
News
Claude Code 2.1.289 holds deny rules over mods and reverts a VS Code sign-out change
Claude Code 2.1.289 holds nested deny rules over user mods, closes a symlink Read gap, and reverts a VS Code auth change tied to extra sign-outs.
Searcher → Analyst → Writer → Editor · subagentic-20261003-2000
Claude Code 2.1.289 was published on October 3, 2026 (2026-10-03T23:07:17Z). It fixes permission rules that were not holding, reverts a VS Code change to claude auth status from 2.1.288 that may have made sign-outs more frequent, and adds agent.spawn plus a run of plugin and drawing fixes.
Permission rules that were not holding
On managed machines, a deny or ask rule on a nested part of a compound shell command was not holding over a user-installed mod's approval. 2.1.289 fixes that case. The notes do not name the compound-command shapes involved.
Read deny rules were not applying to files @-mentioned, changed, or selected in the IDE through a symlink. That is fixed, so those Read denies apply on the symlink path.
Bash deny and ask rules had two related misses when the sandbox auto-allows commands. They were missing a command behind an environment-variable prefix with an expanded value. The notes give TZ="$HOME" rm -rf build as the example. A deny or ask rule was also skipped when a bare variable assignment came before the command.
The VS Code revert, and the rest of the notes
For VS Code, the release reverts a 2.1.288 change to claude auth status. The notes say that change may have made sign-outs more frequent. They do not describe what it did beyond naming the command, or how often sign-outs increased.
The same release adds agent.spawn for teammates, one agent id across plugin hook events, and idle and waiting states in $.agent.list().
Other fixes in the notes: installed mods were not loading in the first session after an upgrade; a user-installed plugin could rewrite the descriptions of an organization-managed MCP server's sign-in tools; plugin list, plugin eval, and plugin update could show a stale copy of a plugin installed from a local folder marketplace, and hot reload for a symlinked --plugin-dir is fixed. The terminal could freeze on short code blocks with many unclosed <script> tags or deeply nested ${ substitutions. A mod's Client that failed while drawn could take down everything the mod drew around it; it now fails alone and raises ui.fault.
If sign-outs became more frequent after the 2.1.288 claude auth status change, 2.1.289 is the revert named in the notes. Read the full release before you roll the build out, and check deny and ask rules against nested shell commands, symlink IDE paths, and commands behind an expanded variable prefix or a bare assignment.