跳到主内容
@wquguru
精选88Claude Code(GitHub Releases)AI 编程与模型

Claude Code v2.1.289:修复终端冻结、沙箱规则绕过及插件崩溃等

v2.1.289

原文
发到 X
推荐理由

涉及沙箱规则绕过和 symlink 权限校验失效,直接威胁操作安全;同时修复了导致终端冻结和插件崩溃的高频稳定性问题,建议立即升级以保障开发环境稳定与安全。

What's changed

变更内容

  • Fixed a deny or ask rule on a nested part of a compound shell command not holding over a user-installed mod's approval on managed machines
  • Fixed the terminal freezing on short code blocks with many unclosed <script> tags or deeply nested ${ substitutions
  • Fixed Read deny rules not applying to files @-mentioned, changed, or selected in the IDE through a symlink
  • [VSCode] Reverted a 2.1.288 change to claude auth status that may have made sign-outs more frequent
  • Improved how quickly large files open in a plugin code pane by laying the highlighted view out once at its final width
  • Fixed plugin list, plugin eval and plugin update showing a stale copy of a plugin installed from a local folder marketplace, and hot reload for a symlinked --plugin-dir
  • Fixed installed mods not loading in the first session after an upgrade
  • Fixed a plugin's rows above the prompt showing a stale row while the Background tasks dialog was open in fullscreen
  • Fixed plugin panes drawing nothing when a link used a localhost address, an @ in its path, an uppercase host or a file: path
  • Fixed a user-installed plugin being able to rewrite the descriptions of an organization-managed MCP server's sign-in tools
  • Fixed a freeze or forced quit at launch when a plugin drew a Box with a border style the terminal does not know
  • Fixed supervised and background sessions ending when a plugin's on-screen handler threw asynchronously
  • Fixed sessions ending with an interface error when a plugin region with no height kept growing
  • Fixed Bash deny and ask rules missing a command behind an environment variable prefix with an expanded value (e.g. TZ="$HOME" rm -rf build) when the sandbox auto-allows commands
  • Fixed a Bash deny or ask rule being skipped under sandbox auto-allow when a bare variable assignment came before the command
  • Fixed claude plugin validate skipping the plugin when the folder also holds a marketplace manifest
  • Added agent.spawn for teammates, one agent id across plugin hook events, and idle and waiting states in $.agent.list()
  • Fixed sessions ending with "unrecoverable interface error" when a value a mod's ui.render hook wrote made a row throw while drawn; the engine now draws its own row instead
  • Fixed text with a tab, a stray escape and a C1 control, or a short text with a tab and CRLF line endings, drawing over the rows below it
  • Fixed right-aligned content in a mod's pane or band drawing under the close mark or [-], which now also keep one column in from the terminal's edge
  • Fixed a mod's Client that fails while drawn taking down everything the mod drew around it; it now fails alone and raises ui.fault
  • Fixed claude plugin validate failing an Anthropic marketplace's own plugin and listing a clean plugin.json in --json
  • Fixed a mod's band that fails to draw briefly telling the cards under it to step aside
  • Fixed a failed plugin component showing Error or nothing as its reason when the failure carried no message
  • Improved the line a mod's author sees when its band or pane fails to draw: it names the mod and says nothing was drawn
  • Fixed published artifact pages freezing or crashing the reader's browser tab on short code blocks with many unclosed <script> tags
  • Fixed a mod's Client region staying failed for the whole session after the terminal threw while drawing it
  • 修复了在托管设备上,嵌套在复合 shell 命令部分的拒绝或询问规则未延续用户已安装模块的审批状态的问题
  • 修复了当代码块较短且包含大量未闭合的 <script> 标签或深层嵌套的 ${ 替换时终端冻结的问题
  • 修复了读取拒绝规则未应用于 IDE 中通过符号链接提及、更改或选中的文件的问题
  • [VSCode] 回退了 2.1.288 版本中关于 Claude 认证状态的更改,该更改可能导致登出频率增加
  • 通过在插件代码窗格中将高亮视图一次性布局为其最终宽度,改善了大文件的打开速度
  • 修复了从本地文件夹市场安装的插件列表、插件评估和插件更新显示过时副本的问题,以及针对符号链接 --plugin-dir 的热重载问题
  • 修复了升级后首次会话中已安装的模块未加载的问题
  • 修复了在全屏模式下打开后台任务对话框时,提示符上方显示的插件行出现过时数据的问题
  • 修复了当链接使用 localhost 地址、路径中包含 @、主机名大写或使用 file: 路径时,插件窗格不绘制任何内容的问题
  • 修复了用户安装的插件能够重写组织管理的 MCP 服务器登录工具描述的问题
  • 修复了当插件绘制终端不支持的边框样式的 Box 时,启动过程中出现冻结或强制退出的问题
  • 修复了当插件的屏幕处理程序异步抛出异常时,受监督和后台会话结束的问题
  • 修复了当无高度的插件区域持续增大时,会话以界面错误结束的问题
  • 修复了当沙箱自动允许命令时,Bash 拒绝和询问规则遗漏环境变量前缀展开值后的命令(例如 TZ="$HOME" rm -rf build)的问题
  • 修复了当裸变量赋值位于命令之前时,在沙箱自动允许下 Bash 拒绝或询问规则被跳过的问题
  • 修复了 claude 插件验证在文件夹同时包含市场清单时跳过插件的问题
  • 为队友添加了 agent.spawn,实现了跨插件钩子事件的单一代理 ID,并在 $.agent.list() 中增加了空闲和等待状态
  • 修复了当模块的 ui.render 钩子写入的值导致某行在绘制时抛出异常,从而使会话以“不可恢复的界面错误”结束时的问题;引擎现在会自行绘制该行
  • 修复了包含制表符、孤立转义字符和 C1 控制字符的文本,或包含制表符和 CRLF 换行符的短文本,覆盖其下方行的问题
  • 修复了模块窗格或栏中右对齐的内容绘制在关闭标记或 [-] 下方的问题,这些标记现在也保持与终端边缘一列的距离
  • 修复了某个 mod 的 Client 在绘制时失败并导致其周围所有由该 mod 绘制的元素一同崩溃的问题;现在它仅独立失败并触发 ui.fault
  • 修复了 claude 插件验证功能错误地判定 Anthropic 市场自有插件失败,并在 --json 模式下列出干净的 plugin.json 的问题
  • 修复了某个 mod 的 band 在短暂绘制失败时,未能让位于其下方的卡片退让的问题
  • 修复了当插件组件失败且无具体错误信息时,显示为 Error 或空白作为失败原因的问题
  • 改进了 mod 作者在其 band 或 pane 绘制失败时看到的提示行:该行现在会指明 mod 名称并说明未绘制任何内容
  • 修复了已发布的制品页面中,包含大量未闭合 <script> 标签的短代码块导致阅读器浏览器选项卡冻结或崩溃的问题
  • 修复了某个 mod 的 Client 区域在终端绘制时抛出异常后,整个会话期间持续处于失败状态的问题

更进一步:量化金融体系

看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力

进入量化体系 →

相似阅读

关联信息,但可能不是同一事件