Two versions on October 8: 2.1.294 at 03:42 UTC, 2.1.295 at 18:22 UTC. Both circle the same subject, and that isn’t a coincidence. After 2.1.293, this pair is about hooks that do what they claim.
The difference between “failed” and “let it through”
New in 2.1.295 is onFailure: "block" for command and HTTP hooks. A hook that can’t start, times out, or exits with an unexpected code now blocks the action instead of letting it through.
Until now the quiet default ran the other way, which matters to anyone using hooks as a guardrail. A guard that goes down wasn’t a guard.
The one real fix in 2.1.294 fits right next to it: prompt and agent hooks written as instructions, the “Block commands that…” kind, were allowing what they should have blocked. The same release improves how such instruction-style hooks are judged on Stop and SubagentStop, so Claude is less likely to quit early.
And a third finding in the same class, from 2.1.295: a mod’s hook was handed deeply nested tool input cut short, with no error raised. So a guard could pass content it never saw.
The terminal gets to know whether Claude is working
2.1.295 supports the Program Status Protocol over OSC 7501. Terminals that implement it can show whether Claude Code is working, waiting on you, or done. If you keep several sessions across several tabs, that’s the most practical small thing of the day.
More from the everyday pile: /copy can take the drafted message without its > markers, claude plugin install warns when the settings file it writes to doesn’t actually load, and claude -p prints on stderr what a run is waiting for when it stays open past its last turn. Mods get $.ui.notify for native notifications and can put children in a Button, so text and a chip sit in one pressable row.
The gateway gets limits and a paper trail
The larger block is the Claude apps gateway. Each upstream can now carry a models list, and only the listed models are sent there, failover included; a * in an entry is a wildcard. timeouts.upstream_ttfb_ms caps how long a stream may take to start on Bedrock, Vertex, Foundry and other upstreams before it fails over or returns a 502. The inference audit event now carries upstream_request_id, and successful responses carry a request-id header, so the request_id in telemetry lines up with the gateway’s audit log.
One fix lands squarely on enterprise setups: every request on a [1m] model was failing when a gateway, Bedrock, Vertex or Foundry refused the context-1m beta. Claude Code now resends without it.
Two releases, one thought
Security work in this project rarely looks like security work. Here it’s three lines about hooks that suddenly add up to one sentence. A guard that won’t start, a guard written as prose, and a guard that only sees half its input all produce the same outcome.
If you run hooks as policy rather than as convenience, don’t skip these two versions — and set onFailure while you’re in there, before the next timeout makes the call for you.