release aidev BREAKING SIG 3/5

Claude Code 2.1.205: transcript-tampering block, Windows worktree data-loss fix

Adds an auto mode rule blocking tampering with session transcript files and hardens background task notifications against fabricated in-transcript approvals. Also fixes a Windows bug where removing a worktree deleted files outside it through an NTFS junction or directory symlink, and reserves the "Claude Browser" MCP server name so user configs can no longer register under it.

PUBLISHED2026-07-08
OBSERVED2026-08-11
AGE1mo
SOURCES1
  • New auto mode rule blocks tampering with session transcript files
  • Background task notifications now explicitly state that no human input has occurred, preventing fabricated in-transcript approvals from being acted on
  • Auto mode now asks before running rm -rf on a variable it can't resolve from context
  • Fixed Windows worktree removal deleting files outside the worktree when an NTFS junction or directory symlink existed inside it
  • Reserved the "Claude Browser" MCP server name (alongside "Claude Preview"); user-configured MCP servers can no longer register under either name
  • Fixed --json-schema silently producing unstructured output on an invalid schema, and schemas using format being rejected
  • Fixed a message sent mid-turn being silently lost when the turn ended at the --max-turns limit
  • Fixed subagents resumed with SendMessage still showing "failed"/"completed"; jobs flipping from "needs input" back to "working"; claude attach erroring during a mid-upgrade restart
  • Fixed session-to-PR linking missing a PR created in a Bash call whose output exceeded the 30K inline limit
  • Fixed claude mcp add-from-claude-desktop sticking on unsupported characters in a server name; a plugin LSP server failing to initialize blocking another plugin's valid server for the same extension
  • Fixed Windows crash when the launch directory is deleted/locked/unmounted mid-command; crash when a file watcher closed during an in-flight directory scan
  • Auto-update downloads stream to disk instead of buffering, cutting updater peak memory by ~400 MB
  • Agent view rows now show a colored state word and a classifier-written headline instead of raw tool call text; sessions that edit/merge/comment/push to an existing PR link it
  • /doctor is now a full setup checkup that can diagnose and fix issues; /checkup is an alias
  • Fixed Cowork VM-mode local-agent sessions failing to start with "Not logged in · Please run /login" on CLI 2.1.203+

COMMUNITY

No curated reactions recorded for this event. Facts and takes are kept in separate layers — community context is added by hand, never blended into the record above.