| ▲ | varl 5 hours ago | |
I've had issues with the sandbox feature, both on linux (archlinux) and two macos machines (tahoe). There is an open issue[1] on the claude-code issue tracker for it. I'm not saying it is broken for everyone, but please do verify it does work before trusting it, by instructing Claude to attempt to read from somewhere it shouldn't be allowed to. From my side, I confirmed both bubblewrap and seatbelt to work independently, but through claude-code they don't even though claude-code reports them to be active when debugging. | ||
| ▲ | OJFord 4 hours ago | parent [-] | |
Its seccomp filter also doesn't work, at all: https://github.com/anthropics/claude-code/issues/24238 | ||