AI 编程 4.0 · 优秀 2026-08-28 · GitHub

Claude Code v2.1.251: model-switch hooks, /cost prompt-cache line, symlink path-escape fixes

anthropics/claude-code 发布 v2.1.251(2026-08-28T18:19Z)新增:PreModelSwitch/PostModelSwitch 钩子(block/confirm/annotate,SessionStart resume 钩子附会话过期与预估重缓存成本,用于保护 prompt cache);前台 subagent 的工具调用与结果可直播到 Remote Control 客户端(后台 subagent 仍只报状态);/usage 加 Spend limit 条与 rate_limits.spend_limit 状态行;/cost 新增每会话 prompt-cache 行(命中率miss重缓存 tokenwarm/cold)...

打开原文回到归档

Claude Code v2.1.251: model-switch hooks, /cost prompt-cache line, symlink path-escape fixes

中文导读

anthropics/claude-code 发布 v2.1.251(2026-08-28T18:19Z)。新增:PreModelSwitch/PostModelSwitch 钩子(block/confirm/annotate,SessionStart resume 钩子附会话过期与预估重缓存成本,用于保护 prompt cache);前台 subagent 的工具调用与结果可直播到 Remote Control 客户端(后台 subagent 仍只报状态);/usage 加 Spend limit 条与 rate_limits.spend_limit 状态行;/cost 新增每会话 prompt-cache 行(命中率、miss、重缓存 token、warm/cold);claude --help 补 attach/logs/stop/respawn/rm 后台会话命令。修复簇集中在路径与权限:文件工具在权限检查后跟随被换掉的 symlink 可读写审批路径外(类 TOCTOU)、marketplace 插件命令拒绝 path-traversal、Workflow scriptPath 不再预读会话外路径、Grep/Glob 经 symlink 绕过 Read deny 已堵、Bash OPTIND 算术赋值不再自动放行、项目 settings 不再能设 CLAUDE_CONFIG_DIR/TMPDIR。把 Claude Code 接进真实代码库的团队值得复读运行配置

原文摘录(节选)

摘录来源:opencli web read 全文抓取
# Claude Code v2.1.251 release notes

- tag: v2.1.251
- published_at: 2026-08-28T18:19:32Z
- author: ashwin-ant
- url: https://github.com/anthropics/claude-code/releases/tag/v2.1.251

## Body

## What's changed

- Added `PreModelSwitch` and `PostModelSwitch` hook events (block, confirm, or annotate a model switch); `SessionStart` resume hooks now receive session staleness and the estimated re-cache cost
- Added live streaming of a foreground subagent's tool calls and results to Remote Control clients (background subagents, the default, still show status only)
- Added a Spend limit bar to `/usage` and a `rate_limits.spend_limit` status line field for developers behind a Claude apps gateway with spend limits
- Added a per-session prompt-cache line to `/cost` (hit ratio, misses, tokens re-cached, warm/cold) and a matching `prompt_cache` object for status line scripts
- Added `attach`, `logs`, `stop`, `respawn`, and `rm` to `claude --help`; the `--resume` message for a running background session now names the exact `claude attach <id>` command
- Fixed file tools (Read, Write, Edit) following a symlink swapped inside the working directory after the permission check, which could read or write outside the approved location
- Fixed plugin commands declared in a marketplace entry being able to point outside the plugin directory; such paths are now rejected with a path-traversal error
- Fixed project settings being able to enable detailed beta tracing or raw API body logging, and a lower-scope beta tracing endpoint bypassing an OTLP collector pinned by managed settings or a host app
- Fixed the Workflow tool reading (and quoting in errors) a `scriptPath` outside what the session may read before the permission check ran
- Fixed Grep and Glob not applying `Read(...)` deny rules to files reached through a symlinked search path
- Fixed conversations getting stuck on "text content blocks must be non-empty" errors after a turn where the model produced only thinking
- Fixed the first launch on a fresh install starting in default mode instead of auto mode for accounts whose startup default is auto mode
- Fixed Opus 5 requests failing with "effort … is not supported when thinking is disabled" when effort was xhigh/max and thinking was turned off; effort is now sent as `high` in that case
- Fixed replying to a message Claude Desktop delivered from another session: `SendMessage` to that session id now delivers through Claude Desktop instead of failing with "not reachable"
- Fixed TUI lag with many parallel subagents: per-second progress ticks now replace their predecessor instead of piling up in the transcript
- Fixed agent teams: a teammate's final answer not reaching the team lead — it now arrives in the idle notification instead of a content-free "available" notice
- Fixed background subagents being unable to reply to a message from an unnamed sibling or parent agent (`from` was the agent type, which is not an address)
- Fixed managed-settings `disableAutoMode` arriving mid-session not moving an already-running auto-mode session back to default mode
- Fixed a "switch to Opus 1M for 5x more context" tip that appeared even when the current Opus model already has a 1M context window
- Fixed Claude apps gateway sessions treating a stored Anthropic profile (e.g. a Console sign-in) as active: listing it in `/status` and retrying gateway 401s with it, though requests never use it
- Fixed cloud sessions telling Claude the model had changed when the host was only setting the session's initial model
- Fixed Remote Control reporting a failure when an organization's policy disables it; it now shows a single quiet notice instead
- Fixed `/mcp reconnect` on Remote Control showing a generic withheld-detail error instead of the real remedy when a server was disabled in another session
- Fixed `--input-format stream-json`: client-injected assistant tool calls sent without a message id were merged into the first one and their results lost, including when resuming older sessions
- Fixed session transcripts being silently overwritten when a directory change relocated a session onto an existing same-ID transcript
- Fixed background sessions and their subagents being unable to edit files inside a git worktree they created with `git worktree add`
- Fixed background sessions occasionally starting without any plugin skills (and staying that way) when another Claude Code process was refreshing the plugin marketplace at the same moment
- Fixed selecting text in an opened background session inside tmux over SSH: it now copies to the tmux buffer like a foreground session instead of falling back to OSC 52
- Fixed SDK and cloud sessions hanging indefinitely when an SDK MCP server's handshake acknowledgment was lost; the wait now times out after 70 seconds and marks only that server failed
- Fixed self-hosted runner leaving a stuck session's Bash tool processes running after the session was force-stopped
- Fixed `/usage-credits` for Team and Enterprise members whose admin set the org's usage-credit limit to $0: it now offers to ask the admin instead of saying a cap was reached
- Fixed `--worktree --tmux` with a merge-request number on a gitlab.com origin trying a doomed GitHub-style fetch first instead of fetching the GitLab ref directly
- Fixed Ctrl+G failing with "Emacs quit unexpectedly" in background sessions for editors that open `/dev/tty`, such as `emacs -nw` and `micro`
- Fixed an `additionalDirectories` entry containing a null byte crashing startup, or breaking `/add-dir` and later settings updates when it came from an SDK host, IDE, or hook; it is now skipped
- Fixed the MCP server menu's copy shortcut: it now says how the sign-in URL was copied instead of always claiming success
- Fixed italic text (such as the session recap line) rendering as highlighted blocks in GNU screen and in tmux sessions using a `screen` terminal type
- Fixed `claude mcp add --header` and `claude mcp add-json` help text naming the wrong transports
-
本文由 daily-intake-evening 流水线于 2026-08-29 归档;摘录为原文节选,全文见原文链接。