Claude Code v2.1.214 が権限チェック不具合を修正
本文の状態
日本語全文を表示中
詳細モードで約9分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
Claude Code Changelog
Claude Code v2.1.214 は、Windows PowerShell や Bash の権限チェックのバグ修正に加え、悪意あるユーザーへの対応ツールや Docker コマンドの認証強化など、セキュリティと安定性を大幅に改善した。
AI深層分析を開く2026年8月1日 03:59
AI深層分析
キーポイント
セキュリティ脆弱性の修正
Windows PowerShell 5.1 における権限チェックバイパスや、Bash のファイル記述子リダイレクト・長いコマンド・変数修飾子に関する誤判定を修正し、不正な実行を防ぐ。
Docker コマンドの認証強化
以前は自動承認されていた Docker および Podman のデーモンリダイレクトフラグを持つコマンドに対して、新たに権限プロンプトを表示するよう変更された。
悪意あるユーザーへの対応機能追加
Claude が極めて悪質または jailbreak 試行を行うユーザーとのセッションを終了できる「EndConversation」ツールが追加され、2025 年の claude.ai の機能を反映した。
安定性と監視機能の向上
GrowthBook のバグ修正やメモリ増大問題の解消に加え、OpenTelemetry ログへの追跡属性追加や長時間実行時の進捗ハートビート機能が導入された。
セッションコストとトークン計測の二重カウント修正
複数の累積 message_delta フレームを発行するストリームで、セッションコストとトークン計測が重複してカウントされる不具合を修正した。
重要な引用
Fixed a permission-check bypass affecting commands run in Windows PowerShell 5.1 sessions
Added the EndConversation tool: Claude can end sessions with highly abusive users or jailbreak attempts
Fixed Bash permission checks to no longer auto-approve certain help and man commands that could run unsafe options
Fixed stream-json output truncation at exit for slow-reading SDK/pipeline consumers; the exit drain now scales with queued bytes instead of a flat 2s cap
編集コメントを表示
編集コメント
今回のアップデートは、AI エージェントがローカル環境で動作する際のセキュリティリスクを軽減するための重要なパッチ群である。特に Docker コマンドの認証強化と PowerShell のバグ修正は、実務における信頼性を高める要素となる。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
変更点
- ディレクトリパスの
dir/**といった単一セグメントの許可ルールが、以前はツリー内のどこでも/dir配下への書き込みを自動承認していましたが、このバグを修正しました。これにより、指定されたディレクトリのみが正しく処理されるようになりました。 - Windows PowerShell 5.1 セッションで実行されるコマンドにおいて、権限チェックを回避する脆弱性を修正しました。
- Bash のパーミッションチェックにおいて、Bash が解析するファイル記述子リダイレクトの形式と、パーミッション解析エンジンが想定する形式との不一致により正しく判定されなかったケースを修正し、適切にブロックするようにしました。
- 10,000 文字を超える非常に長いコマンドに対して、以前は自動実行されていましたが、現在は必ず確認プロンプトを表示するように修正しました。
[[ ]]比較式内の zsh の変数サブスクリプトや修飾子を、Bash のパーミッションチェックが「無効なテキスト」として誤認していた問題を修正し、これらを含むコマンドは承認を促すプロンプトを表示するようになりました。- 安全でないオプションの指定、コマンド置換、バックスラッシュパスの使用が可能になる恐れのあるヘルプや man コマンドに対して、以前は自動承認されていましたが、現在は確認プロンプトを表示するように修正しました。
- リモートセッションにおける権限プロンプトが、ローカルの確認ダイアログが表示される前に処理が進んでしまう不具合を修正しました。
- 悪意のあるユーザーや脱獄(ジャイルブレイク)試行に対してセッションを終了できる「EndConversation」ツールを追加しました。これは 2025 年以降の claude.ai で実装されている機能と同様のものです。詳細は https://www.anthropic.com/research/end-subset-conversations をご覧ください。
- 以前は応答が途絶えていた長時間実行されるツールの呼び出しに対して、定期的な進捗状況を示す「ハートビート」機能を追加しました。
- メモリファイルのフロントマータに ISO 形式の更新タイムスタンプを追加しました。
- OpenTelemetry ログイベントに
message.uuid、client_request_id、tool_sourceの各属性を追加し、メッセージレベルでの相関付けとツールの出所追跡を可能にしました。
- OpenTelemetry のコンテンツ属性に対する 60 KB の切り捨て制限を設定できるよう、
CLAUDE_CODE_OTEL_CONTENT_MAX_LENGTHを追加しました。 - サブエージェントの状態ライン(subagentStatusLine)ペイロードに推論の努力度合い(reasoning effort)を追加し、カスタムエージェント行でモデルと努力度をレンダリングできるようにしました。
- 以前は許可プロンプトなしで実行されていた、デーモンリダイレクトフラグ(
--url,--connection,--identity、および Podman のリモートモード)を含む Docker コマンド(Podman の Docker シム含む)に対して、許可プロンプトを追加しました。 - GrowthBook の機能が null を評価した際のクラッシュと、不正なフラグペイロードがキャッシュされた機能フラグを消去してしまうバグを修正しました。
- Bash ツールで
pkill -fパターンが CLI プロセス自体に誤って一致した場合(Linux)、Claude セッションが終了する問題を修正しました。 --settingsオプションがデバイスファイルや数 GB のファイルを指した際にメモリが無制限に増大する問題を修正しました。2 MiB を超える設定ファイルは、起動時に明確なエラーメッセージとともに拒否されます。- 企業のプロキシ環境下にある Windows で、ストリーミングターンが「ソケットが閉じられています」というエラーで失敗する問題を修正しました。
- ストリーム JSON の出力が、読み込みが遅い SDK やパイプラインのコンシューマーに対して終了時に切り捨てられる問題を修正しました。終了時の排水処理を固定の 2 秒から、キューに残ったバイト数に応じて動的に調整するように変更しました。
- 予定されたタスクが設定されたプロンプトを信頼できない入力として拒否する問題を修正しました。実行されるプロンプトは、セッションに割り当てられたタスクとして直接提供されます。
- PowerShell ツールのコマンドで、子プロセスが標準入力を待機している場合にタイムアウトまで応答しない(ハングする)問題を修正しました(Windows)。
- Windows 環境において、PowerShell ツール経由で Python スクリプトを実行した際、標準入力から非 UTF-8 データを読み込もうとして UnicodeDecodeError でクラッシュする不具合を修正しました。
- 同じく Windows 環境で、PowerShell ツール経由の Python スクリプトが非 ASCII の出力を行う際に UnicodeEncodeError でクラッシュしたり、PowerShell 7 のエラーメッセージに生の ANSI エスケープシーケンスが含まれて表示される問題を修正しました。
- Windows 版 PowerShell ツールにおいて、where.exe、fc.exe、diff.exe が有効な否定応答(存在しない等)を返した際にも誤ってエラーとして報告されていた不具合を修正しました。
- Windows PowerShell 5.1 環境での PowerShell ツールにおける > や >> の処理で、UTF-8 として他のツールが読み込めない UTF-16LE 形式のファイルが作成される問題を修正しました。
- バックグラウンドデーモンがシャットダウン時に次世代の制御ソケットを誤って削除し、結果として次のクライアントが正常な代替デーモンを停止させてしまう不具合を修正しました。
- ← または /background でバックグラウンドセッションを一時停止し、アイドル状態のまま放置した場合に、バックグラウンドデーモンとワーカープロセスが無限に稼働し続ける問題を修正しました。
- バックグラウンドサービスがアイドル状態になった後、claude rm コマンドやエージェントビューから完了したバックグラウンドセッションを削除できなくなる不具合を修正しました。
- Git フォルダ以外から起動されたバックグラウンドセッションについて、エージェントビューから削除できない問題を修正しました。
- 停止したバックグラウンドセッションを再開する際、セッションストア内に読み込み不能なフォルダが存在すると、保存された会話履歴が復元されない不具合を修正しました。
- リモートコントロール機能が明示的に有効化されていないセッションに対して、「セッション準備完了」プッシュ通知が誤って送信される問題を修正しました。
- エージェントビューセッションでは /install-github-app コマンドや /mcp 設定メニューがブロックされていましたが、ターミナルを接続していないバックグラウンドセッションでのみ拒否されるようになりました。
- --settings CLI フラグで有効化したプラグインが読み込まれない不具合(v2.1.181 以降の回帰)を修正しました。
- OAuth トークンのローテーション後に、長時間実行中のセッション内で機能フラグが無効化され続ける問題を解消しました。
- マージベースが存在しないリポジトリで /ultrareview コマンドが実行できなくなっていたのを修正。現在は追跡されている全ファイルのレビューを提案するようになりました。
- シェル設定パスがディレクトリになっている場合、claude の更新やドクターコマンドが静かにフリーズしたり、/status システム診断セクションが空白になる不具合を修正しました。
- メモリファイル保存時に、インラインの # 記号で値が意図せず切り捨てられていた問題を修正しました。
- ストリーム内で複数の累積的な message_delta フレームが発信される際、セッションコストやトークン使用量の計測が二重カウントされていた不具合を修正しました。
- アドバイザーが思考中に表示されていた「ネットワークを確認してください」という誤った警告メッセージを削除しました。
- ハンドシェイクの標準出力 JSON がスキーマ検証に失敗した場合、終了コード 2 を返すフックが文書通りブロックされない不具合を修正しました。
- トーンの非同期コンテキスト外で OTel ログイベントが発行された際、インタラクションのスパンのトレースコンテキストが含まれていなかった問題を修正しました。
- プロンプトやリソースの更新時に発生する MCP の一時的なエラーにより、サーバーのスラッシュコマンドとリソースがすべて消去されてしまう不具合を修正しました。
- ホームディレクトリでの claude rc に関するワークスペース信頼エラーメッセージを改善。ホームディレクトリに信頼設定は保存されないことを明記し、プロジェクトディレクトリから実行するよう促すように変更しました。
dir/**フックの条件式を修正しました。これまでは単一セグメントでの一致のみでしたが、現在は/dirに限定されるようになりました。深さ不限定でマッチさせたい場合は、明示的に**/dir/**を記述してください。なお、権限拒否(deny)や確認(ask)ルールは、引き続き深さ不限定のマッチングを維持します。
-m/--magic-fileまたは-f/--files-fromオプションを使用するファイルコマンドについて、以前は読み取り専用として自動的に許可されていましたが、現在は明示的な権限が必要となりました。
- 接続プーリングの「keep-alive」機能を修正しました。ステール(古くなった)接続エラーが発生した際、プーリングを無効化し、再試行時に新しいソケットを開放するように変更しています。
SessionStartフックの動作を変更しました。セッションがフォークとして開始された場合、ソース情報を「resume」ではなく「fork」として報告するようになりました。
原文を表示
What's changed
- Fixed single-segment dir/ allow rules like Edit(src/) auto-approving writes to nested dir/ directories anywhere in the tree instead of only /dir
- Fixed a permission-check bypass affecting commands run in Windows PowerShell 5.1 sessions
- Fixed Bash permission checks to fail closed on file-descriptor redirect forms that bash parses differently than the permission analyzer
- Fixed Bash permission checks misjudging very long commands — commands over 10,000 characters now always prompt instead of running automatically
- Fixed Bash permission checks treating zsh variable subscripts and modifiers in [[ ]] comparisons as inert text — these commands now prompt for approval
- Fixed Bash permission checks to no longer auto-approve certain help and man commands that could run unsafe options, command substitutions, or backslash paths
- Fixed permission prompts on remote sessions that could proceed before the local confirmation dialog
- Added the EndConversation tool: Claude can end sessions with highly abusive users or jailbreak attempts, as on claude.ai since 2025 — see https://www.anthropic.com/research/end-subset-conversations
- Added a periodic progress heartbeat for long-running tool calls that previously went silent
- Added an ISO modified timestamp to memory file frontmatter
- Added message.uuid, client_request_id, and tool_source attributes to OpenTelemetry log events for message-level correlation and tool provenance
- Added CLAUDE_CODE_OTEL_CONTENT_MAX_LENGTH to configure the 60 KB truncation limit on OpenTelemetry content attributes
- Added reasoning effort to the subagentStatusLine payload, so custom agent rows can render model and effort
- Added permission prompts for docker commands (including the Podman docker shim) carrying daemon-redirect flags (--url, --connection, --identity, and Podman's remote mode) that previously ran without one
- Fixed a crash when a GrowthBook feature evaluates to null, and a bug where a malformed flag payload could wipe the cached feature flags
- Fixed Bash tool killing the Claude session when a pkill -f pattern accidentally matched the CLI's own process (Linux)
- Fixed unbounded memory growth when --settings points at a device file or multi-GB file; oversized (>2 MiB) settings files now fail at startup with a clear error
- Fixed streaming turns failing with "Socket is closed" behind corporate proxies on Windows
- Fixed stream-json output truncation at exit for slow-reading SDK/pipeline consumers; the exit drain now scales with queued bytes instead of a flat 2s cap
- Fixed scheduled tasks refusing their own configured prompt as untrusted input — the fired prompt is now delivered as the session's assigned task
- Fixed PowerShell tool commands hanging until timeout when a child process waited on standard input (Windows)
- Fixed Python scripts under the PowerShell tool crashing with UnicodeDecodeError when reading non-UTF-8 data from standard input (Windows)
- Fixed Python scripts run via the PowerShell tool crashing with UnicodeEncodeError on non-ASCII output, and PowerShell 7 error messages containing raw ANSI escape sequences (Windows)
- Fixed the PowerShell tool reporting where.exe, fc.exe, and diff.exe as errors when they return a valid negative answer (Windows)
- Fixed > and >> under the PowerShell tool on Windows PowerShell 5.1 writing UTF-16LE files that other tools couldn't read as UTF-8
- Fixed a displaced background daemon deleting its successor's control socket on shutdown, which made the next client kill the healthy replacement daemon
- Fixed background sessions parked with ← or /background and left idle keeping the background daemon and a worker process alive indefinitely
- Fixed completed background sessions being impossible to remove via claude rm or the agent view once the background service had gone idle
- Fixed background sessions dispatched from a non-git folder being impossible to delete from the agents view
- Fixed reopening a stopped background session failing to restore its saved conversation when an unreadable folder exists in the session store
- Fixed the Remote Control "session ready" push notification firing for sessions where Remote Control was not explicitly enabled
- Fixed /install-github-app and the /mcp settings menu being blocked in agent-view sessions — they're now refused only in background sessions with no terminal attached
- Fixed plugins enabled via the --settings CLI flag not loading (regression since v2.1.181)
- Fixed feature flags going stale in long-running sessions after the OAuth token rotates
- Fixed /ultrareview refusing to run in repos with no merge base — it now offers to review all tracked files
- Fixed claude update and claude doctor hanging silently, and the /status System diagnostics section going blank, when a shell-config path is a directory
- Fixed memory frontmatter values being silently truncated at an inline # when memory files are saved
- Fixed session cost and token telemetry double-counting on streams that emit multiple cumulative message_delta frames
- Fixed a spurious "check your network" warning that appeared while the advisor was thinking
- Fixed hooks with exit code 2 not blocking as documented when the hook's stdout JSON fails schema validation
- Fixed OTel log events emitted outside the turn's async context missing the interaction span's trace context
- Fixed MCP transient errors during prompts/resources refresh clearing the server's slash commands and resources
- Improved the claude rc workspace-trust error in the home directory to say trust there is never saved and to suggest running from a project directory
- Changed single-segment dir/ hook if: conditions to match only /dir; write /dir/** for any-depth matching. deny/ask permission rules keep their any-depth match.
- Changed file commands using -m/--magic-file or -f/--files-from to require permission instead of being auto-allowed as read-only
- Changed keep-alive connection pooling to disable after a stale-connection error, so retries open a fresh socket
- Changed SessionStart hooks to report source "fork" when a session begins as a fork instead of "resume"
AI算出
主要ニュースainew評価高い
Claude Code の具体的なバージョンアップによる権限チェック不具合の修正や、新しいセキュリティ機能の追加は、開発者にとって即座に実装・適用が必要な重要な技術情報であり、新規性と検索意図が極めて高い。ただし、これは Anthropic によるグローバルなツール更新であり、日本固有の規制や企業事例が含まれていないため、日本の関連性は標準的なレベルとなる。
6つの評価軸を見る
- AI関連度
- 100
- 情報源の信頼性
- 100
- 新規性
- 75
- 調べる価値
- 100
- 重複の少なさ
- 100
- 日本での有用性
- 25
関連記事
News to Guide
ニュースの次に確認する
発表内容を、現在の料金や仕様と照らし合わせられる関連ガイドです。
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み