Claude Code 2.1.238: plugin headersHelper auth, self-hosted-runner proxy flags, long-session memory fix
A wide maintenance release: plugin marketplaces and MCP configs can now mint HTTP headers via a headersHelper command (gated behind folder trust and stripped of inherited credential env vars), self-hosted runners get graceful-shutdown and proxy-authorization options, and unbounded memory growth in long interactive sessions is fixed. Most of the rest is Remote Control and cross-session messaging reliability. Anyone relying on the Ctrl+L double-press /clear shortcut loses it.
PUBLISHED2026-08-20
OBSERVED2026-08-21
AGE5d
SOURCES1
New
keybindingFlavorsetting;"readline"makes Ctrl+W delete back to the previous whitespace (default"classic"unchanged)headersHelperon url marketplaces and catalog entries runs a command that mints HTTP headers (e.g. short-lived tokens) for catalog and same-origin archive fetches; a catalog entry's helper runs only on install/update, after the command is shown, with a[y/N]prompt (or-y)claude self-hosted-runner --defer-shutdown-max-min <minutes>: on SIGTERM keep serving attached sessions, park the rest after N minutes, then exitclaude self-hosted-runner --proxy-authorization-command/--proxy-authorization-filefor egress proxies needing a freshProxy-Authorizationper connection
Changed
- Ctrl+L / Cmd+K in fullscreen always just repaint; the double-press
/clearshortcut is removed (1-row nvim terminals no longer trigger/clearloops) claude mcp list/getshow disabled servers as⊘ Disabledinstead of health-checking themheadersHelperin a project.mcp.json, and inline MCP servers in project or--add-diragent files, require that folder's trust dialog to have been accepted — including underclaude -p- Project/plugin/agent-file
headersHelperruns without inherited credential env vars; user, managed and claude.ai-scope helpers run from the Claude config dir - Cross-session messaging surfaces refusals (
crossSessionInbound: "refuse") and dropped inboxes to the sender instead of reporting silent success - Bundled
claude-apiskill updated for the Managed Agents Aug 19 release (web search/fetch domain settings, memory stores on self-hosted sandboxes)
Fixed
- Unbounded memory growth in long sessions — subagent tool results released once out of the display window
- Custom/project/plugin output styles drifting back to the default voice mid-session
- stdio MCP servers getting
server/discoverbeforeinitialize, forcing lazy servers to boot every session - Self-hosted runners removed after a single slow or lost poll, handing a healthy session to another runner
- Leftover
/tmp/claude-*-cwdfiles after a killed, timed-out or interrupted Bash command - Worktree-isolation Bash refusals citing a redirect the command didn't have
- MCP elicitation dialogs blank for URLs over 4,096 chars; permission prompts dropping "don't ask again" on narrow terminals; diff text clipped on emoji/tab lines
- Held Backspace ignored on Ctrl+H terminals over slow SSH/mosh; suspended (Ctrl+Z) sessions leaving bracketed-paste on with a hidden cursor
- Proxy connection refusals reported as generic network errors
/modeland/effortcache-miss warning firing on an already-expired cacheCLAUDE_CODE_ENABLE_PROMPT_SUGGESTION=truenot holding when near but not over the usage limit- Remote Control: per-task Stop no-op on CLI-hosted sessions; exits on a message with no valid role; inherited session-scoped env vars via
claude remote-control; crashed sessions unavailable until restart; mid-turn web/Desktop messages vanishing from the transcript; phone/web model picks not reflected in the terminal; "login expired" on brief network hiccups; failed-reconnect report on sign-out ListAgents/SendMessage: "Remote Control is not connected" in server-mode and Desktop/IDE-hosted sessions; pre-warmed idle worker no longer exposed until a task claims it
Improved
- Faster bare
claudestartup on macOS; update check deferred ~10s after launch - Bash permission checking for zsh-specific conditional syntax
- Remote Control tolerates brief HTTP 403 refusals from an edge/VPN/proxy for up to 3 minutes, naming the blocker if it persists
COMMUNITY
No curated reactions recorded for this event. Facts and takes are kept in separate layers — community context is added by hand, never blended into the record above.