anthropics / anthropics/claude-code

Cowork sandbox network allowlist not affected by sandbox.enabled toggle in settings

Abierto
#92,273 1 comentario 0 reacciones 0 asignados Ver en GitHub
area:cowork area:sandbox bug has repro platform:macos
Lenguaje dominante
Python
Estrellas
145k
Forks
23.1k
Métricas de merge de PR
Métricas de PR pendientes

Descripción

### Preflight Checklist

- [x] I have searched [existing issues](https://github.com/anthropics/claude-code/issues?q=is%3Aissue%20state%3Aopen%20label%3Abug) and this hasn't been reported yet
- [x] This is a single bug report (please file separate reports for different bugs)
- [x] I am using the latest version of Claude Code

### What's Wrong?

After toggling `sandbox.enabled` in `~/.claude/settings.json`, the Cowork ("dispatch") Linux sandbox stayed network-restricted regardless of the setting. Turning sandbox mode off did not lift the restriction.

**Environment**
- macOS (Darwin 24.6.0), Claude Code + Cowork mode
- `~/.claude/settings.json` -> `sandbox.enabled: false`, with a populated `sandbox.network.allowedDomains` (incl. `*.cloudflare.com`, `hazards.fema.gov`)
- No `/Library/Application Support/ClaudeCode/managed-settings.json` present

**Steps to reproduce**
1. Set `sandbox.enabled: true` and add domains (e.g. `*.cloudflare.com`, `hazards.fema.gov`) to `sandbox.network.allowedDomains`.
2. In a Cowork session, run a curl loop against those domains from the sandbox shell.
3. Set `sandbox.enabled: false`.
4. Re-run the loop.

Test loop used:
```
for u in https://api.cloudflare.com/client/v4 https://cloudflare.com https://www.google.com https://hazards.fema.gov https://registry.npmjs.org; do
c=$(curl -sS -o /dev/null -w "%{http_code}" --max-time 15 "$u" 2>/dev/null); echo "$c $u"
done
```

**Actual**
In both states, only the platform's built-in allowlist applies. Unlisted domains return curl exit 56 (HTTP 403 from proxy, header `X-Proxy-Error: blocked-by-allowlist`); listed domains like `registry.npmjs.org` return 200. Result from inside the Cowork sandbox:
```
000 https://api.cloudflare.com/client/v4
000 https://cloudflare.com
000 https://www.google.com
000 https://hazards.fema.gov
200 https://registry.npmjs.org
```
The same loop on the host Mac (CLI, sandbox off) returns normal codes for all five.

**Root cause (observed)**
The Cowork sandbox enforces egress via an external proxy (`localhost:3128`) reading a platform policy at `/etc/srt-settings.base.json` (plus per-request `/etc/srt-settings/oneshot-*.json`). This policy is independent of `~/.claude/settings.json`, so user `sandbox` settings have no effect on the Cowork sandbox, and there is no user-facing way to change it. The in-sandbox policy file is root-owned and unwritable; `sudo` is disabled (no-new-privileges).

### What Should Happen?

Either honor the user's `sandbox` settings (`sandbox.enabled`, `sandbox.network.allowedDomains`) in Cowork sessions, or clearly document that Cowork's sandbox allowlist is platform-fixed and separate from the CLI's `sandbox` config — so the settings do not appear to be silently ignored.

### Error Messages/Logs

```shell
curl: (56) Received HTTP code 403 from proxy after CONNECT
< HTTP/1.1 403 Forbidden
< X-Proxy-Error: blocked-by-allowlist

Inside Cowork sandbox:
000 https://api.cloudflare.com/client/v4
000 https://cloudflare.com
000 https://www.google.com
000 https://hazards.fema.gov
200 https://registry.npmjs.org
```

### Steps to Reproduce

1. In `~/.claude/settings.json`, set `sandbox.enabled: true` and add domains to `sandbox.network.allowedDomains` (e.g. `*.cloudflare.com`, `hazards.fema.gov`).
2. Open a Cowork session and run this loop from the sandbox shell:
```
for u in https://api.cloudflare.com/client/v4 https://cloudflare.com https://www.google.com https://hazards.fema.gov https://registry.npmjs.org; do
c=$(curl -sS -o /dev/null -w "%{http_code}" --max-time 15 "$u" 2>/dev/null); echo "$c $u"
done
```
3. Observe that the domains you allow-listed still return 000 (blocked), while only the platform defaults (e.g. registry.npmjs.org) return 200.
4. Set `sandbox.enabled: false` and re-run the same loop.
5. Observe the result is unchanged — the Cowork sandbox is still restricted, and the same loop run on the host Mac (CLI, sandbox off) returns normal codes for all five domains.

### Claude Model

None

### Is this a regression?

Yes, this worked in a previous version

### Last Working Version

_No response_

### Claude Code Version

2.1.260 (Claude Code)

### Platform

Anthropic API

### Operating System

macOS

### Terminal/Shell

Terminal.app (macOS)

### Additional Information

_No response_

Guía de contribución

No hay ninguna guía de contribución indexada para este repositorio

Línea de trabajo

Start by tracing how ~/.claude/settings.json is read for sandbox.enabled and sandbox.network.allowedDomains, then compare that path with Cowork's /etc/srt-settings.base.json and /etc/srt-settings/oneshot-*.json policy. Confirm whether the intended fix is integration or documentation, and validate the chosen behavior with the curl loop in the report in both enabled and disabled states.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
python
Área
cli, networking, security
Tipo de issue
Error
Dificultad
5/5
Tiempo estimado
Más de una semana
Estado de actividad
Activo
Claridad
Necesita aclaración
Aptitud para principiantes
35/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.