A sandbox is only useful if it actually keeps the agent inside the fence. Claude Code 2.1.216 tightens several gaps that could let a background task, subagent, or resumed session wander outside its assigned directory. This release introduces a new configuration switch, but the more important work is under the hood: smarter handling of Git worktrees, symlinks, and agent restarts. If you run Claude Code locally or in CI, these changes deserve more than a quick skim of the changelog.

The Filesystem Toggle You Should Not Touch Lightly

Version 2.1.216 adds sandbox.filesystem.disabled. When this is set, Claude Code skips its own filesystem isolation while still enforcing the network sandbox. At first glance this sounds like a way to stop permission errors or speed up file operations. It is not. You should only enable this setting if another layer is already protecting your disk.

That means a disposable container that gets deleted after every run, or a dedicated virtual machine with no access to your home directory or production volumes. If you run Claude Code directly on macOS, Windows, or a bare Linux host, leave filesystem isolation on. The network sandbox is not a substitute for filesystem controls, and the minor friction of sandboxed file access is far cheaper than recovering from an accidental overwrite or a malicious prompt injection that breaks out of the project folder.

Think of the toggle as a compatibility shim, not a performance knob. It exists for environments where the operating system or orchestrator already handles isolation, and Claude’s own sandbox adds unnecessary complexity.

What the Update Actually Fixes

Beyond the new setting, 2.1.216 closes several practical holes that could let an agent reach places it should not.

Worktree isolation. Subagents can no longer redirect Git commands into a parent or sibling directory outside their own worktree. Previously, a subagent running inside your project could aim Git operations at your shared checkout or adjacent repositories. That matters because many developers keep multiple projects under a common parent folder. Now those boundary-crossing commands fail.

Symlink hardening at the .claude path. Workflow definitions and scheduled tasks used to follow symlinks when writing configuration. An attacker who could create a symlink from .claude to, say, your shell profile or SSH directory could potentially get the agent to write outside the project. The update stops this by refusing to follow symlinks at that path.

Safer rewinds. The /rewind command, which lets you roll back recent changes, now skips symlinked and hard-linked paths. Without this guard, a rewind operation could chase a symlink and overwrite a file far away from your repository. Claude now reports those skipped paths explicitly so you know the boundary held.

Resumed agents keep their restrictions. Background sessions that get stopped and later resumed used to fall back to default tool permissions. If you had intentionally restricted an agent so it could read but not write, a restart could silently restore broader access. Now the original restrictions are persisted and restored with the session.

Picking a Security Profile

Claude Code 2.1.216 organizes these controls into three profiles. Choose based on where you run the tool, not based on what feels fastest.

Default. Filesystem and network sandboxing both stay active. This is the right choice for local development on your laptop or workstation. It protects your home directory, system files, and neighboring projects without requiring you to manage containers.

Compatibility. Filesystem isolation is turned off, but the network sandbox remains. Restrict this profile to disposable containers or VMs where the filesystem is already ephemeral or strictly scoped. Do not use it because you are tired of typing passwords to let the agent access a protected folder.

Managed Hard Gate. Both sandbox layers stay on, and the profile expects additional container policies enforced by your orchestrator or security team. This is built for CI pipelines, remote dev environments, and enterprise setups where defense in depth is mandatory.

If you are unsure which one fits, start with Default. You can downgrade the protection later only after you have verified that your runtime environment genuinely isolates the filesystem by itself.

Upgrading Without Breaking Your Workflow

Đừng coi đây là một bản vá định kỳ mà bạn cài đặt vào một chiều thứ Sáu. Lộ trình nâng cấp lên 2.1.216 rất đơn giản, nhưng hậu quả của việc cấu hình sai thì không.

Đầu tiên, hãy nâng cấp lên 2.1.216 thông qua trình quản lý gói hoặc trình cài đặt thông thường của bạn. Sau đó, hãy chọn một trong ba cấu hình cô lập (isolation profiles) trước khi bắt đầu bất kỳ tác vụ agent nào. Đừng trộn lẫn các cấu hình giữa các phiên đang chạy mà không hiểu rõ cấu hình nào sẽ được ưu tiên.

Tiếp theo, hãy chạy năm bài kiểm tra ranh giới không gây hại được mô tả dưới đây. Đây là các bước kiểm tra nhanh bằng script nhằm chứng minh sandbox hoạt động đúng như cấu hình đã cam kết. Trong quá trình kiểm tra, hãy tạo các mã băm sentinel (sentinel hashes) cho các tệp nằm ngoài kho lưu trữ thử nghiệm tạm thời của bạn. Một mã băm sentinel đơn giản là mã checksum của một tệp hoặc thư mục nhạy cảm mà bạn muốn bảo vệ. Sau khi chạy các bài kiểm tra, hãy so sánh các mã băm. Nếu có bất kỳ thay đổi nào, sự cô lập của bạn đang bị rò rỉ.

Hãy so sánh cả nhật ký (logs) của bạn nữa. Claude Code ghi lại các lệnh từ chối và các sự kiện sandbox vào nhật ký cục bộ. Hãy tìm kiếm các thông báo từ chối rõ ràng khi một host bị chặn bị truy cập hoặc khi một subagent bước ra khỏi worktree của nó. Các lỗi im lặng (silent failures) còn tệ hơn các lỗi hiển thị rõ ràng, vì vậy hãy xác minh rằng nhật ký cho thấy các rào chắn bảo vệ (guardrails) đang hoạt động.

Cuối cùng, hãy triển khai thay đổi một cách dần dần. Bắt đầu với một dự án duy nhất hoặc một nhánh không phải môi trường production. Hãy để phiên bản mới chạy trong một hoặc hai ngày trước khi bạn triển khai cho toàn bộ đội ngũ hoặc hệ thống CI của mình.

Năm bài kiểm tra ranh giới chứng minh sandbox của bạn hoạt động hiệu quả

Luôn chạy các bài kiểm tra này bên trong một kho lưu trữ tạm thời chứa đầy dữ liệu giả. Đừng bao giờ trỏ chúng vào mã nguồn production, thông tin xác thực thật hoặc cơ sở hạ tầng đang hoạt động.

Ranh giới mạng (Network boundary). Thử truy cập vào hai điểm cuối (endpoints): một điểm bạn đã cho phép rõ ràng và một điểm bạn đã chặn. Một yêu cầu HTTP đơn giản đến một dịch vụ thử nghiệm công khai như httpbin.org có thể đóng vai trò là mục tiêu được cho phép, trong khi một yêu cầu đến một endpoint metadata cục bộ hoặc một IP nội bộ sẽ phải thất bại. Nếu yêu cầu bị chặn thành công, sandbox mạng của bạn đã bị cấu hình sai.

Cô lập worktree (Worktree isolation). Từ bên trong một subagent, hãy chạy một lệnh Git hướng tới thư mục cha. Ví dụ, hãy thử git -C .. status hoặc yêu cầu agent mô tả các tệp nằm ngoài thư mục checkout của nó. Với bản sửa lỗi trong 2.1.216, việc này phải thất bại. Subagent chỉ được phép nhìn thấy worktree của chính nó.

Bẫy symlink (Symlink trap). Tạo một symlink bên trong dự án của bạn trỏ đến một thư mục nằm ngoài kho lưu trữ, chẳng hạn như /tmp/sentinel-target. Sau đó, hãy thử lưu một tác vụ hoặc quy trình công việc (workflow) dưới đường dẫn .claude mà sẽ ghi thông qua liên kết đó. Sau khi lưu, hãy kiểm tra thư mục bên ngoài. Nếu nó vẫn trống, việc tăng cường bảo mật symlink (symlink hardening) đang hoạt động tốt.

Bỏ qua khi rewind (Rewind skip). Thiết lập một thư mục bên trong repo của bạn có chứa một symlink đến một tệp hệ thống hoặc một thư mục khác. Chạy /rewind trên thư mục đó. Claude sẽ liệt kê các đường dẫn symlink hoặc hard-link bị bỏ qua thay vì truy vết chúng. Xác nhận rằng mục tiêu bên ngoài repo vẫn không bị chạm tới.

Khôi phục phiên làm việc (Session resurrection). Khởi chạy một agent chạy ngầm với một hạn chế nghiêm ngặt, chẳng hạn như vô hiệu hóa các công cụ ghi tệp. Tạm dừng hoặc dừng phiên làm việc, sau đó khôi phục lại. Ngay lập tức thử yêu cầu agent ghi một tệp. Nếu hạn chế vẫn còn hiệu lực, bản sửa lỗi cho các agent được khôi phục đang hoạt động. Nếu agent đột nhiên có lại toàn quyền truy cập công cụ, bạn vẫn đang gặp rủi ro.

Lời kết

Claude Code 2.1.216 mang lại cho bạn nhiều sự linh hoạt hơn các phiên bản trước, nhưng sự linh hoạt đó đi kèm với một yêu cầu rõ ràng: hãy xác minh trước khi tin tưởng. Nút chuyển đổi hệ thống tệp (filesystem toggle) mới không phải để giúp công việc của bạn dễ dàng hơn bằng cách đánh đổi sự an toàn. Nó dành cho những kỹ sư đã xây dựng một nền tảng bảo mật vững chắc bên dưới công cụ. Những cải tiến thực sự trong bản phát hành này là các rào chắn bảo vệ thầm lặng giúp ngăn chặn các subagent xâm nhập vào các thư mục cha, từ chối đi theo các symlink trong quá trình ghi cấu hình, và ghi nhớ các quy tắc ngay cả sau một khoảng thời gian tạm dừng dài.

Chạy năm bài kiểm tra. Kiểm tra các mã băm sentinel của bạn. Đọc nhật ký. Sau đó, và chỉ sau đó, hãy để phiên bản mới xử lý công việc thực tế.

Nguồn: Claude Code v2.1.216 Release Notes

Cộng đồng học tập tùy chọn: GyaanSetu on Telegram