Massive stability pass fixes CPU-pinning idle hangs, WebFetch freezes, and MCP secret leaks — plus a breaking change restricting task-tracking tools to specific models.
pricing: set in gateway.yaml, signed-in Claude Code clients receive the same rates through managed settings, so /cost and telemetry match the spend meteraccess_control.allow_cidrs is empty, and a one-time warning the first time a request arrives from a public addressgatewayInternalNetworks managed setting, letting administrators allow /login to a Claude apps gateway on their organization's own public IPv4 blockclaude self-hosted-runner --remove-session-state (default off): delete each session's per-session directories under <base-dir>/_sessions/ when the session endsconfigDirectory to the output of claude auth status --json--json to claude plugin install, uninstall, update, enable and disable, and errorDetails/noteDetails to each row of claude plugin list --json--continue / --resume: the conversation appears immediately instead of waiting for SessionStart hooks, and the first message no longer re-reads the whole transcript.claude/workflows/ scripts: listing them no longer parses each script/diff selection now shows inside the prompt input, and fullscreen mode shows Remote Control status in the header instead of the footer/plugin: installing, enabling or disabling a plugin now takes effect when you close the menu; /reload-plugins is no longer needed afterwardsANTHROPIC_BASE_URL) since 2.1.265: a regex in the Artifact tool's input schema that those endpoints rejectCLAUDE_CODE_WEBFETCH_DEADLINE_MS to override the deadline (0 turns it off)/etc, /tmp, /var on macOS; /bin on Linux) not applying when a path was given by its real location, and Bash commands ignoring deny rules written on a symlinked path spellingenv -C, eval or similar command the permission checker cannot analyze was on the same line/mcp and /plugin server details, claude mcp list/get, and MCP login errors showing secrets resolved from ${VAR} placeholders in MCP configsexcludeDynamicSections: the first message is no longer re-rendered each request401 … jti reused/compact and auto-compact mangling text that contained $ sequences/compact: its restored-file notes now load in the same order on every resume/rename sending the conversation from before a compaction@ file and / command suggestions not appearing after recalling a previous prompt with the up arrow and editing itclaude agents: pressing ← again at a natural pace to go back to the agent list no longer gets ignored until you pause for over a secondclaude agents session delete getting stuck when a worktree can't be removed: the message names the cause and next step, and for a git worktree ctrl+x again deletes the directory anyway/bug and /feedback description field showing no cursor when the terminal's native cursor is enabledclaude remote-control showing a generated name instead of their session title in ListAgentsclaude plugin validate rejecting plugin paths whose directory name begins with two dots, which the plugin loader accepts--print mode-p) runs/resume listing a /fork background session under its parent's name instead of its own ⑂ fork name/remote-control and other claude.ai-gated commands to suggest /login when signed out instead of showing a Claude for Enterprise migration messageCLAUDE_CODE_SESSIONEND_HOOKS_TIMEOUT_MS not extending SessionEnd hooks that have no per-hook timeout (they were still cancelled after 1.5 seconds)/autofix-pr and other cloud-session commands saying to retry or install the Claude GitHub App when no GitHub account is connected; they now point to /web-setup or the web connect page/teleport and /remote-env to explain when an organization policy turns them off, instead of answering "Unknown command"CLAUDE_CONFIG_DIR is set in a settings file or the environmentVariables setting~/.claude/settings.jsonclaudeCode.preferredLocation: "sidebar" (it always opened a panel), and programmatic opens resetting that setting to "panel"CLAUDE_CONFIG_DIR is set through settingsCLAUDE_CODE_ENABLE_TODO_TOOLS=1 elsewhereWebFetch deny and ask rules to no longer apply to Artifact tool reads and updates; use an Artifact rule (or WebFetch(domain:claude.ai)) to block or gate them@Claude !restart in a thread with its own session sometimes also posting a contradictory "this thread is handled by the channel session" notice