Claude Code v2.1.288:修复MCP重复调用、Bash越权及会话恢复等严重问题
v2.1.288
推荐理由
涉及 MCP 重复调用与 Bash 权限绕过等高危问题,直接影响自动化工作流稳定性与安全,建议立即升级以规避风险。
What's changed
变更内容
- Added $.ui.selection() for mods: returns the text you last selected in fullscreen mode and, when the selection lies within one transcript row, that row
- Added a built-in gh api to cloud sessions whose image has no GitHub CLI, and fixed the built-in sending control characters from file names, jq filters or GitHub errors to the terminal
- Added recovery for a prompt cleared with Ctrl+C: pressing Up on the empty prompt brings the draft back, including pasted text and images
- Added a re-authenticate prompt when an MCP server asks for more OAuth scope during a tool call
- Added --max-findings <n>|all to /code-review to report more or fewer findings than the usual limit; the choice is reused until you pass --max-findings default
- Added Ctrl+F to find a session by name and Alt+↑/↓ to jump between groups in the agents view; both, and rename, can be rebound in keybindings.json
- Added a screen reader mode announcement of the new permission mode when you approve a plan, including with Shift+Tab
- Fixed mid-response API timeouts failing the turn: non-interactive sessions and subagents now continue from the partial response, and thinking-only responses are retried
- Fixed long conversations failing with "Prompt is too long" instead of auto-compacting when the last reply reported zero token usage
- Fixed --resume sometimes dropping files and other context that a compaction had just restored
- Fixed a resumed session sometimes not saving the last response of a turn, so that the next --resume showed the prompt unanswered
- Fixed resume occasionally loading a transcript cut short when the same session rewrote the file during the load
- Fixed resuming a conversation started on 2.1.286 or earlier dropping the model's earlier thinking
- Fixed session titles, memory recall and prompt hooks failing on Mantle or behind gateways that reject structured outputs; added CLAUDE_CODE_DISABLE_STRUCTURED_OUTPUTS to turn structured outputs off
- Fixed auto mode denials pointing Claude at a Bash permission rule when the blocked tool was not Bash
- Fixed auto mode on Bedrock and Mantle switching to the local classifier for the rest of the session after a request to an older model, such as a WebFetch summary or a sonnet subagent
- Fixed cloud sessions that restarted on a newly picked model replying with that model after the server refused it
- Fixed Cowork cloud sessions staying marked as waiting for input after a WebFetch permission prompt for an unapproved URL went unanswered for five minutes
- Fixed prompt suggestions not appearing on a phone that joins a Cowork cloud session started on another device
- Fixed a mod's button sometimes running a different button's action when pressed on a view drawn before Claude Code restarted
- Fixed a plugin's pane showing nothing when one Code element held a diff that does not parse; it now draws as plain code
- Fixed plugin LSP servers receiving literal ${user_config.*} and ${CLAUDE_PLUGIN_ROOT} placeholders in initializationOptions and settings instead of substituted values or manifest defaults
- Fixed a plugin's tool.call hook making Bash fail and file searches read the wrong folder in subagents that run in a worktree
- Fixed git-subdir plugin installs failing, or caching an incomplete plugin, on older git (before 2.39, e.g. Ubuntu 22.04's 2.34)
- Fixed plugins loaded with --plugin-dir not showing "Configure options" in /plugin
- Fixed background sessions ending when a plugin was reloaded or disabled while one of its timers or reads was still running
- Fixed sandboxed heredocs with an unquoted delimiter (python3 <<EOF) asking for approval on every run under sandbox auto-allow when the body holds only plain text and simple $VAR references
- Fixed Bash tool permission check to prompt before a BASHPID assignment whose value the shell would evaluate as arithmetic, instead of allowing it silently
- Fixed fullscreen sessions exiting with "unrecoverable interface error" when opening the background tasks dialog while a plugin or mod showed rows above the prompt
- Fixed Claude reporting a message to another session as delivered when that session held it: the notice now says it wasn't delivered and names the session, and in SDK sessions Claude can now learn of it mid-turn
- Fixed OpenTelemetry claude_code.tool.blocked_on_user spans reporting unknown source or decision in -p and SDK sessions and for PreToolUse hook approvals
- Fixed permission asks that ended unanswered, in -p or on an interrupted turn, emitting no tool_decision event
- Fixed Edit and Retry in Cowork cloud sessions refusing a message sent before /compact even though its history was still saved
- Fixed unattended sessions (CLAUDE_CODE_RETRY_WATCHDOG) retrying for hours after a very long response stream failed; Claude Code now streams again, and gives up after three timeouts
- Fixed /login reporting "Login successful" when credentials could not be saved to secure storage; it now shows the failure, and offers a retry when the new login didn't take effect (#73861)
- Fixed a Stop during Bedrock credential lookup sometimes moving the session to a fallback model instead of ending the request
- Fixed a second gcpAuthRefresh/awsAuthRefresh browser sign-in opening when a laptop wakes from sleep while another Claude Code process is signing in
- Fixed agent teams: a plugin-defined agent spawned by name now runs with its own prompt, tools, disallowedTools and effort instead of the defaults
- Fixed headless (-p / SDK) sessions occasionally ignoring SIGTERM when a supervisor such as timeout or systemd sends SIGCONT alongside it
- Fixed restarted cloud sessions restoring a model that the organization's enforced model list refuses
- Fixed MCP tool calls sometimes running twice when a remote server's result was over 16 MB or could not be parsed
- Fixed subagents in Claude Desktop's Code tab getting none of the tools of a user-configured MCP server named memory
- Fixed Claude in Chrome asking before every screenshot and page read on a site you allowed when auto mode is unavailable (such as with disableAutoMode or an older model); typing, navigation and JavaScript still ask
- Fixed claude plugin install failing for GitHub-source plugins on macOS and Linux machines with no GitHub SSH key: the clone now falls back to HTTPS and prints a notice
- Fixed sandbox.credentials.files entries on git config files not taking effect while permissions.blockReadsOutsideWorkingDirectories is on
- Fixed Claude leaving out your organization's design systems when starting slides or a design with the Artifact tool on Team and Enterprise plans or machines with managed settings
- Fixed the keyboard not working on Windows after Claude Code restarts itself (first sign-in to a Claude apps gateway, provider setup, /tui)
- Fixed a stall when launching an agent whose tools: lists very many Agent(...) entries
- Fixed sessions on Claude 3 Opus and Claude 3 Sonnet failing on every turn after a whole PDF entered the conversation
- Fixed the npm auto-updater reporting success when the platform-native binary failed to download and only the placeholder claude stub was installed
- Fixed Remote Control cleanup archiving a session that is still connected or was just re-attached by another Claude Code process
- Fixed owner/repo plugin marketplaces showing only the second attempt's error when both the SSH and HTTPS fetch fail; both errors are now shown, with the transport tried first on top
- Fixed path-scoped .claude/rules and nested CLAUDE.md files not loading when Write or Edit creates or changes a file in their scope (previously only Read loaded them)
- Fixed a dangerous rm (such as one on / or the home directory) inside a bash -c or sh -c script running without a prompt in bypassPermissions mode or under a shell allow rule (#96300)
- 为 mods 添加了 $.ui.selection():返回你在全屏模式下最后选中的文本,当选中内容位于单个转录行内时,返回该行
- 为镜像中未包含 GitHub CLI 的云端会话添加了内置 gh api;修复了内置功能将文件名、jq 过滤器或 GitHub 错误中的控制字符发送到终端的问题
- 添加了使用 Ctrl+C 清除提示符后的恢复功能:在空提示符上按向上键可恢复草稿,包括粘贴的文本和图片
- 当 MCP 服务器在工具调用期间请求更多 OAuth 权限范围时,添加了重新身份验证提示
- 为 /code-review 添加了 --max-findings <n>|all 参数,以报告比通常限制更多或更少的发现项;该选择会一直保留,直到你传入 --max-findings default 为止
- 添加了通过名称查找会话的 Ctrl+F 快捷键,以及在代理视图中通过 Alt+↑/↓ 在组之间跳转的功能;两者以及重命名功能均可在 keybindings.json 中重新绑定
- 当你批准计划(包括使用 Shift+Tab)时,屏幕阅读器模式会播报新的权限模式信息
- 修复了因响应中途 API 超时而导致回合失败的问题:非交互式会话和子代理现在会从部分响应继续执行,且仅思考类型的响应会被重试
- 修复了在最后一次回复报告零令牌使用情况时,长对话因“提示过长”而失败而非自动压缩的问题
- 修复了 --resume 有时丢弃文件和其他上下文的问题,而这些上下文刚刚被压缩过程恢复
- 修复了恢复后的会话有时未保存回合的最后一次回复,导致下一次 --resume 显示提示未被回答的问题
- 修复了当同一会话在加载过程中重写文件时,偶尔加载截断的转录记录的问题
- 修复了从 2.1.286 或更早版本开始的对话在恢复时丢失模型早期思考内容的问题
- 修复了在 Mantle 上或在拒绝结构化输出的网关后方,会话标题、记忆召回和提示钩子失效的问题;添加了 CLAUDE_CODE_DISABLE_STRUCTURED_OUTPUTS 环境变量以关闭结构化输出
- 修复了自动模式下,当被阻止的工具不是 Bash 时,拒绝操作会将 Claude 指向 Bash 权限规则的问题
- 修复了 Bedrock 和 Mantle 上的自动模式在请求旧版模型(如 WebFetch 摘要或 sonnet 子代理)后,将剩余会话切换为本地分类器的问题
- 修复了云端会话在新选择的模型被服务器拒绝后,仍使用该模型进行回复的问题
- 修复了 Cowork 云端会话在针对未批准 URL 的 WebFetch 权限提示五分钟无响应后,仍标记为等待输入的问题
- 修复了在手机上加入由其他设备启动的 Cowork 云会话时,固定提示建议不显示的问题
- 修复了在某些情况下,当视图在 Claude Code 重启前绘制时,按下某个模块(mod)按钮会执行另一个按钮的操作的问题
- 修复了当某个代码元素包含无法解析的差异(diff)时,插件面板显示为空的问题;现在该差异将作为纯代码绘制
- 修复了插件 LSP 服务器在 initializationOptions 和 settings 中收到字面量 ${user_config.*} 和 ${CLAUDE_PLUGIN_ROOT} 占位符,而非替换后的值或清单默认值的问题
- 修复了插件的 tool.call 钩子导致 Bash 失败,以及在 worktree 中运行的子代理(subagents)中文件搜索读取错误文件夹的问题
- 修复了在较旧版本的 git(2.39 之前,例如 Ubuntu 22.04 的 2.34)上,git-subdir 插件安装失败或缓存不完整插件的问题
- 修复了使用 --plugin-dir 加载的插件在 /plugin 中未显示“配置选项”的问题
- 修复了在后台会话中,当某个计时器或读取操作仍在运行时重新加载或禁用插件,导致后台会话结束的问题
- 修复了在使用沙箱自动允许的情况下,对于仅包含纯文本和简单 $VAR 引用且分隔符未加引号的沙箱化 heredoc(python3 <<EOF),每次运行都要求批准的问题
- 修复了 Bash 工具权限检查问题:对于 shell 会将其值评估为算术表达式的 BASHPID 赋值,现在会在执行前进行提示,而不是静默允许
- 修复了在打开后台任务对话框时,如果插件或模块在提示符上方显示了行,全屏会话会以“不可恢复的界面错误”退出的问题
- 修复了当目标会话持有该消息时,Claude 报告消息已发送至另一会话的问题;现在通知会说明消息未送达并指明会话名称,且在 SDK 会话中,Claude 可以在回合中途获知此情况
- 修复了 OpenTelemetry claude_code.tool.blocked_on_user span 在 -p 和 SDK 会话中以及 PreToolUse 钩子审批场景中报告未知来源或决策的问题
- 修复了在 -p 模式或中断的回合中,以未回答方式结束的权限请求未发出 tool_decision 事件的问题
- 修复了在 Cowork 云会话中,即使消息历史仍被保存,编辑和重试功能仍拒绝发送在 /compact 之前的消息的问题
- 修复了无人值守会话(CLAUDE_CODE_RETRY_WATCHDOG)在响应流非常长且失败后重试数小时的问题;现在 Claude Code 会再次尝试流式传输,并在三次超时后放弃
- 修复了当凭据无法保存到安全存储时,/login 命令报告“登录成功”的问题;现在它会显示失败信息,并在新登录未生效时提供重试选项(#73861)
- 修复了在 Bedrock 凭据查找过程中有时出现停止,导致会话被转移到备用模型而非结束请求的问题
- 修复了当笔记本电脑从睡眠中唤醒且另一个 Claude Code 进程正在登录时,再次打开 gcpAuthRefresh/awsAuthRefresh 浏览器登录窗口的问题
- 修复了智能体团队问题:通过名称生成的插件定义智能体现在使用其自身的提示词、工具、禁用工具和精力设置,而非默认值
- 修复了无头模式(-p / SDK)会话在 supervisor(如 timeout 或 systemd)同时发送 SIGCONT 时偶尔忽略 SIGTERM 信号的问题
- 修复了重启后的云会话恢复模型时,该模型被组织强制执行的模型列表拒绝的问题
- 修复了当远程服务器结果超过 16 MB 或无法解析时,MCP 工具调用有时执行两次的问题
- 修复了 Claude Desktop 的 Code 标签页中的子智能体无法获取用户配置的名为 memory 的 MCP 服务器的任何工具的问题
- 修复了在自动模式不可用时(例如设置了 disableAutoMode 或使用较旧模型),Claude 在您已允许的网站上进行每次截图和页面读取前都询问的问题;输入、导航和 JavaScript 操作仍会询问
- 修复了在没有 GitHub SSH 密钥的 macOS 和 Linux 机器上,claude 插件安装因 GitHub 源插件失败的问题:克隆操作现在回退到 HTTPS 并打印通知
- 修复了 git config 文件中的 sandbox.credentials.files 条目在 permissions.blockReadsOutsideWorkingDirectories 开启时未生效的问题
- 修复了在使用 Artifact 工具在 Team 和 Enterprise 计划或具有托管设置的机器上启动幻灯片或设计时,Claude 遗漏您组织的 Design Systems 的问题
- 修复了 Claude Code 自我重启后 Windows 键盘无法使用的问题(首次登录 Claude 应用网关、提供商设置、/tui)
- 修复了启动包含大量 Agent(...) 条目的 tools 列表的智能体时出现的卡死问题
- 修复了在整份 PDF 进入对话后,Claude 3 Opus 和 Claude 3 Sonnet 上的会话在每一轮都失败的问题
- 修复了 npm 自动更新器在平台原生二进制文件下载失败且仅安装了占位符 claude stub 时报告成功的问题
- 修复了 Remote Control 清理功能归档仍处于连接状态或刚刚被另一个 Claude Code 进程重新附加的会话的问题
- 修复了 owner/repo 插件市场在 SSH 和 HTTPS 拉取均失败时仅显示第二次尝试的错误的问题;现在会显示两个错误,先尝试的传输方式位于顶部
- 修复了当 Write 或 Edit 在其范围内创建或更改文件时,路径受限的 .claude/rules 和嵌套的 CLAUDE.md 文件无法加载的问题(此前仅 Read 会加载它们)
- 修复了在 bypassPermissions 模式下或在 shell allow 规则下运行且无提示的 bash -c 或 sh -c 脚本中执行危险 rm 命令(例如针对 / 或主目录)的问题 (#96300)
更进一步:量化金融体系
看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力