2.1.216
Claude Code 2.1.216 - リリースノート
2026年7月20日
Claude Code
日本語サマリー
Claude Code 2.1.216 リリースノート要約
⚠️ セキュリティ修正
- Windowsの権限プロンプト回避を修正: 読み取り専用コマンドがネットワークパスにアクセスする際、権限プロンプトなしで実行されてしまう問題を修正。
- シンボリックリンクを介した意図しない書き込みを修正:
.claudeのシンボリックリンクを経由してプロジェクト外に書き込まれてしまう問題を修正。 - プロセスの誤終了を修正:
claude daemon stop --anyが古いロックファイルにより無関係なプロセスを終了させてしまう問題を修正。
🚀 重要な変更・機能追加
- 新設定
sandbox.filesystem.disabledを追加: ファイルシステム分離を無効化し、ネットワーク接続制御のみを維持できるようになりました。 - 長時間セッションのパフォーマンスを改善: ターン数に応じてメッセージ正規化のコストが二次関数的に増加し、数秒間の停止やレジューム遅延が発生する問題を修正しました。
/forkの確認画面を改善: 新しいセッション名やclaude attachIDなどが1行で表示されるように改善しました。- コンテキスト超過時の警告を明確化:
/contextがコンテキストウィンドウを超過した際に明確な警告を表示し、/compact失敗時にはエラーを表示するようになりました。
🐛 バグ修正(主なもの)
- OAuth/認証関連: トークン期限切れやローテーション時の
HTTP 401エラーによるautoモードのコマンド拒否を修正。MCPの再認証で有効な資格情報が先に無効化される問題などを修正。 - バックグラウンド・エージェントセッション: 復帰時のエージェント設定やプロンプトがデフォルトに戻る問題、Git worktreeの分離を迂回する問題(
git -Cなど)、不要なプロセスのキャンセルなどを修正。 - UI/ターミナル操作: アイドル状態時の
Esc-Escでのrewindピッカー表示不良、Ctrl+Xでのセッション削除失敗、フルスクリーン時のダイアログ画面はみ出し、VSCodeでの右横書き言語のレンダリング順序などを修正。 - コマンド解析・権限:
&&内のリダイレクトや否定を含む複合ステートメントの権限チェック、非ASCII文字を含むBashコマンドのパース、不可視Unicode文字を含むPowerShellコマンドの検証などを修正。
原文(Release Notes)
What's changed
- Added
sandbox.filesystem.disabledsetting to skip filesystem isolation while keeping network egress control- Fixed a slowdown in long sessions where message normalization cost grew quadratically with the number of turns, causing multi-second stalls and slow resumes
- Fixed auto mode denying commands with "HTTP 401" classifier errors after the OAuth token expired or rotated mid-session
- Fixed AskUserQuestion telling Claude to continue even when your answer asked it to wait or explain first — free-text answers now get neutral wording
- Fixed Claude Code on the web re-asking the same question and dropping your answer after the session sat idle for a few minutes
- Fixed @-mentions silently attaching nothing after file-modifying hooks, vim dot-repeat of
c-operators and paste, statusline running twice on resume, and resume-picker hangs on failure- Fixed resumed background agent sessions reverting to the default agent: the agent's prompt and tool restrictions are now restored
- Fixed worktree-isolated subagents redirecting git into the shared checkout via
git -C,--git-dir, orGIT_DIR/GIT_WORK_TREE- Fixed worktree sessions landing in another project's leftover worktree when the working directory did not match the selected project
- Fixed background sessions whose worktree has no git repository being undeletable
- Fixed
claude daemon stop --anypotentially terminating an unrelated process via a stale legacy daemon lockfile- Fixed Esc-Esc at an idle prompt not opening the rewind picker in long-running sessions with background tasks
- Fixed Bash command permission checking for compound statements with redirects inside
&&lists or negations- Fixed pressing Ctrl+X twice in the agent list failing to delete a session, and deleted sessions reappearing when their background worker had died
- Fixed background subagents getting cancelled when a high-priority message arrives during their startup window
- Fixed mouse and focus garbage in the terminal while a GUI editor from
/memory,/plan,/keybindings, or Ctrl+G is open;/memoryno longer waits for the editor to close- Fixed Claude-in-Chrome 403-looping on reconnect when the session's OAuth token lacks a required scope
- Fixed workflow saves and scheduled-task writes following a symlink at
.claude, which could redirect writes outside the project- Fixed MCP re-authenticate revoking working credentials before the new sign-in succeeds, and the reconnect needs-auth message in background sessions pointing at an unusable command
- Fixed read-only commands on Windows accessing network paths without a permission prompt
- Fixed Bash command parsing of non-ASCII characters to match real shell word boundaries
- Fixed PowerShell tool permission validation of commands containing invisible Unicode characters
- Fixed dialogs in fullscreen mode stretching past the right-hand edge of their panel
- Fixed the
/configsettings list in fullscreen mode clipping its keyboard-hint footer- Fixed the transcript-mode (Ctrl+O) footer hint wrapping on terminals narrower than 104 columns
- Fixed the Prometheus metrics endpoint (
OTEL_METRICS_EXPORTER=prometheus) emitting invalid# UNITlines- Fixed skills and commands changed during a session not appearing in the slash menu until restart
- Fixed plugin skills with a
namefrontmatter field losing their plugin prefix in slash-command autocomplete- Fixed telemetry misreporting permission denials: failed permission-prompt requests no longer count as user rejections, and user interrupts are now reported as user aborts instead of rejections
- Improved the
/forkconfirmation to one line with the new session's name,claude attachid, and a note when the copy shares your checkout- Improved validation of
gitandghcommand arguments in the PowerShell tool- Improved the
/ultrareviewdiff-too-large error to show configured limits, measured diff size, and largest contributing files- Improved
/code-review ultraempty-diff message to name the exact base ref and suggest passing an explicit base- Improved the spend limit adjustment prompt to show the server's reason when a spend limit change is rejected
/contextnow shows an explicit warning when the conversation exceeds the context window, and a failed/compactdisplays as an error/rewindno longer restores or deletes files through symlinks or hard links at tracked paths and reports how many paths it skipped- Background sessions:
/mcpand/install-github-appnow park a "needs input" request in the agent view when no client is attached- Updated the bundled dataviz skill: reordered the default chart palette and fixed guidance that suggested direct labels for four-series charts
- [VSCode] Fixed right-to-left text (Arabic, Hebrew, Persian) rendering in the wrong order when mixed with English or code
- Fixed cloud sessions dropping the in-flight message when the session's container restarts mid-turn — the interrupted turn now re-runs on resume instead of leaving the session unresponsive