2.1.234
Claude Code 2.1.234 - リリースノート
2026年8月17日
Claude Code
日本語サマリー
Claude Code 2.1.234 リリースノート要約
🔒 セキュリティ関連
- セキュリティ修正:リモートファイル読み取り、セッション復元、CLAUDE.md インクルード、ワークフロースクリプト、ファイルアップロードで、Windows NT名前空間(
\??\)パスを拒否。NTLM資格情報リーク攻撃ベクトルへの対策を強化 strictKnownMarketplacesの許可リストが、実際に接続するホストと異なるSCP形式のgit marketplaceソースを受け入れる問題を修正- リレーされる権限プレビューの認証情報マスキングが、承認者からコマンド・パス・宛先を隠してしまう問題を修正
✨ 新機能
- 環境変数
CLAUDE_CODE_PROJECT_DIR_NAMEを追加(セッションごとの設定ディレクトリに短い名前を指定可能) - テキスト選択をクリアする
selection:clearキーバインドアクションを追加 - GitLab マージリクエストバッジ(MR !N)をフッターとステータスラインに表示
- claude.ai の利用制限リセット時にセッションを自動継続(
/configでオフ可能) - アカウントメールは本人識別のみに使用し、無関係なサービスへ送信しないよう明確化
🐛 重要な修正
- 長時間セッションでの自動モードが、コンパクト化後にサンドボックスコマンドのネットワークアクセスを繰り返し拒否する問題を修正
- 非ストリーミングフォールバック経路(サードパーティゲートウェイ等)でAPI応答に欠損フィールドがある場合のクラッシュを修正
SendMessageが200文字上限や絵文字多用のセッション名で受信者を拒否する問題を修正- MCP診断で解決済みシークレットが表示される問題を修正(
${VAR}形式のみ表示) - リモートコントロールセッションでアカウント/組織切替時に、数秒以内にセッション停止と理由を表示(従来は数時間後のHTTP 404)
- フルスクリーン再描画プロンプト承認時に
--dangerously-skip-permissions等の設定が失われる問題を修正
🔧 改善
- 組み込み
claude-apiスキルのコンテキストコストを約200k+トークンから約25kに削減 /permissions、/add-dirなどがClaude動作中でも開けるように(変更は現ターンに即時反映)/goal:リカバリ不能なエラーで自動クリア、バックグラウンドタスク待ちが30分以上でチェックイン(CLAUDE_CODE_GOAL_CHECKIN_MINUTES=0でオプトアウト可)- 自動生成セッションタイトルを短く具体的な名前に改善
原文(Release Notes)
What's changed
- Added the optional
CLAUDE_CODE_PROJECT_DIR_NAMEenvironment variable: hosts that give each session its own config directory can choose a short name for the per-project transcript directory- Added the
selection:clearkeybinding action, so a key can be bound to clear an in-app text selection; also works in the agents view- Added a GitLab merge request badge to the footer and statusline: repos with a GitLab remote and an authenticated glab CLI show MR !N with draft/pending/green states
- Claude Code now continues your session automatically when a claude.ai usage limit resets; turn it off in
/config("Continue automatically at usage limit")- Claude is now told to use your account email only to identify you, and not to send it to unrelated services unless you ask
- Security: remote file reads, session restore, CLAUDE.md includes, workflow scripts and file uploads now reject Windows NT-namespace (
\??\) paths, hardening the remaining pre-approval file accesses against the NTLM credential-leak vector- Fixed auto mode in very long sessions repeatedly re-checking and denying sandboxed commands' network access after the conversation had been compacted
- Fixed session-scoped permission answers (including denies) being dropped when answering background subagent tool permission prompts
- Fixed a crash when an API response on the non-streaming fallback path (typically via third-party gateways) contained a thinking block missing its thinking field or a text block missing its text field
- Fixed markdown rendering becoming extremely slow for some messages containing unusual Unicode sequences
- Fixed
SendMessagerejecting a recipient copied fromListAgentswhen the session name is at the 200-character cap or emoji-heavy- Fixed repository detection mis-reading the host of git remotes with unusual userinfo, producing links and repo-specific behavior for the wrong host
- Fixed MCP diagnostics printing resolved secrets: scope-conflict warnings now show the configured
${VAR}form, and connection-failure details show only the server origin- Fixed
strictKnownMarketplacesallowlists accepting SCP-style git marketplace sources whose host differs from the one git would actually connect to- Fixed modal text such as the
/loginOAuth URL losing characters when copied in fullscreen- Fixed a
---horizontal rule in rendered markdown running into the line after it- Fixed consecutive shell commands splitting into multiple "Ran 1 shell command" rows when todo/task updates were interleaved between them
- Fixed dialogs like
/permissionsopened while a!shell command was running being dismissed when the command finished- Fixed a queued
!shell command being sent to the model as plain text after pressing up-arrow to edit the queued input- Fixed queued messages reappearing in the prompt history while still queued, Esc while selecting a queued message no longer interrupts the turn, and
!mode no longer sticks after a mid-turn submit- Fixed accepting the "Try the new fullscreen renderer?" prompt restarting the session without its permission mode (e.g.
--dangerously-skip-permissions), tool allow/deny rules, model or effort flags- Fixed
/tuidropping launch--allowed-tools/--disallowed-toolsrules when it restarts; it now declines to switch, with the reason, when the session has restrictions a restart can't carry over- Fixed trust prompts omitting the repository-wide scope warning when the directory was first seen before the repository existed there
- Fixed a case where an IDE diff tab closing during a permission re-prompt could answer the new prompt with the previous input
- Fixed: files sent to the user during Remote Control sessions hosted by Claude Code Desktop or VS Code now upload, so they open on phone and web instead of showing an empty card
- Fixed: after
/loginwhileCLAUDE_CODE_OAUTH_TOKENis set, the stale-token reminder no longer leaks into Claude's automatically resumed turn — it now appears only to you- Fixed: permission previews now relay only to channel servers admitted by the inbound trust gate, and a server's explicit permission-capability opt-out is honored
- Fixed: credential masking on relayed permission previews can no longer hide commands, paths, or destinations from the approver; oversized private-key blocks now redact under full-strength redaction
- Fixed: provider API tokens that mask on permission previews now mask even when directly followed by shell delimiters
- Fixed Claude Desktop inter-session messages being silently dropped by the recipient session when cross-session messaging read as disabled, which left the sender's query "thinking" for many minutes
- Remote Control: signing this computer in to a different claude.ai account or organization now stops the running session within seconds and says why, instead of a misleading HTTP 404 hours later
- Remote Control sessions started from Claude Code Desktop or VS Code now keep phones and claude.ai/code updated on the session's permission mode (and claude.ai/code on the model) as they change
- Remote Control: effort picks made on a phone or on claude.ai/code now apply to terminal- and Desktop/VS Code-hosted sessions, and the session publishes its effort level to connected clients
SendMessageandListAgentsnow say when your account's session list was too long to check completely, instead of treating unseen sessions as absent- Expired Anthropic profile credential now points you at
/loginwhen a claude.ai login would take precedence- Improved the transcript: your own prompts now render markdown (highlighted code blocks, inline code, lists) the same way replies do
- Improved the "API returned an empty or malformed response" error to say what came back (content type, body kind, size, request ID) and why the original streaming request failed
- Improved auto-generated session titles to read as short, specific names (e.g. "Login button bug") rather than sentences restating your request (e.g. "Fix the login button on mobile")
- Reduced the context cost of loading the built-in
claude-apiskill from ~200k+ tokens to ~25k by loading reference docs on demand/permissionscan now be opened while Claude is working — rule changes apply to the rest of the current turn/add-dir <path>can now be used while Claude is working;/add-dir,/autocompact,/theme,/help,/configand/advisordialogs open mid-turn in the fullscreen TUI/goalnow clears itself with a notice when a turn dies on an unrecoverable error (e.g. revoked auth, an exhausted credit balance, or a context overflow) instead of staying armed/goal: when background tasks keep a goal waiting for 30+ minutes, Claude now checks in on them instead of waiting indefinitely (setCLAUDE_CODE_GOAL_CHECKIN_MINUTES=0to opt out)claude setup-tokennow rejects unexpected extra arguments instead of silently ignoring them- Changed Esc in fullscreen mode to no longer clear a mouse text selection: it interrupts or dismisses as usual and the selection stays highlighted
- Removed the redundant "Allowed by auto mode classifier" line that auto mode showed under every Agent tool call
- Removed the "Default teammate model" setting from
/config; agent-team teammates now use the leader's model unless the spawn names one- Dimmed the elapsed-time counter on the running tool header so it no longer competes with the bold counts
- Background task notifications delivered between turns are now sent to the model inside
<system-reminder>tags, matching mid-turn delivery- Mantle: skip the admin-pin availability probe at startup when a main-loop model is already picked
- Windows: startup no longer stalls on repeated rename retries when
~/.claude.jsonis read-only