Major stability pass fixing session-resume corruption, prompt-cache breaks, and Windows sandbox file-access failures, plus a big plugin-system security hardening pass.
user.email and user.groups to the telemetry Claude Desktop and Cowork send through a Claude apps gateway, matching terminal sessions--plugin-dir at a folder of plugins: each child folder with a manifest loads, and children added or removed while running are picked up--worktree startup on large repositories: the new worktree is now checked out in parallel (git 2.32+)/workflows agent detail: tool calls are marked running, failed or done, the subagent's task list is shown when it has one, and Enter unfolds the listed calls with their inputs and results/model opusplan[1m] being rejected with "Model not found"?, Erlang $, or Perl $ sigil--bg) sessions occasionally being retired mid-turn when a message arrived just before the idle timeout/add-dir <subdirectory> refusing to load a subdirectory's agents when managed settings lock only skills to plugins, and promising agents when only agents are lockedcontext: fork) not streaming their kickoff prompt and, with --forward-subagent-text, their text turns as progress events in stream-json/plugin with the error code/plugin Discover/Browse and claude plugin list --json --available showing no description or display name for marketplace plugins whose metadata lives only in their plugin.json/login showing "no gateway URL is configured" when re-run in a session that signed in to a Claude apps gateway set by managed settings/model claiming a model was "saved as your default" when the settings file couldn't be written; it now says the save failed and why/clear from Remote Control waiting on SessionStart hooks and on open terminal dialogs before completing/config dialog changing height when switching between its tabsclaude-api skill's error-code reference: model access failures return 404 and unavailable beta headers return 400, not 403-p with stream-json input, Agent SDK, cloud sessions) resetting the shell working directory at each new user message; a cd now persists across turnshttp that only speak the legacy HTTP+SSE transport never connecting; Claude Code now falls back to SSE as the MCP spec describes.claude folder permission option to say what it actually allows: editing files in the project's .claude folder (or ~/.claude) for the sessionforceLoginGatewayUrl in managed settings to be Claude apps gateway sessions from startup, like forceLoginMethod: "gateway"; a leftover claude.ai login or API key is not usedplugin.json on the Installed tab and claude plugin details, filling gaps from plugin.jsonOTEL_EXPORTER_OTLP_ENDPOINT, instead of through the gateway's relay; sessions without a named collector still use the relay