
Claude Code v2.1.296 Major Updates - Added autoCompactWindow for Sub-agents and allow_large for Read
This page has been translated by machine translation. View original
This is Ishikawa from the Cloud Business Division. Claude Code v2.1.296 (released 2026-10-09) has been released. This article organizes the changes by type and introduces the results of actually testing allow_large with Opus 5.5 and Haiku 5.5 as the highlight of this release.
The previous update article is here.
Update Summary
v2.1.296 includes 79 changes. The breakdown is: 47 fixes, 8 security, 7 new features, 7 improvements, 5 developer experience, 3 breaking changes, and 2 performance. In addition to new configuration options for subagents and workflows, many fixes related to hooks and permission checks are included. There are also changes outside the CLI, including VS Code extension (5) and Claude Tag (7).
Highlight Updates
autoCompactWindow for Subagents (New Feature)
You can now specify autoCompactWindow in subagent frontmatter and --agents definitions. This allows subagents to auto-compact earlier than the main conversation window.
The same autoCompactWindow setting already exists for the main conversation, specified as a token count like "autoCompactWindow": 200000. The format of the value specified in subagent frontmatter is not yet documented in the official documentation at the time of writing (2026-10-10).
If you use investigation-type subagents to read large amounts of files or logs, it may be worth trying the setting to auto-compact only the subagents earlier than the main conversation.
CLAUDE_CODE_WORKFLOW_SUBAGENT_MODEL (New Feature)
Setting the environment variable CLAUDE_CODE_WORKFLOW_SUBAGENT_MODEL allows you to run all workflow agents with a single model. Non-workflow subagents continue to run with the model configured for each of them.
This makes it easier to use a different model exclusively for workflow agents while leaving the settings for regular subagents unchanged.
allow_large for the Read Tool (New Feature)
An allow_large option has been added to the Read tool. When the entire file is needed and there is sufficient context, it allows reading text files exceeding the normal size limit in a single call. The behavior is verified for both Opus 5.5 and Haiku 5.5 in the "Testing allow_large for Read" section below.
This should reduce the number of Read calls when you need to review large logs or generated files in their entirety.
Bug Fix for Edit / NotebookEdit on Non-UTF-8 Files (Bug Fix)
A bug where editing files that are not valid UTF-8 (Windows-1252, Shift-JIS, GBK) with Edit or NotebookEdit would replace all non-ASCII characters in the file has been fixed. Going forward, edits to such files will be rejected. The before and after are summarized in the "Breaking Changes" section.
We expect situations where Edit is rejected to arise in Japanese projects where Shift-JIS files remain.
Fix for Permission Check Bypass via BASH_ARGV0 (Security)
Bash permission checks were automatically approving some commands that assign to the BASH_ARGV0 shell variable and then use it. After the fix, these commands will prompt for approval.
For those using Claude Code with permission confirmation in mind, this feels like a fix to update to promptly.
Fix for Secret Masking Gaps (Security)
In shared transcripts and debug logs, some values following keys with no values were not being masked, including JSON written inside shell strings. The fix extends masking coverage to include these cases.
This feels like a particularly relevant fix for those who share transcripts or pass debug logs internally or externally.
Update Details
New Features
autoCompactWindowhas been added to subagent frontmatter and--agentsdefinitions. This allows subagents to auto-compact earlier than the main conversation window.- The environment variable
CLAUDE_CODE_WORKFLOW_SUBAGENT_MODELhas been added. This allows you to run all workflow agents with a single model while leaving the models of other subagents unchanged. - An
allow_largeoption has been added to the Read tool. When the entire file is needed and there is sufficient context, it allows reading text files exceeding the normal size limit in a single call. - The environment variable
CLAUDE_CODE_OVERLOADED_RETRY_MAX_DELAY_MShas been added. This allows you to set a longer maximum backoff delay when retrying requests that result in overload (529) errors. - A
codekey has been added tomanaged.policies[]in Claude apps gateway. This applies the same settings asclito the Code tab in Claude Desktop, and when listed alongsidedesktop, it enables gateway mode for Claude Desktop. - [Cloud sessions] Status filters have been added to the Sessions and Runners lists in the Activity tab of self-hosted environment management settings. Multiple statuses can be selected simultaneously.
- [Claude Tag] Members with Claude Tag Admin permissions can now create, edit, and delete workspace and channel memory files in the Memory tab of the Activity page.
Improvements
- The default maximum length for MCP tool descriptions and MCP server instructions sent in advance has been changed from 2,048 characters to 4,096 characters.
- Cost calculations for
/cost, the status line,--max-budget-usd, and the SDK now calculate Sonnet 5.5 cache reads at $0.10 per million tokens (previously $0.20). - The
--debugoutput for hooks has been improved. Command hooks for tool calls, prompts, SessionStart, and Stop now log the command, plugin, result, and duration upon completion, making it easier to identify slow hooks. --debugoutput now identifies unrecognized frontmatter fields in custom agent files by name and displays hints if there may be a typo.- Syntax-highlighted code blocks are now cached, improving the responsiveness of transcript switching (ctrl+o) in conversations with a lot of code.
CLAUDE_CODE_TRANSCRIPT_LOCAL_GCno longer rewrites large transcript files when less than 10% of space can be freed.- A note is now displayed in
/pluginfor plugins whose hooks are excluded because a different plugin with the same name is enabled. - In auto mode, tool calls that were not executed because a valid checked response could not be obtained are now displayed as faint "Not run" lines instead of red errors.
- In full-screen mode, links under the mouse pointer are now underlined.
- In the Code tab of Claude Desktop under Claude apps gateway, when a session cannot be started (including machines that do not support the gateway
codesetting), the reason is now returned as a reply. - Errors when a cloud session is rejected now show the reason the organization's policy could not be loaded and any API keys or auth tokens overriding the claude.ai login.
- The bundled dataviz skill has been updated (the 7th series in light mode to bright purple, primary text in dark mode to softer colors, and y-axis labels to abbreviated notation like 1K).
- [Claude Tag] In Claude in Slack, the footer containing the session link, model, and cost is now displayed only on the latest reply within a thread.
- [Code Review] In Code Review management settings, specific reasons why settings could not be saved (such as policy restrictions) are now shown instead of a generic failure message.
Security
- Fixed automatic approval via BASH_ARGV0 in Bash permission checks: Some commands that assigned to the
BASH_ARGV0shell variable and then used it were being automatically approved. These now prompt for approval. - Fixed secret masking gaps: In shared transcripts and debug logs, some values following keys with no values (including JSON written inside shell strings) were not being masked.
- Fixed auto mode checks being skipped in cloud sessions: When feature flags were not loaded, auto mode checks for Claude in Chrome actions permitted by saved permissions were being skipped.
- Fixed rm -rf not prompting in bypass permissions mode on Windows:
rm -rf /c/Users/<name>in Git Bash was not prompting for confirmation in bypass permissions mode. - Fixed disabled MCP servers starting in headless sessions: After changing directories or reloading plugins,
.mcp.jsonor plugin MCP servers that had been disabled in that folder were starting up. - Fixed pre-check prompts passing through when interrupted during UserPromptSubmit hook execution: Pressing Esc or interrupting during
UserPromptSubmithooks or modprompt.submithooks could cause headless sessions to terminate, entered prompts to disappear, or prompts that had not gone through checks to pass through as-is. - Fixed turns not ending when rejected by managed settings hooks: When a managed settings
PreToolUsehook rejected a tool call with"continue": false, or when a managedprompthook blocked, the call was rejected but the turn was not ending. - Fixed updatedMCPToolOutput not being applied in managed settings PostToolUse hooks:
updatedMCPToolOutputwas not being applied in some sessions.
Fixes
- Fixed regression where Claude apps gateway sign-in was being ignored: On machines with
forceLoginMethodset togatewayin managed settings and noforceLoginGatewayUrlspecified, saved sign-ins were being ignored (regression in 2.1.295). - Fixed token counting for adaptive thinking-only models: For models that only support adaptive thinking, such as Haiku 5.5, counting was failing through some gateways and being calculated as budget thinking through others.
- Fixed incorrect rejection notification to resumed subagents: Tool calls interrupted by session termination were being reported to resumed subagents as "rejected by user."
- Fixed CLAUDE_CODE_RESUME_INTERRUPTED_TURN re-executing completed turns: When a turn had ended with an MCP tool result, the completed turn was being re-executed after restart.
- Fixed double execution of prompts immediately after ←: When background service responses were slow, prompts sent immediately after
←were being executed twice (once invisibly in the foreground). - Fixed Workflow tool rejecting scripts with CRLF line endings: The Workflow tool was rejecting script files with CRLF line endings, such as files checked out on Windows.
- Fixed long PowerShell commands always prompting for confirmation on Windows: PowerShell commands exceeding approximately 1 KB were always prompting for permission. Permission rules and read-only determination now apply up to 32 KB.
- A subtly welcome fix: An issue where toasts and notifications would wait without being displayed while the
/diffpanel or dialog was open has been fixed. It's subtly nice to no longer miss notifications while reviewing diffs. - In addition, numerous minor bugs have been fixed in plugins and mods, cloud sessions and self-hosted runners, Claude Tag and Code Review, the VS Code extension, Windows environments, and more.
Breaking Changes / Deprecations
There are no deprecations this time. There are 3 changes with behavioral differences. The before/after examples below are explanatory examples based on the CHANGELOG descriptions.
Edit / NotebookEdit Now Rejects Editing Non-UTF-8 Files
As a result of fixing a bug where Edit and NotebookEdit would replace all non-ASCII characters in files that are not valid UTF-8 (Windows-1252, Shift-JIS, GBK), edits to such files are now rejected. The filename legacy.c in the example is for illustrative purposes.
Before (up to v2.1.295):
Example: Editing legacy.c saved in Shift-JIS using the Edit tool in Claude Code
Edit → The edit is executed
However, all non-ASCII characters in legacy.c (such as Japanese comments) are replaced
After (v2.1.296 and later):
Example: Editing legacy.c saved in Shift-JIS using the Edit tool in Claude Code
Edit → The edit is rejected
Turns Started While Moving to Background via ← Are Now Stopped
Turns and ! commands started while a session is moving to the background are now stopped instead of continuing to run invisibly to completion.
Before (up to v2.1.295):
- A turn or ! command is started while the session is moving to the background
(during the operation of moving to the background with ←) - That turn / ! command runs to completion invisibly in the background
After (v2.1.296 and later):
- A turn or ! command is started while the session is moving to the background
(during the operation of moving to the background with ←) - That turn / ! command is stopped
[VSCode] Claude in Chrome Now Prompts for Confirmation Before Browser Operations in All Sessions
Claude in Chrome in the VS Code extension now prompts for confirmation before browser operations in all sessions, including sessions connected via @browser, in the same way as terminals. If you allow the site during the session, subsequent confirmations will not appear.
Before (up to v2.1.295):
In some sessions, such as those connected via @browser, confirmation before browser operations might not be requested
After (v2.1.296 and later):
In all sessions (including those connected via @browser), confirmation is requested before browser operations
If you allow the site during the session, subsequent confirmations will not appear
Testing allow_large for Read
In Claude Code v2.1.296, an allow_large option has been added to the Read tool. The CHANGELOG describes it as an option that allows reading text files exceeding the normal size limit in a single call when the entire file is needed and there is sufficient context.
According to the official documentation, when Read attempts to read an entire file and the token limit is exceeded, it returns only the first page. In this hands-on, we prepare a text file larger than the limit and verify how the number of lines returned by Read changes with and without allow_large using claude -p.
- Without
allow_large, a 3,000-line file is truncated partway through - When told "the entire file is needed," Claude specifies
allow_large: trueand reads all lines in a single call
Step 1: Create a Working Directory
Create an empty directory for verification files and results, then move into it. All subsequent steps are executed in this directory.
% mkdir allow-large
% cd allow-large
Step 2: Create a Verification File
Create a text file big.txt with 3,000 lines of 68 bytes per line. Also verify the line count, byte count, and the first and last lines.
% seq -f "line %05g: The quick brown fox jumps over the lazy dog. 0123456789" 1 3000 > big.txt
% wc -l -c big.txt
3000 204000 big.txt
% head -n 2 big.txt
line 00001: The quick brown fox jumps over the lazy dog. 0123456789
line 00002: The quick brown fox jumps over the lazy dog. 0123456789
% tail -n 1 big.txt
line 03000: The quick brown fox jumps over the lazy dog. 0123456789
Step 3: Prepare a jq Filter to Extract Results
Running claude -p with --output-format stream-json outputs messages during execution as one JSON per line. We prepare a filter filter.jq to extract only the necessary values from this output.
% cat > filter.jq <<'EOF'
if .type == "system" and .subtype == "init" then {claude_code_version, model}
elif .type == "assistant" then (.message.content[] | select(.type == "tool_use") | {tool: .name, allow_large: .input.allow_large})
elif .type == "user" then (.tool_use_result.file | {numLines, totalLines, truncatedByTokenCap})
elif .type == "result" then {subtype, num_turns, total_cost_usd}
else empty end
EOF
This filter extracts the following values for each message type.
| Message | Extracted values | Meaning |
|---|---|---|
system (init) |
claude_code_version, model |
The Claude Code version used and the model used |
assistant |
tool, allow_large |
The name of the tool called by Claude and the value of allow_large passed to Read |
user |
numLines, totalLines, truncatedByTokenCap |
Lines returned by Read, total lines in the file, whether truncated by the token limit |
result |
subtype, num_turns, total_cost_usd |
Type of termination, number of turns, cost (USD) |
Step 4: Read Without allow_large (Verification 1)
Instruct not to use allow_large and have Read read big.txt. Confirm the exit code of the claude command with echo "exit code: $?".
% claude -p --max-turns 1 --no-session-persistence --setting-sources project --strict-mcp-config \
--allowedTools Read --output-format stream-json --verbose \
"Please read big.txt with the Read tool. Do not use allow_large." > run1.jsonl
% echo "exit code: $?"
exit code: 1
The exit code is 1 because execution terminates upon reaching the turn limit specified by --max-turns 1. The Read tool itself is executed and the results are output to run1.jsonl.
The role of each option is as follows.
| Option | Role |
|---|---|
-p |
Run in non-interactive mode, output results, and exit |
--max-turns 1 |
Stop after 1 turn. Stops before returning the Read result to the model |
--no-session-persistence |
Do not save the session to disk (only valid with -p) |
--setting-sources project |
Load only project settings. Hooks from user settings (~/.claude/settings.json) are not loaded |
--strict-mcp-config |
Use only MCP servers specified with --mcp-config and ignore all other MCP settings. Since --mcp-config is not specified this time, no MCP servers are used |
--allowedTools Read |
Allow the Read tool to be used without confirmation |
--output-format stream-json |
Output messages during execution as one JSON per line |
--verbose |
Required when using stream-json with -p. Without it, execution terminates with Error: When using --print, --output-format=stream-json requires --verbose |
Extract the results of Verification 1 using the filter from Step 3.
% jq -c -f filter.jq run1.jsonl
{"claude_code_version":"2.1.296","model":"claude-opus-5-5"}
{"tool":"Read","allow_large":null}
{"numLines":732,"totalLines":3001,"truncatedByTokenCap":true}
{"subtype":"error_max_turns","num_turns":2,"total_cost_usd":0.0643468}
allow_largeis not included in the Read input (null).- Of the 3,001 total lines in the file, only 732 were returned.
truncatedByTokenCapistrue, indicating truncation by the token limit.
Also check the last 2 lines of the content returned by Read.
% jq -r 'select(.type == "user") | .message.content[] | select(.type == "tool_result") | .content' run1.jsonl | tail -n 2
731 line 00731: The quick brown fox jumps over the lazy dog. 0123456789
732 line 00732: The quick brown fox jumps over the lazy dog. 0123456789
It ends at line 732, and line 733 and beyond are not returned.
Step 5: Read After Telling It the Entire File Is Needed (Verification 2)
This time, without mentioning allow_large, we tell it that the entire file is needed. The options are the same as Step 4, with only the prompt and output filename being different.
% claude -p --max-turns 1 --no-session-persistence --setting-sources project --strict-mcp-config \
--allowedTools Read --output-format stream-json --verbose \
"The entire big.txt file is needed. Please read the entire file in a single Read call without omitting anything." > run2.jsonl
% echo "exit code: $?"
exit code: 1
As in Verification 1, the exit code is 1 because execution terminates upon reaching the turn limit.
% jq -c -f filter.jq run2.jsonl
{"claude_code_version":"2.1.296","model":"claude-opus-5-5"}
{"tool":"Read","allow_large":true}
{"numLines":3001,"totalLines":3001,"truncatedByTokenCap":null}
{"subtype":"error_max_turns","num_turns":2,"total_cost_usd":0.052076}
- Claude specified
allow_large: truein the Read input. - All 3,001 lines were returned, and
truncatedByTokenCapis not included (null).
Also check the last 2 lines.
jq -r 'select(.type == "user") | .message.content[] | select(.type == "tool_result") | .content' run2.jsonl | tail -n 2
Example output:
% jq -r 'select(.type == "user") | .message.content[] | select(.type == "tool_result") | .content' run2.jsonl | tail -n 2
3000 line 03000: The quick brown fox jumps over the lazy dog. 0123456789
3001
Lines up through line 3,000 are returned. While wc -l shows 3,000 lines, totalLines is 3,001 because Read displays the empty content after the final newline as a 3,001st line.
Step 6: Compare the Two Results
| Item | Verification 1 (without allow_large) | Verification 2 (instructed entire file needed) |
|---|---|---|
allow_large in Read input |
None (null) |
true |
Lines returned (numLines) |
732 | 3,001 |
Total lines in file (totalLines) |
3,001 | 3,001 |
truncatedByTokenCap |
true |
None (null) |
| Last line returned | Line 732 | Line 3,001 (empty line) |
Without allow_large, Read truncated the 3,001-line file at 732 lines. When told the entire file was needed, Claude specified allow_large: true and read all lines in a single Read call.
Supplement: Additional Verification with Opus 5.5 and Haiku 5.5
Here we compare the results of having Opus 5.5 and Haiku 5.5 each perform the Read operation in Claude Code v2.1.296. With Haiku 5.5 as well, the allow_large value, lines returned, and termination reason were the same as Opus 5.5, with the only difference in the items collected being cost.
Cost Comparison
| Verification | Opus 5.5 | Haiku 5.5 | Ratio (Opus 5.5 ÷ Haiku 5.5) |
|---|---|---|---|
| Verification 1 | 0.0643468 USD | 0.00186747 USD | Approx. 34.5x |
| Verification 2 | 0.052076 USD | 0.00142273 USD | Approx. 36.6x |
Within the same model, the cost of Verification 2 was lower than Verification 1.
- Opus 5.5: Verification 2 is 19.1% lower than Verification 1
- Haiku 5.5: Verification 2 is 23.8% lower than Verification 1
Even though Verification 2 returns more lines, the cost was lower for both models.
Under the conditions of this test, Claude specified allow_large: true on its own when told "the entire file is needed." When you want to have the entire file read, making that intent explicit in the prompt seems to be the basic approach. This update looks like it could effectively reduce costs when combined with subagent Haiku 5.5.
Closing Thoughts
The change making Edit / NotebookEdit unable to edit non-UTF-8 files such as Shift-JIS is something worth checking on in Japanese projects that handle such files. It would be good to decide in advance how to handle character encoding conversion and related matters.
Those dealing with non-UTF-8 files or using subagents and workflows might want to update and give it a try.
References
