Refusal records now remember if any step of an episode was a cyber refusal, so restores re-arm protection.
What's wrong with this entry?
Refusal-fallback records persist a new saw_cyber_refusal field, also echoed in the SDK event stream. Its description says it is set when any hop of a banner's episode was a cyber refusal, not just the first, and that it exists so the CLI can re-arm its cyber-exclusion header when a session is restored.
- Marked internal and never rendered to the user; written whenever the condition holds, with no gate.
saw_cyber_refusal
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.242
Claude checks a checkout's git configuration before running git in it
Both mention safety
-
v2.1.242
Wider detection of tampered git directories
Both mention safety
-
v2.1.242
Claude Code's git commands no longer recurse into submodules
Both mention safety