेड्युल केलेले टास्क कॉन्फिगरेशन लिहिताना सिम्बॉलिक लिंक्स (symlinks) फॉलो करत असत. एखादा अटॅकर .claude पासून तुमच्या शेल प्रोफाइल किंवा SSH डिरेक्टरीपर्यंत सिम्बॉलिक लिंक तयार करू शकला असता, ज्यामुळे एजंट प्रोजेक्टच्या बाहेर काहीतरी लिहू शकेल. हे अपडेट त्या पाथवर सिम्बॉलिक लिंक्स फॉलो करण्यास नकार देऊन हे थांबवते.

सुरक्षित रिव्हाइंड्स (Safer rewinds). /rewind कमांड, जी तुम्हाला अलीकडील बदल मागे (roll back) नेण्यास मदत करते, ती आता सिम्बॉलिंक आणि हार्ड-लिंक केलेल्या पाथ्स वगळते. या संरक्षणाशिवाय, रिव्हाइंड ऑपरेशन सिम्बॉलिंकचा पाठलाग करून तुमच्या रिपॉझिटरीपासून दूर असलेली फाईल ओव्हरराईट करू शकते. Claude आता ते वगळलेले पाथ स्पष्टपणे रिपोर्ट करते जेणेकरून तुम्हाला समजेल की मर्यादा पाळली गेली आहे.

पुन्हा सुरू केलेले एजंट्स त्यांचे निर्बंध कायम ठेवतात. बॅकग्राउंड सेशन्स जे थांबवले जातात आणि नंतर पुन्हा सुरू केले जातात, ते पूर्वी डीफॉल्ट टूल परमिशनवर परत जात असत. जर तुम्ही एजंटला मुद्दाम फक्त वाचण्यासाठी (read) आणि लिहिण्यासाठी (write) नाही अशा प्रकारे मर्यादित केले असेल, तर रिस्टार्टमुळे पुन्हा व्यापक प्रवेश (broader access) मिळू शकत होता. आता मूळ निर्बंध सेशन्ससोबतच कायम ठेवले जातात आणि पुन्हा मिळवले जातात.

सुरक्षा प्रोफाइल निवडणे

Claude Code 2.1.216 या नियंत्रणांचे तीन प्रोफाइल्समध्ये वर्गीकरण करते. तुम्ही टूल कुठे चालवता यावर आधारित निवड करा, ते सर्वात वेगवान वाटते यावर नाही.

Default. फाईलसिस्टम आणि नेटवर्क सँडबॉक्सिंग दोन्ही सक्रिय राहतात. तुमच्या लॅपटॉप किंवा वर्कस्टेशनवर स्थानिक विकासासाठी (local development) हा योग्य पर्याय आहे. हे कंटेनर्स मॅनेज करण्याची गरज न पडता तुमची होम डिरेक्टरी, सिस्टम फाइल्स आणि शेजारील प्रोजेक्ट्सचे संरक्षण करते.

Compatibility. फाईलसिस्टम आयसोलेशन बंद केले आहे, परंतु नेटवर्क सँडबॉक्स कायम आहे. हे प्रोफाइल केवळ डिस्पोजेबल कंटेनर्स किंवा VMs साठी मर्यादित ठेवा जिथे फाईलसिस्टम आधीच तात्पुरती (ephemeral) किंवा कडक मर्यादेत आहे. एजंटला प्रोटेक्टेड फोल्डरमध्ये प्रवेश देण्यासाठी पासवर्ड टाईप करण्याच्या त्रासापासून वाचण्यासाठी याचा वापर करू नका.

Managed Hard Gate. दोन्ही सँडबॉक्स लेयर्स चालू राहतात, आणि हे प्रोफाइल तुमच्या ऑर्केस्ट्रेटर किंवा सुरक्षा टीमद्वारे लागू केलेल्या अतिरिक्त कंटेनर पॉलिसीजची अपेक्षा करते. हे CI पाइपलाइन्स, रिमोट डेव्हपमेंट एन्व्हायरनमेंट्स आणि एंटरप्राइझ सेटअपसाठी बनवले आहे जिथे 'डिफेन्स इन डेप्थ' (defense in depth) अनिवार्य आहे.

जर तुम्हाला नक्की कळत नसेल की कोणते योग्य आहे, तर Default ने सुरुवात करा. तुमचे रनटाइम एन्व्हायरनमेंट स्वतः फाईलसिस्टमला खरोखरच आयसोलेट करते याची खात्री केल्यावरच तुम्ही नंतर संरक्षण कमी करू शकता.

तुमचा वर्कफ्लो न बिघडवता अपग्रेड करणे

Do not treat this as a routine patch you install on a Friday afternoon. The upgrade path in 2.1.216 is straightforward, but the consequences of misconfiguration are not.

First, upgrade to 2.1.216 through your normal package manager or installer. Then pick one of the three isolation profiles before starting any agent tasks. Do not mix profiles across running sessions without understanding which one takes precedence.

Next, run the five non-destructive boundary tests described below. These are quick, scripted checks that prove the sandbox behaves the way the profile promises. During testing, generate sentinel hashes for files outside your disposable test repository. A sentinel hash is simply a checksum of a sensitive file or directory you want to protect. After running the tests, compare the hashes. If anything changed, your isolation is leaking.

Compare your logs as well. Claude Code writes denials and sandbox events to its local logs. Look for explicit rejections when a blocked host is reached or when a subagent steps out of its worktree. Silent failures are worse than loud ones, so verify that the logs show the guardrails kicking in.

Finally, roll the change out gradually. Start with a single project or a non-production branch. Let the new version run for a day or two before you deploy it across your entire team or CI fleet.

Five Boundary Tests That Prove Your Sandbox Works

Always run these tests inside a disposable repository stuffed with fake data. Never point them at production code, real credentials, or live infrastructure.

Network boundary. Attempt to reach two endpoints: one you have explicitly allowed and one you have blocked. A simple HTTP request against a public test service like httpbin.org can serve as the allowed target, while a request to a local metadata endpoint or an internal IP should fail. If the blocked request succeeds, your network sandbox is misconfigured.

Worktree isolation. From inside a subagent, run a Git command aimed at the parent directory. For example, try git -C .. status or have the agent describe files outside its checkout. With the fix in 2.1.216, this must fail. The subagent should see only its own worktree.

Symlink trap. Create a symlink inside your project that points to a directory outside the repository, such as /tmp/sentinel-target. Then try to save a task or workflow under the .claude path that would write through that link. After the save, check the outside directory. If it is still empty, the symlink hardening is working.

Rewind skip. Set up a folder inside your repo that contains a symlink to a system file or another directory. Run /rewind on that folder. Claude should list the skipped symlinked or hard-linked paths rather than chasing them. Confirm that the target outside the repo remains untouched.

Session resurrection. Launch a background agent with a strict restriction, such as disabling file-write tools. Pause or stop the session, then resume it. Immediately try to make the agent write a file. If the restriction is still active, the fix for resumed agents is working. If the agent suddenly has full tool access again, you are still exposed.

Final Word

Claude Code 2.1.216 gives you more flexibility than previous versions, but that flexibility comes with a clear mandate: verify before you trust. The new filesystem toggle is not there to make your life easier at the expense of safety. It is there for engineers who already built a hardened floor underneath the tool. The real improvements in this release are the silent guardrails that stop subagents from creeping into parent directories, that refuse to follow symlinks during configuration writes, and that remember the rules even after a long pause.

Run the five tests. Check your sentinel hashes. Read the logs. Then, and only then, let the new version handle real work.

Source: Claude Code v2.1.216 Release Notes

Optional learning community: GyaanSetu on Telegram