This release includes 2 breaking changes for platform teams planning a safe upgrade.
✓ No known CVEs patched in this version
ReleasePort's take
Light signal/fork now copies conversations into background sessions and /subtask replaces the old in‑session subagent launch.
Why it matters: Limits WebSearch calls to 200 per session (configurable) and caps subagent spawns at 200 per session, preventing runaway loops; critical for resource‑constrained environments.
Summary
AI summary/fork now copies conversations into background sessions, /subtask replaces old in‑session subagent launch, and two new limits cap WebSearch and subagent spawns per session.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Low |
/fork now copies conversation into a new background session, keeping original active; subtask command replaces old in‑session launch /fork now copies conversation into a new background session, keeping original active; subtask command replaces old in‑session launch Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Feature | Low |
Added `claude auto-mode reset` to restore default auto‑mode configuration, with optional `--yes` to skip confirmation prompt Added `claude auto-mode reset` to restore default auto‑mode configuration, with optional `--yes` to skip confirmation prompt Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Feature | Low |
Added session‑wide limit on WebSearch tool calls (default 200, configurable via `CLAUDE_CODE_MAX_WEB_SEARCHES_PER_SESSION`) to prevent runaway loops Added session‑wide limit on WebSearch tool calls (default 200, configurable via `CLAUDE_CODE_MAX_WEB_SEARCHES_PER_SESSION`) to prevent runaway loops Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Feature | Low |
Added per‑session cap on subagent spawns (default 200, configurable via `CLAUDE_CODE_MAX_SUBAGENTS_PER_SESSION`); `/clear` resets the budget Added per‑session cap on subagent spawns (default 200, configurable via `CLAUDE_CODE_MAX_SUBAGENTS_PER_SESSION`); `/clear` resets the budget Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Feature | Low |
MCP tool calls longer than 2 minutes now move to background automatically; threshold configurable via `CLAUDE_CODE_MCP_AUTO_BACKGROUND_MS` MCP tool calls longer than 2 minutes now move to background automatically; threshold configurable via `CLAUDE_CODE_MCP_AUTO_BACKGROUND_MS` Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Feature | Low |
/resume in agent view now opens a picker of past sessions (including deleted) and resumes selected as background session /resume in agent view now opens a picker of past sessions (including deleted) and resumes selected as background session Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Feature | Low |
Improved reliability of web search and fetch by retrying 529 errors and rate‑limited requests with bounded backoff Improved reliability of web search and fetch by retrying 529 errors and rate‑limited requests with bounded backoff Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
| Bugfix | Medium |
Fixed worktree creation following a committed symlink at `.claude/worktrees` that could create files outside the repository Fixed worktree creation following a committed symlink at `.claude/worktrees` that could create files outside the repository Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Bugfix | Medium |
/background and `claude --bg` now succeed on Windows when Group Policy blocks PowerShell 5.1 by preferring PowerShell 7 /background and `claude --bg` now succeed on Windows when Group Policy blocks PowerShell 5.1 by preferring PowerShell 7 Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Bugfix | Medium |
Fixed plan mode auto‑running file‑modifying Bash commands (e.g., `touch`, `rm`) without permission prompt or SDK `canUseTool` callback Fixed plan mode auto‑running file‑modifying Bash commands (e.g., `touch`, `rm`) without permission prompt or SDK `canUseTool` callback Source: llm_adapter@2026-07-17 Confidence: low |
— |
| Bugfix | Medium |
Fixed SIGTERM during a running Bash tool orphaning the process tree in print/SDK mode; CLI now aborts turn, kills tree, exits 143 Fixed SIGTERM during a running Bash tool orphaning the process tree in print/SDK mode; CLI now aborts turn, kills tree, exits 143 Source: llm_adapter@2026-07-17 Confidence: low |
— |
| Bugfix | Medium |
Fixed hosted sessions failing at startup when mTLS certs, extra CA bundles, or OAuth scopes were configured; settings are now ignored with a warning Fixed hosted sessions failing at startup when mTLS certs, extra CA bundles, or OAuth scopes were configured; settings are now ignored with a warning Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
| Bugfix | Low |
Fixed `/ultrareview` rejecting PR references like `#123`, `PR 123`, and pasted URLs; error hints now name the command typed Fixed `/ultrareview` rejecting PR references like `#123`, `PR 123`, and pasted URLs; error hints now name the command typed Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
| Bugfix | Low |
/ultrareview <branch> now fetches missing remote branch instead of failing silently /ultrareview <branch> now fetches missing remote branch instead of failing silently Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
| Bugfix | Low |
Fixed `/ultrareview` skipping billing confirmation after /clear and handling non‑git repository errors with better suggestions Fixed `/ultrareview` skipping billing confirmation after /clear and handling non‑git repository errors with better suggestions Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
| Bugfix | Low |
Fixed spurious "File has not been read yet" error after editing a file previously read with offset/limit before resuming a session Fixed spurious "File has not been read yet" error after editing a file previously read with offset/limit before resuming a session Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
| Bugfix | Low |
Fixed `ExitWorktree` failing with "no active EnterWorktree session" after resuming with `--continue`/`--resume` in print/SDK mode Fixed `ExitWorktree` failing with "no active EnterWorktree session" after resuming with `--continue`/`--resume` in print/SDK mode Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
| Bugfix | Low |
Fixed workflow agent grid staying empty for Remote Control clients joining mid‑run Fixed workflow agent grid staying empty for Remote Control clients joining mid‑run Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
| Bugfix | Low |
Fixed streaming‑mode control requests being marked complete prematurely, which could lose the request on session restart Fixed streaming‑mode control requests being marked complete prematurely, which could lose the request on session restart Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
| Bugfix | Low |
/fork background sessions no longer lose live‑parent protection after a state write failure /fork background sessions no longer lose live‑parent protection after a state write failure Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
| Bugfix | Low |
Fixed reopening stopped background sessions from agent view failing silently; now resumes or shows error and allows force restart Fixed reopening stopped background sessions from agent view failing silently; now resumes or shows error and allows force restart Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
| Bugfix | Low |
Fixed duplicate idle notifications from stopping teammate in agent teams when team initialization re‑ran within a session Fixed duplicate idle notifications from stopping teammate in agent teams when team initialization re‑ran within a session Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
| Bugfix | Low |
Fixed plan‑approval dialog footer splitting "ctrl+g to edit in <editor>" when file path is long Fixed plan‑approval dialog footer splitting "ctrl+g to edit in <editor>" when file path is long Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
| Bugfix | Low |
Fixed welcome banner retaining old panel widths after combined width+height resize in fullscreen mode Fixed welcome banner retaining old panel widths after combined width+height resize in fullscreen mode Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
| Bugfix | Low |
Fixed diff previews losing line numbers and +/- markers in narrow layouts Fixed diff previews losing line numbers and +/- markers in narrow layouts Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
| Bugfix | Low |
Fixed @‑mentions attaching nothing after partial file read, plugin uninstall targeting wrong marketplace, and false "Command timed out" on exit code 143 Fixed @‑mentions attaching nothing after partial file read, plugin uninstall targeting wrong marketplace, and false "Command timed out" on exit code 143 Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
| Bugfix | Low |
Fixed OpenTelemetry HTTP exports being rejected with 411/400 by endpoints that don't accept chunked transfer encoding Fixed OpenTelemetry HTTP exports being rejected with 411/400 by endpoints that don't accept chunked transfer encoding Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
| Bugfix | Low |
Fixed OTLP event log records missing `trace_id`/`span_id` when `TRACEPARENT` is set in SDK/headless mode Fixed OTLP event log records missing `trace_id`/`span_id` when `TRACEPARENT` is set in SDK/headless mode Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
| Bugfix | Low |
Fixed conversations with many images failing with "Request too large" and improved error message to explain cause Fixed conversations with many images failing with "Request too large" and improved error message to explain cause Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
| Bugfix | Low |
Fixed web search and fetch returning "API Error" text as results when API overloaded Fixed web search and fetch returning "API Error" text as results when API overloaded Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
Full changelog
What's changed
/forknow copies your conversation into a new background session (its own row inclaude agents) while you keep working; the in-session subagent it used to launch is now/subtask- Added
claude auto-mode resetto restore the default auto-mode configuration, with a confirmation prompt (pass--yesto skip) - Added a session-wide limit on WebSearch tool calls (default 200, tunable via
CLAUDE_CODE_MAX_WEB_SEARCHES_PER_SESSION) to stop runaway search loops - Added a per-session cap on subagent spawns (default 200, override with
CLAUDE_CODE_MAX_SUBAGENTS_PER_SESSION) to stop runaway delegation loops;/clearresets the budget - MCP tool calls running longer than 2 minutes now move to the background automatically so the session stays usable; configure the threshold or disable with
CLAUDE_CODE_MCP_AUTO_BACKGROUND_MS - Typing
/resumein the agent view now opens a picker of past sessions — including sessions deleted from the list — and resumes your pick as a background session - Fixed plan mode auto-running file-modifying Bash commands (e.g.
touch,rm) without a permission prompt or SDKcanUseToolcallback - Fixed worktree creation following a repository-committed symlink at
.claude/worktrees, which could create files outside the repository - Fixed a
continue:falsehook's halt being dropped when the tool fails or completes mid-stream, and hook infrastructure errors being misreported as user rejections - Fixed SIGTERM during a running Bash tool orphaning the command's process tree in print/SDK mode; the CLI now aborts the turn, kills the tree, and exits 143
- Fixed
/backgroundandclaude --bgfailing with "EUNKNOWN: unknown error, uv_spawn" on Windows when Group Policy blocks PowerShell 5.1; the daemon now prefers PowerShell 7 - Fixed shell mode (
!) not executing commands containing file paths while the path autocomplete popup was open - Fixed auto-mode denial notifications rendering broken characters when a long denial reason was truncated mid-emoji
- Fixed Ctrl+J not inserting a newline in the agent view dispatch input on terminals with extended key reporting, and surfaced the newline shortcut in the
?help overlay - Fixed
/ultrareviewrejecting PR references like#123,PR 123, and pasted PR URLs; error hints now name the command you actually typed - Fixed
/ultrareview <branch>not fetching the branch from origin when it exists remotely; it now suggests the closest branch name on typos - Fixed
/ultrareviewskipping the billing confirmation in a new conversation after/clear - Fixed
/ultrareview's "not a git repository" error on Claude Desktop now suggesting the project's repository folder instead of terminal commands - Fixed hosted (host-managed) sessions failing at startup when repository settings configured mTLS certs, extra CA bundles, or OAuth scopes; these transport settings are now ignored with a warning
- Fixed a spurious "File has not been read yet" error when editing a file that had been read with offset/limit before resuming a session
- Fixed
ExitWorktreefailing with "no active EnterWorktree session" after resuming a session with--continue/--resumein print/SDK mode - Fixed the workflow agent grid staying empty for Remote Control clients that join a session mid-run
- Fixed streaming-mode control requests being marked complete before their handler finished, which could lose the request on session restart
- Fixed background sessions created with
/forklosing their live-parent protection after a state write failure - Fixed reopening a stopped background session from the agent view failing silently — it now resumes the session, or shows why it can't and lets you force a restart
- Fixed agent teams: a stopping teammate could send the leader duplicate idle notifications when team initialization re-ran within a session
- Fixed the plan-approval dialog footer splitting "ctrl+g to edit in " apart when the file path is long
- Fixed the welcome banner keeping its old panel widths after a combined width+height terminal resize in fullscreen mode
- Fixed diff previews losing their line numbers and +/- markers in narrow layouts
- Fixed @-mentions attaching nothing after a partial file read, plugin uninstall targeting the wrong marketplace, and false "Command timed out" on exit code 143
- Fixed OpenTelemetry HTTP exports being rejected with 411/400 by Azure Monitor and other endpoints that don't accept chunked transfer encoding
- Fixed OTLP event log records missing
trace_id/span_idwhenTRACEPARENTis set in SDK/headless mode - Fixed conversations with many images incorrectly failing with "Request too large" errors, and improved the error message to explain the actual cause
- Fixed web search and web fetch returning "API Error" text as search results or page content when the API was overloaded
- Improved web search and web fetch reliability by retrying 529 errors and rate-limited requests with bounded backoff
- Improved prompt caching: the mid-conversation system block now works behind LLM gateways and custom base URLs (Bedrock, Vertex, 1P)
- Improved background agent attach: cold-attaching now instantly shows the formatted transcript while the session boots, instead of a blank wait
- Reduced token usage in inter-agent messaging:
SendMessagebodies are no longer duplicated into replayed history and tool results - Changed
/forkto name the copy after your prompt when the session has no title, so the row is recognizable in the agent view - Changed bare
/btwto reopen the side-question panel on your most recent exchange so you can browse earlier answers - Changed the
←footer hint to pulseN donefor a moment when a background agent finishes while nothing needs your input - Deprecated the Task tool's
modeparameter (now ignored); subagents inherit the parent session's permission mode by default - Changed Enterprise
forceLoginMethodto be enforced for VS Code extension, SDK,setup-token, andinstall-github-applogins, not just the terminal - Changed session transcripts to record the reasoning effort level on each assistant message
- Changed headless/SDK sessions to apply a
set_modelcontrol request mid-turn; the next model round-trip uses the new model instead of waiting for the next turn - Changed agent view /
claude agents --json: sessions waiting on a sandbox, MCP-input, or managed-settings prompt now show as "Needs input" instead of "Working" - Updated the auth status panel title from "Cloud authentication" to "Authentication"
- Corrected an earlier release note (2.1.200): tmux through the 3.6 series lacks synchronized output; newer tmux with support is detected automatically
Breaking Changes
- /fork renamed: old in‑session subagent launch moved to /subtask
- Task tool's `mode` parameter deprecated (now ignored)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About claude-code
All releases →Related context
Earlier breaking changes
- v2.1.215 Claude no longer automatically runs /verify and /code-review skills
- v2.1.160 Renames dynamic‑workflow trigger keyword from `workflow` to `ultracode`; `workflow` no longer triggers a run
- v2.1.160 Deprecates and removes the `CLAUDE_CODE_OPUS_4_6_FAST_MODE_OVERRIDE` environment variable; it is now a no‑op
- v2.1.147 Renames /simplify to /code-review; removes cleanup-and-fix behavior.
Beta — feedback welcome: [email protected]