2.1.268
Claude Code 2.1.268 - リリースノート
2026年9月10日
Claude Code
日本語サマリー
Claude Code 2.1.268 リリースノート要約
⚠️ 重要な修正・破壊的変更
- セキュリティ修正:
deny/ask権限ルールがシンボリックリンクされたディレクトリ(macOSの/etc,/tmp,/var、Linuxの/bin)で、実パス指定時に適用されない問題を修正。またenv -Cやevalなど解析不能なコマンドと同一行にある Read/Edit の deny ルールが無視される問題も修正 - セキュリティ修正: git ソースURLのトークン・パスワード、MCP設定の
${VAR}プレースホルダで解決されたシークレットがエラー表示に露出する問題を修正 - 重大な不具合修正: 2.1.265 以降、
ANTHROPIC_BASE_URLのサードパーティ互換エンドポイントで毎ターン HTTP 400 エラーになる問題(Artifact tool の入力スキーマの regex が原因)を修正 - 動作変更:
WebFetchの deny/ask ルールが Artifact tool の読み書きに適用されなくなった。ブロックするにはArtifactルール(またはWebFetch(domain:claude.ai))を使用 - 動作変更: タスク管理ツール(TaskCreate/Get/Update/List, TodoWrite)は Claude 3.x、Opus 4.0–4.7、Sonnet 4.0–4.6、Haiku 4.5 のみに提供。それ以外は
CLAUDE_CODE_ENABLE_TODO_TOOLS=1を設定
主な新機能
- Gateway:
gateway.yamlのpricing:設定に対応し、/costとテレメトリーが使用量メーターと一致。gatewayInternalNetworks管理設定を追加 - self-hosted-runner:
--remove-session-stateオプションでセッション終了時に<base-dir>/_sessions/を削除 - CLI:
claude plugin install/uninstall/update/enable/disableに--jsonを追加、claude auth status --jsonにconfigDirectoryを追加 - WebFetch: 無応答サーバーで無限ハングする問題を修正。300秒でタイムアウト(
CLAUDE_CODE_WEBFETCH_DEADLINE_MSで変更可能)
主な修正・改善
- CPU: アイドルセッションのビジーループによるCPUコア占有、session recap中の高CPU使用を修正
--continue/--resume: SessionStart hooks を待たず会話を即時表示し、初回メッセージがトランスクリプト全体を再読込しないよう改善- SDK:
excludeDynamicSections使用時に prompt caching と extended thinking がセッション途中で壊れる問題を修正 - MCP: OAuthサインインの「No available ports for OAuth redirect」エラーを修正
- フルスクリーンモード: Shift+Enter によるプロンプト行の追加・削除が高速に再描画されるよう改善
/plugin: プラグインのインストール・有効化・無効化がメニューを閉じるだけで反映(/reload-plugins不要に)- VSCode:
CLAUDE_CONFIG_DIR設定時の各種不具合、Windows/WSL 関連の問題を修正。アクセシビリティ向けに矢印キー操作や「Focus last message」コマンドを追加
原文(Release Notes)
What's changed
- Added to the Claude apps gateway: with
pricing:set ingateway.yaml, signed-in Claude Code clients receive the same rates through managed settings, so/costand telemetry match the spend meter- Added a startup warning for gateways when
access_control.allow_cidrsis empty, and a one-time warning the first time a request arrives from a public address- Added the
gatewayInternalNetworksmanaged setting, letting administrators allow/loginto a Claude apps gateway on their organization's own public IPv4 block- Added
claude self-hosted-runner --remove-session-state(default off): delete each session's per-session directories under<base-dir>/_sessions/when the session ends- Added
configDirectoryto the output ofclaude auth status --json- Added
--jsontoclaude plugin install,uninstall,update,enableanddisable, anderrorDetails/noteDetailsto each row ofclaude plugin list --json- Added browser-tab icons for published artifacts, chosen by Claude to match each page
- Fixed every turn failing with HTTP 400 on third-party Anthropic-compatible endpoints (
ANTHROPIC_BASE_URL) since 2.1.265: a regex in the Artifact tool's input schema that those endpoints reject- Fixed WebFetch hanging indefinitely on a server that keeps the response open without finishing; a fetch now fails after 300 seconds. Set
CLAUDE_CODE_WEBFETCH_DEADLINE_MSto override the deadline (0 turns it off)- Fixed a respawned in-process teammate picking up tools or a system prompt from a same-named agent file in a folder you have not trusted
- Fixed sustained high CPU usage: a busy loop in long-running idle sessions no longer pins a CPU core, and rapid terminal focus reports during a session recap no longer keep the CPU high
- Fixed Claude sometimes replying "your message came through empty" after an MCP tool call
- Fixed deny and ask permission rules on symlinked directories (
/etc,/tmp,/varon macOS;/binon Linux) not applying when a path was given by its real location, and Bash commands ignoring deny rules written on a symlinked path spelling- Fixed a case where a Read or Edit deny rule did not apply when an
env -C,evalor similar command the permission checker cannot analyze was on the same line- Fixed plugin and marketplace errors showing a token or password from a git source URL
- Fixed
/mcpand/pluginserver details,claude mcp list/get, and MCP login errors showing secrets resolved from${VAR}placeholders in MCP configs- Fixed prompt caching and extended thinking breaking mid-session for SDK sessions using
excludeDynamicSections: the first message is no longer re-rendered each request- Fixed entitled users being told a model is restricted after restart or in the Desktop Code tab when a cached model-access denial was stale
- Fixed a running session silently switching to the organization's default model when another Claude Code process refreshed a stale model-access entry
- Fixed long-context 429s on Fable models showing the usage-credits consent prompt instead of the 1M-context message on Pro and Team plans
- Fixed workload identity federation via a profile (as claude-code-action configures it): processes sharing the profile could fail mid-run with
401 … jti reused- Fixed MCP server OAuth sign-in failing with "No available ports for OAuth redirect" when the local callback port range can't be bound
- Fixed the conversation summary produced by
/compactand auto-compact mangling text that contained$sequences- Fixed resuming a conversation that ended with
/compact: its restored-file notes now load in the same order on every resume- Fixed SDK prompt suggestions, side questions and
/renamesending the conversation from before a compaction- Fixed
@file and/command suggestions not appearing after recalling a previous prompt with the up arrow and editing it- Fixed
claude agents: pressing ← again at a natural pace to go back to the agent list no longer gets ignored until you pause for over a second- Fixed
claude agentssession delete getting stuck when a worktree can't be removed: the message names the cause and next step, and for a git worktree ctrl+x again deletes the directory anyway- Fixed background agent and workflow rows in the agents panel expanding to many lines when their text contained line breaks
- Fixed Claude in Slack sessions losing their Slack tools when org managed settings set an MCP allowlist
- Fixed Claude in Chrome asking to allow the host "https" when a navigation URL had a scheme but a host that could not be parsed
- Fixed the spinner wrapping onto several lines when the current task's label is long; the label and the "Next:" task line now stay within one terminal row
- Fixed the
/bugand/feedbackdescription field showing no cursor when the terminal's native cursor is enabled- Fixed Remote Control sessions served by
claude remote-controlshowing a generated name instead of their session title inListAgents- Fixed
claude plugin validaterejecting plugin paths whose directory name begins with two dots, which the plugin loader accepts- Fixed plugins silently skipping a default monitors file or root SKILL.md that could not be checked
- Fixed WebFetch's error for localhost and other dotless hostnames to explain why the URL is refused and suggest curl
- Fixed PermissionRequest hooks not firing in
- Fixed policy-helper warnings not printing on headless (
-p) runs- Fixed
/resumelisting a/forkbackground session under its parent's name instead of its own⑂fork name- Fixed
/remote-controland other claude.ai-gated commands to suggest/loginwhen signed out instead of showing a Claude for Enterprise migration message- Fixed
CLAUDE_CODE_SESSIONEND_HOOKS_TIMEOUT_MSnot extending SessionEnd hooks that have no per-hooktimeout(they were still cancelled after 1.5 seconds)- Fixed
/autofix-prand other cloud-session commands saying to retry or install the Claude GitHub App when no GitHub account is connected; they now point to/web-setupor the web connect page- Fixed cloud-session commands such as
/teleportand/remote-envto explain when an organization policy turns them off, instead of answering "Unknown command"- Fixed Bash sandbox instructions over-stating confinement: no unenforced path lists when filesystem isolation is off, and strict mode no longer claims commands can never run unsandboxed
- Improved fullscreen mode: adding or removing a prompt line (Shift+Enter) now repaints as fast as typing a character instead of re-rendering the visible transcript
- Improved
--continue/--resume: the conversation appears immediately instead of waiting for SessionStart hooks, and the first message no longer re-reads the whole transcript- Improved responsiveness during tool-heavy turns by no longer redrawing the transcript for a hidden per-tool-batch reminder
- Improved startup time in projects with
.claude/workflows/scripts: listing them no longer parses each script- Improved auto mode denials: the message Claude receives now names the rule that blocked the action and asks Claude to try a safer method and finish unrelated work before stopping to ask you
- Improved Claude in Chrome: long page reads now stay inline instead of being saved to a file and read back
- Improved the MEMORY.md truncation warning to say how many lines were cut and where the cut starts
- Improved the terminal permission prompt for artifacts: it now leads with the ask's question
- Improved the prompt footer: an editor or
/diffselection now shows inside the prompt input, and fullscreen mode shows Remote Control status in the header instead of the footer- Improved the "Usage credits required for 1M context" message to say that usage credits turned on mid-session take effect after restarting Claude Code
- Improved
/plugin: installing, enabling or disabling a plugin now takes effect when you close the menu;/reload-pluginsis no longer needed afterwards- Changed the system prompt on Bedrock, Vertex and Foundry to deliver environment, model and settings details as attachments, matching first-party sessions
- Changed Bedrock, Vertex and Foundry sessions to keep the tool list byte-stable across a conversation (late-connecting tools load deferred instead of rewriting it), matching first-party sessions
- Changed the task-tracking tools (TaskCreate/Get/Update/List, TodoWrite) to be offered only on Claude 3.x, Opus 4.0–4.7, Sonnet 4.0–4.6, Haiku 4.5; set
CLAUDE_CODE_ENABLE_TODO_TOOLS=1elsewhere- Changed the artifact data-edit permission prompt in the terminal to a card that shows the document count and who can open the artifact
- Changed local Cowork sessions set to skip all approvals: the Artifact tool now refuses a local file outside the session's folders, or behind a symlink, instead of reading it without asking
- Changed plain
WebFetchdeny and ask rules to no longer apply to Artifact tool reads and updates; use anArtifactrule (orWebFetch(domain:claude.ai)) to block or gate them- Changed the "N MCP servers need authentication" startup notice to announce each server once instead of at every launch
- [VSCode] Fixed the session list, settings toggles, and chat tabs when
CLAUDE_CONFIG_DIRis set in a settings file or theenvironmentVariablessetting- [VSCode] Fixed the model pill, model picker and command menu going blank in open tabs for a few seconds after a login, logout or account switch
- [VSCode] Fixed Auto disappearing from the mode picker in new-tab or just-reloaded conversations when a project or local setting overrides the model named in
~/.claude/settings.json- [VSCode] Fixed session names reverting to the last prompt after a window reload when a SessionStart hook is configured
- [VSCode] Fixed the footer's model pill and Remote Control pill waiting for the new tab's Claude process to start when another tab in the window is already up
- [VSCode] Fixed a second Claude process running through its full startup when a session tab's launch arrived more than half a second after its config read
- [VSCode] Fixed resuming a session from the session list ignoring
claudeCode.preferredLocation: "sidebar"(it always opened a panel), and programmatic opens resetting that setting to "panel"- [VSCode] Fixed Windows issues: the WSL install prompt no longer appears on machines without WSL installed, and IDE diagnostics are now returned correctly for Windows files when WSL is installed
- [VSCode] Fixed the custom style builder saving a User level style in a folder the CLI does not read when
CLAUDE_CONFIG_DIRis set through settings- [VSCode] Added Left and Right arrow keys to change where an always-allow permission rule is saved, for keyboard and screen reader users
- [VSCode] Added a "Claude Code: Focus last message" command that moves keyboard focus to the newest message in the conversation, for keyboard and screen reader users
- [VSCode] Changed the Manage plugins dialog to apply installs, enables, disables and uninstalls to open sessions without a restart
- [VSCode] Changed some artifact permission prompts to omit the "don't ask again" choice, matching the terminal
- [Claude Code on the web] Fixed cloud sessions running longer than about six hours silently losing files saved to persisted session folders; saves now persist for up to a day
- [Claude Code on the web] Fixed "Invalid effort level" errors when a routine resumes a session, or a session starts with no set effort, in orgs where an admin caps a model's effort
- [Claude Code on the web] Improved routine creation from a conversation: when the new routine has no connectors, Claude now says so and how to add them instead of only confirming it
- [Claude Tag] Fixed the admin settings page hanging on a loading skeleton or going blank after a transient load failure; a section that fails to load now shows a Retry button
- [Claude Tag] Added a link from a Slack channel's configure page back to the organization's Claude in Slack admin settings
- [Claude Tag] Fixed a Slack Enterprise Grid channel losing its Claude settings (repository, environment, access) after a Slack admin moved it to another workspace
- [Claude Tag] Improved how Claude explains a blocked action: it now says whether a permission check, its own decision to confirm first, or missing access stopped it
- [Claude Tag] Improved reply speed: Claude now runs several read-only lookups (searching Slack, reading a thread, finding people) at once instead of one after another
- [Claude Tag] Improved formatting of comparisons: sentence-length comparisons now come as lists instead of wide tables that scroll sideways, and long table cells wrap
- [Claude Tag] Fixed
@Claude !restartin a thread with its own session sometimes also posting a contradictory "this thread is handled by the channel session" notice- [Claude Tag] Improved the message shown when your Claude account is in a different organization than the Slack workspace: it now explains how to connect the workspace to your org
- [Claude Tag] Fixed Markdown links whose URL is wrapped in angle brackets showing as literal bracket text in Slack instead of a clickable link
- [Claude Tag] Fixed a workspace guest's top-level @mention in a channel where guests may use Claude sometimes getting a "your Slack account isn't connected" reply instead of an answer
- [Claude Tag] Fixed a channel's long-running session being replaced with a fresh one mid-conversation; the scheduled refresh now waits until the channel and its threads are quiet
- [Claude Tag] Fixed channel-settings cards clicked more than once telling the proposing session the change was refused after it had already applied; the outcome is now sent once
- [Claude Tag] Changed memory in public channels: each channel now keeps its own notes, and Claude no longer recalls notes it saved in other public channels; workspace notes stay shared
- [Code Review] Added a note under the still-open findings list in follow-up reviews: resolving a finding's thread, not just replying to it, stops later reviews from counting it as open
- [Code Review] Fixed reviews sometimes ending as incomplete when one of the agents verifying a finding failed midway; the review now replaces that agent and reaches a verdict
- [Code Review] Fixed a push-triggered review that was queued behind a running review still posting after the pull request had been converted to draft
- [Code Review] Fixed reviews ignoring a directory's CLAUDE.md conventions when the PR edited a root file (e.g. README.md) that only shares a name with a file that CLAUDE.md lists