What
Claude Code's handling of compliance_taints (labels used to decide feature restrictions) was reworked:
- The function that merges incoming
compliance_taintsnow filters out taints that fail a new predicate before merging and truncating the combined list. - The restriction check (
fTt) now only appliescompliance_taintsfrom state when the session data actually came from a server fetch (sessionFromServerFetch); otherwise it falls back to locally hinted taints only. - The
hipaataint is now special-cased separately from other compliance taints, and is checked against server-populated feature restrictions rather than being folded in with generic hints.
Why
This avoids applying compliance restrictions based on stale or unverified local hints when authoritative server data isn't available yet, and gives HIPAA-specific restrictions more careful, server-backed handling than generic compliance taints.
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
What specific taints the new filter excludes, and why, is not stated in the evidence.