Claude Code

Claude Code 2.1.296: autoCompactWindow for subagents, and Edit refuses broken UTF-8

3 min read AI-generated

The Bash permission check was auto-approving commands that set BASH_ARGV0 and then use it. Now it asks.

Featured image for "Claude Code 2.1.296: autoCompactWindow for subagents, and Edit refuses broken UTF-8"

Claude Code 2.1.296 landed on npm on October 9 at 16:58 UTC. A big release, one day after 2.1.295 — and with three fixes that read more like holes than bugs.

Subagents can now compact on their own schedule

autoCompactWindow arrives in subagent frontmatter and in --agents definitions, letting a subagent auto-compact earlier than the main conversation’s window. Handy for agents that read a lot and return little: the main context stays clean while the subagent tidies up after itself.

Two new environment variables come with it. CLAUDE_CODE_WORKFLOW_SUBAGENT_MODEL pins every workflow agent to one model while other subagents keep theirs. And CLAUDE_CODE_OVERLOADED_RETRY_MAX_DELAY_MS raises the maximum backoff delay when a request comes back overloaded with a 529.

The Read tool gains an allow_large option, so Claude can read a text file past the usual size limits in one call when it needs the whole thing and the context has room.

Three holes that were open before

Bash first. The permission check was auto-approving commands that assign the shell variable BASH_ARGV0 and then use it — a way around your allow rules. It prompts now.

Hooks in managed settings second. A PreToolUse hook that denies a tool call with "continue": false refused the call but didn’t end the turn. Same for managed prompt hooks that block an input. If you use hooks as a central kill switch, you were relying on a stop that never came.

Third, secret redaction in shared transcripts and debug logs. It missed values that follow a key with no value, including inside JSON written in a shell string.

And a data-loss bug that isn’t security but stings just as much: Edit and NotebookEdit were replacing every non-ASCII character in files that aren’t valid UTF-8. Windows-1252, Shift-JIS, GBK. Those edits are now refused instead of applied.

Prices and limits

/cost, the status line, --max-budget-usd and the SDK’s cost figures now price Sonnet 5.5 cache reads at $0.10 per million tokens instead of $0.20. The cut itself shipped on October 7; the tooling just hadn’t caught up.

The cap on MCP tool descriptions and server instructions goes from 2,048 to 4,096 characters. And ← behaves differently: a turn or ! command that starts while the session moves to the background is now stopped rather than finishing out of sight.

What this release says about the hook wave

For weeks now, nearly every fix has pointed the same way: hooks, managed settings, gateways, permission checks. Three of the four notable fixes here sit in the machinery organisations use to fence Claude Code in — and in all three cases the fence didn’t hold, even though it was configured.

That’s the bill for a layer that grew very fast. If you run it in production, don’t read updates in this area as cosmetic.

Sources

Claude CodeReleaseSubagentsHooksSecurity