1
00:00:00,000 --> 00:00:01,280
Quick question before we start.

2
00:00:01,440 --> 00:00:06,400
When you set a rule that says Claude has
to ask before running rm,

3
00:00:06,540 --> 00:00:09,520
how sure are you that it actually asks?

4
00:00:09,808 --> 00:00:14,720
This is the Claude Code Changelog, brought
to you by Jellypod AI.

5
00:00:14,880 --> 00:00:15,600
I'm Lachlan.

6
00:00:15,625 --> 00:00:16,545
And I'm James.

7
00:00:16,578 --> 00:00:22,345
Today is version 2.1.289, which shipped on
October 3rd, and the headline is a set of

8
00:00:22,389 --> 00:00:23,545
permission fixes.

9
00:00:23,665 --> 00:00:27,625
The biggest one is for people running the
sandbox with auto allow turned on.

10
00:00:27,801 --> 00:00:31,945
Bash deny and ask rules could miss a
command if something sat in front of it.

11
00:00:32,098 --> 00:00:35,158
Spell out the exact cases, because it's
pretty specific.

12
00:00:36,918 --> 00:00:38,438
The changelog lists two.

13
00:00:39,198 --> 00:00:43,918
First, a command behind an environment
variable prefix with an expanded value.

14
00:00:44,358 --> 00:00:51,298
The example is TZ equals quote dollar HOME
quote, then rm

15
00:00:51,358 --> 00:00:54,298
with the recursive force flags, then
build.

16
00:00:55,378 --> 00:00:58,858
Second, a bare variable assignment sitting
before the command.

17
00:00:59,478 --> 00:01:05,198
In both cases, with sandbox auto allow on,
the deny or ask rule could be skipped.

18
00:01:05,250 --> 00:01:06,850
Here's why that matters in practice.

19
00:01:06,999 --> 00:01:11,090
Models love putting inline variables in
front of commands.

20
00:01:11,234 --> 00:01:17,090
NODE_ENV equals production, CI equals
true, PORT equals 8080.

21
00:01:17,277 --> 00:01:22,210
If you've written an ask rule for rm with
force flags, or for git push with force,

22
00:01:22,290 --> 00:01:24,850
you were counting on that rule as a hard
guardrail.

23
00:01:25,130 --> 00:01:30,770
A prefix in front shouldn't turn that
guardrail off, and in 2.1.289 it doesn't.

24
00:01:30,792 --> 00:01:32,432
So what do you do with this?

25
00:01:32,495 --> 00:01:37,112
Update first, then run claude with the
version flag to confirm you're on

26
00:01:37,192 --> 00:01:39,512
2.1.289.

27
00:01:39,656 --> 00:01:44,472
Then open your dot claude settings file,
and your settings local file too,

28
00:01:44,632 --> 00:01:47,112
and look at the ask and deny blocks.

29
00:01:47,219 --> 00:01:49,112
Those are the rules you were trusting.

30
00:01:49,125 --> 00:01:49,845
Then test it.

31
00:01:49,978 --> 00:01:54,885
In an interactive session with sandbox
auto allow on, put a harmless prefix in front

32
00:01:54,912 --> 00:01:56,005
of a rule you care about.

33
00:01:56,069 --> 00:02:01,045
Something like TEST_MODE equals 1 in front
of rm on a scratch temp folder.

34
00:02:01,205 --> 00:02:04,485
You should now get the confirmation prompt
instead of it just running.

35
00:02:04,672 --> 00:02:08,965
If it still runs silently, check your
version before you check anything else.

36
00:02:09,000 --> 00:02:12,440
Same release, same theme, three more
patches.

37
00:02:12,616 --> 00:02:16,840
Read deny rules now apply to files that
are at mentioned, changed,

38
00:02:16,893 --> 00:02:19,960
or selected in the IDE through a symlink.

39
00:02:20,067 --> 00:02:24,520
So if you've denied Read on dot env files
or your AWS folder,

40
00:02:24,680 --> 00:02:28,120
a symlink in the repo pointing at them is
no longer a side door.

41
00:02:28,125 --> 00:02:33,485
Second, on managed machines, a deny or ask
rule on a nested part of a compound shell

42
00:02:33,535 --> 00:02:38,605
command, think one command and then
another, now holds over a user installed mod's

43
00:02:38,658 --> 00:02:39,245
approval.

44
00:02:39,405 --> 00:02:44,285
And third, a user installed plugin can no
longer rewrite the descriptions of an

45
00:02:44,340 --> 00:02:47,565
organization managed MCP server's sign in
tools.

46
00:02:47,745 --> 00:02:52,365
All three are about the same thing, which
is who gets the final say over a rule.

47
00:02:52,375 --> 00:02:53,255
Now the caveat.

48
00:02:53,522 --> 00:02:58,615
If you, or a script you wrote, leaned on
inline variable prefixes to get commands

49
00:02:58,655 --> 00:03:02,775
through without prompts in sandbox mode,
that was relying on the gap.

50
00:03:02,935 --> 00:03:05,255
Expect prompts to show up now.

51
00:03:05,383 --> 00:03:06,935
That's the fix working.

52
00:03:07,148 --> 00:03:12,455
If a command really is safe, write an
explicit allow rule for it rather than hoping

53
00:03:12,495 --> 00:03:13,975
a prefix gets it past.

54
00:03:14,000 --> 00:03:20,240
This also builds on last episode, 2.1.288,
where path scoped rules and nested CLAUDE

55
00:03:20,280 --> 00:03:23,200
dot md files started loading on Write and
Edit.

56
00:03:23,300 --> 00:03:27,920
Between the two releases, the rules you
write are being applied in more places.

57
00:03:27,958 --> 00:03:32,518
Quick second topic, because it's useful if
you build mods or run agent teams.

58
00:03:33,078 --> 00:03:37,558
2.1.289 adds agent dot spawn for
teammates.

59
00:03:37,798 --> 00:03:42,678
In the mods reference, a hook on that
event fires when a subagent or a teammate is

60
00:03:42,718 --> 00:03:47,718
about to start, and for a teammate, e dot
isTeammate is true.

61
00:03:47,750 --> 00:03:51,030
So a mod can inspect the spawn request and
decide what to do.

62
00:03:51,230 --> 00:03:56,230
The brief we're working from says it can
override the model or return a deny with a

63
00:03:56,287 --> 00:03:59,430
reason, which is a way to put a ceiling on
how many teammates run.

64
00:03:59,606 --> 00:04:04,790
Also, there's now one agent id across
plugin hook events, so you can trace a single

65
00:04:04,857 --> 00:04:06,630
agent from start to stop.

66
00:04:06,730 --> 00:04:11,670
And in dollar dot agent dot list, you get
explicit idle and waiting states,

67
00:04:11,723 --> 00:04:14,870
so a status band can tell waiting on you
apart from idle.

68
00:04:14,875 --> 00:04:16,075
A few smaller wins.

69
00:04:16,235 --> 00:04:22,715
The VS Code extension reverted a 2.1.288
change to claude auth status that may have

70
00:04:22,763 --> 00:04:24,235
made sign outs more frequent.

71
00:04:24,455 --> 00:04:29,355
The terminal no longer freezes on short
code blocks with many unclosed script tags

72
00:04:29,542 --> 00:04:32,395
or deeply nested dollar brace
substitutions.

73
00:04:32,417 --> 00:04:37,617
And if a mod's ui dot render hook throws,
Claude Code now draws its own row instead

74
00:04:37,644 --> 00:04:40,497
of ending the session with an
unrecoverable interface error.

75
00:04:40,777 --> 00:04:44,657
A failing mod Client fails alone and
raises ui dot fault.

76
00:04:44,785 --> 00:04:50,097
Plus, plugin list, plugin eval, and plugin
update no longer show stale copies from

77
00:04:50,150 --> 00:04:54,897
local folder marketplaces, and hot reload
works again for a symlinked plugin dir.

78
00:04:54,917 --> 00:04:56,117
So the takeaway is simple.

79
00:04:56,243 --> 00:05:03,077
Update to 2.1.289, read your ask and deny
rules once, and run one prefixed

80
00:05:03,141 --> 00:05:03,957
test command.

81
00:05:04,090 --> 00:05:05,477
It takes about two minutes.

82
00:05:05,610 --> 00:05:06,917
Catch you next time.

