AIToday
AI Coding AssistantsAI Safety & AlignmentZenn AI/MLPublished: Oct 11, 2026, 22:00 JST

Claude Code 2.1.296: relative deny rules fail, absolute paths hold

Claude Code 2.1.296: relative deny rules fail, absolute paths hold

Tested on Windows 10 with Claude Code 2.1.296, a deny rule written as Edit(../shared/partner/**) did not stop any write attempts, and startup gave no warning. The same folder protected by an absolute path (//c/...) blocked the Write tool, Edit tool and Bash echo >.

Not sure about something? Ask the AI

Questions and answers are published on this page.

Summaries like this, in your inbox every morning.

Context & Analysis

The test grew out of a practical setup: the author runs Claude Code in two working folders and wanted to keep one from modifying the other, so he wrote Edit(../shared/partner/**) into company/.claude/settings.json and assumed it was protected. He only noticed the rule was not holding when he was trying something else and saw the file change anyway. Against the official Configure permissions document, which lists //path, ~/path, /path and path or ./path as the supported forms, the ../ style simply is not among them, and in his run it failed without warning. Writing the rule as a Write(...) rule instead produced a startup warning telling him that Write(path) is not used for file permission checks and that Edit(path) should be used. Across his runs, the absolute-path rule did block the Write tool, Edit tool and Bash echo >, but not a node script run through an auto-allowed Bash. In a separate check, denying .env with Read(./.env) stopped the Read tool and cat .env, yet a node -e script could still read it under auto-allowed Bash. The author notes Claude Code's documentation already states that Read and Edit deny rules do not cover files opened by Python or Node scripts, and that sandboxing is the way to enforce this at the OS level. He suggests running Claude Code under a separate Windows user without file permissions, or in a virtual machine or container, and keeping production keys off the same machine.

FAQ
Why did the relative-path deny rule fail?
The author says the ../ form is not among the four path styles listed in the official Configure permissions document, and the failure produced no warning either. He adds that he cannot tell whether this is a Claude Code bug.
Did the absolute-path rule block everything?
No. It stopped the Write tool, Edit tool and Bash echo >, but when Bash was auto-allowed, a node script still wrote to the folder. The author says deny behaves like a brake, not a wall.
How can I check my own settings safely?
The author provides a Git Bash script called try-deny.sh that creates a fresh test folder under the home directory each run and only touches dummy files. He warns against testing on real files.

AI news that matters for your work, delivered every morning.

Pick your industry and the AI tools you use, and get news related to your work every day.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.

Questions and answers are published on this page.

Related Articles

Next articleGoogle's Playground builds games in minutes, Wired finds slop