Follow Discord
Sweep 08 Oct 2026 · 18:53Z Build v2.1.295 516 read Stable v2.1.286 Latest v2.1.295 Next v2.1.295 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.286 ·

Cloud sessions running commands on your computer get a hook sandbox, auto-mode notices and hook-rewrite rules

Remote tools gains a bubblewrap sandbox for project hooks, reasons for auto mode being off, and finer handling of hook input rewrites

Group of 3 You'll notice Internal Changes
JSON All of v2.1.286
You'll noticeTier: how much it should matter to you
5Useful: my rating, 1 to 5
5Signal: worth watching, 1 to 5
HooksArea: what it touches
Internal ChangesKind: in v2.1.286,
What probably matters to youSection of the release

Unclear It is unclear whether anything beyond the log message changes, such as the classifier's earlier answer being kept.

What

Remote tools let a Claude Code cloud session run commands on your own computer. This release changes how such commands are approved and how project hooks run. A hook is a command your project sets up to run automatically at certain points.

  • Project hooks can run inside a bubblewrap (bwrap) sandbox, a walled-off area that limits what a program can see or do. It cuts the hook off from the network and other processes, gives read-only access to system folders, hides home folders, and applies extra limits through /run/claude-hook/apply-seccomp.
  • The sandbox is tried once first. If it cannot be used, Claude Code logs "[remote-tools] a project hook cannot be run in a sandbox on this machine" with a reason such as bubblewrap_too_old (version 0.10.0 or later needed), no_bubblewrap, no_seccomp_stage, bubblewrap_failed, home_in_view or credentials_in_view.
  • On Linux this requires the server-controlled switch tengu_violin_heel to be true, not set as a local override, plus a further check. macOS does not use that switch. A second switch, tengu_violin_saddle, guards the path used when sandboxing or a proxy is active.
  • New messages explain why auto mode (Claude acting without asking each time) is off for unattended commands from cloud sessions: consent not given, declined or unreadable; turned off by remoteTools.allowUnattendedServing or disableAutoMode; or a built-in safety cut-off.
  • When a hook rewrites the input of a request that asked for approval, the rewrite is now classed as none, own_hooks_alone or unvouched. The message says the classifier answer was set aside only for unvouched rewrites. Before, it always said both the earlier answer and the classifier were set aside.

Why

You now see why a cloud session is asking for approval on your machine. The most recent reading of tengu_violin_heel, taken before this release, was on for this site's account and the anonymous baseline. If the sandbox is in use, a Linux project hook that needs the network may fail.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is unclear whether anything beyond the log message changes, such as the classifier's earlier answer being kept.

See this entry in the whole of v2.1.286 →

Feedback