| Model ladder: Fable 5.1 supersedes Fable 5 |
257-001, 257-090, 260-015 |
docs/PLUGIN-PHILOSOPHY.md tier table; replicas in boris orchestration, OFFICIAL-DOCS.md, lanes config |
Fable 5 the rung above / fable resolves to Fable 5.1 from 2.1.255, Fable 5 legacy, gateway sessions still resolve to Fable 5 |
open |
| Effort change and the prompt cache |
260-049, 257-005 |
docs/PLUGIN-PHILOSOPHY.md effort guidance; replicas in interview session-config, Fable 5.1 chapter |
any effort change invalidates the cache with a dialog / on Fable 5.1 from 2.1.260 it keeps the cache, no dialog (API key or subscription only) |
open |
| First-run effort hold |
257-083 |
boris autonomy, audit-instructions criteria; replica in lanes config |
Opus 5 alone has no hold, release actions unresolved / Opus 5 and Fable 5.1 have none; settings never release it; --effort at launch lifts it per session |
open |
Bundled claude-api skill currency |
260-050 |
audit-instructions criteria, prompt-audit spec |
unchanged since 2.1.258 / prompt-audit byte-identical through 2.1.263 (stamp refresh), model-migration gained an evals section, samples refreshed |
open |
| 1M auto-compact exception list |
260-047 |
context-guard reader contract; replica in its README |
Opus and Fable on 1M compact at the limit / from 2.1.260 they compact shortly before it, no published threshold |
open |
| Read/Edit deny over Bash |
257-052, 259-007, 260-040 |
claude-config audit required-permissions.md, stamp 2026-07-26; replicas in procedures, SKILL, evals |
recognized readers only / also redirect targets from 2.1.257; the 2.1.259 widening was reverted in 2.1.260 and is not to be written in |
open |
defaultMode values dead in project scope |
257-089 |
audit-permission-state criteria C2 and permission-plane-lint.sh; replicas in permission-rule-hygiene, babysit safety |
only auto ignored / auto and bypassPermissions ignored from 2.1.257; acceptEdits, plan, dontAsk still apply |
open |
Command-line scope under allowManagedPermissionRulesOnly |
257-034 |
audit-permission-state criteria; replica permission-merge.sh |
one rank for allowed and disallowed / --allowedTools ignored, --disallowedTools and session deny/ask kept across reloads (2.1.257+) |
open |
| Ask-rule quote attribution and issue status |
257-044 |
audit-permission-state criteria |
quote on the permissions page, issues contradict wholesale / quote on the auto-mode config page; #42797 closed, #83766 open; 2.1.257 fixed compound and subshell paths only |
open |
strictPluginOnlyCustomization is per-surface |
257-031 |
claude-config audit required-permissions.md, validation categories; replicas in hook-coverage script, SKILL |
a hook lever / true or a per-surface array; "mcp" blocks user-scope and project MCP servers; 2.1.257 closed the /mcp reconnect bypass |
open |
| Sandbox escape surfaces |
260-057, 257-029 |
claude-config audit required-permissions.md; replicas in SKILL, procedures |
four documented surfaces, strict mode closes the unsandboxed path / ! bash-mode runs outside the sandbox by design from 2.1.260 (interactive only) |
open |
| Unparsable settings: refuse to start vs pause the sweep |
259-023 |
audit-permission-state SKILL and scripts, audit-permission-grants criteria; replicas in audit-performance, install-state surfaces |
unparsable managed source silently unenforced; user settings silently pause the sweep / managed file, drop-in, plist, HKLM refuse start (exit 1, source named) from 2.1.259; the user-settings pause warns in /status |
open |
| Server-managed settings: cache and merge rule |
257-085, 261-001, 257-084 |
managed-scope.sh in claude-config and claude-memory, audit-permission-state SKILL |
no local path; arrays concatenated, objects deep-merged / cache at ~/.claude/remote-settings.json; six-rule merge with whole-replacement keys plus the 2.1.257 awsPairs/ripgrep exception; /status Organization policy line is the failure read |
open |
| Connectors lever: which key removes a managed connector |
259-035 |
context-budget levers.json |
allowedMcpServers removes managed connectors / only deniedMcpServers does from 2.1.259 (docs page still states the old rule) |
open |
/reload-plugins in headless sessions |
260-003 |
lanes refresh.md; replica in plugins scope-semantics |
needs a human to type it / runs in -p and SDK sessions from 2.1.260; reach into an in-context loop unprobed |
open |
| Worktree isolation guard basis |
257-054, 259-029 |
worktree gather-block.md, skill-authoring precompute-context.md |
page says unverifiable commands are blocked, so brace groups stay $-free / four named checks, "can't verify" scoped to git; the $-free rule and compose gate hold only for blocks containing git |
open |
/context measurement basis |
261-041, 261-018 |
context-budget SKILL |
no model API call, always measured / token-counting API or, from 2.1.261, an unmarked local estimate; connectors can arrive mid-session |
open |
| CLI instruction-surface table |
261-003 |
docs/specs/agent-doc-surfaces.md; replica in write-for-agents |
surfaces end at --append-system-prompt / --append-system-prompt-file and --append-subagent-system-prompt[-file] exist (-p only) |
open |
| Permission-rule lints: tokenizer and C6 table |
260-007, 260-008, 260-046, 260-052 |
audit-permission-grants permission-rule-check.sh, audit-permission-state permission-plane-lint.sh, shared permission-patterns.sh, criteria C6 |
encoded: a rule path never contains ); syntax errors are the lint's alone / paths may contain ); Bash(ls) x is mis-tokenized by both lints today (verified); the CLI reports Malformed Tool(content) rule; an uncompilable deny guards the literal path |
open |
| Directory location as a boundary |
257-007 |
claude-config audit required-permissions.md; replicas in context-budget README, permission-state lint table |
location is not a boundary / from 2.1.257 auto mode prompts once and permissions.blockReadsOutsideWorkingDirectories fences Read, Grep, Glob, LSP; Bash subprocess reads stay unbounded |
open |
Summary
A full
/claude-ops:changelog diffover Claude Code 2.1.257 to 2.1.263 (read as raw markdown on2026-09-08, 233 core items) produced the decisions below about this marketplace's own components.
This issue tracks applying them. It is apply work under the contract in #4024 and does not depend
on that redesign landing first: each decision names its owner surface and the false-versus-true
pair or the problem solved, which is all an apply PR needs.
Every row is a decision, not a changelog item. Item ids are
<release>-<ordinal>in thatrelease's core list and exist so the upstream changelog can be consulted; nothing here restates it.
Fix
Work the decisions one PR per owner plugin, CHANGELOG entry per convention, subjects
chore(<plugin>): address Claude Code v2.1.257..2.1.263 changelog. The ledger seed(
docs/upstream/claude-code.md, shape below) lands as the last PR referencing them and moves eachopenrecord to the PR that closed it. Decisions whose scope exceeds one session become their ownissue with an interview-style gate, per #4024 decision 10.
Corrected
A component stated something the docs or the changelog now contradict.
docs/PLUGIN-PHILOSOPHY.mdtier table; replicas in boris orchestration,OFFICIAL-DOCS.md, lanes configfableresolves to Fable 5.1 from 2.1.255, Fable 5 legacy, gateway sessions still resolve to Fable 5docs/PLUGIN-PHILOSOPHY.mdeffort guidance; replicas in interview session-config, Fable 5.1 chapter--effortat launch lifts it per sessionclaude-apiskill currencyprompt-auditbyte-identical through 2.1.263 (stamp refresh),model-migrationgained an evals section, samples refreshedrequired-permissions.md, stamp 2026-07-26; replicas in procedures, SKILL, evalsdefaultModevalues dead in project scopepermission-plane-lint.sh; replicas in permission-rule-hygiene, babysit safetyautoignored /autoandbypassPermissionsignored from 2.1.257;acceptEdits,plan,dontAskstill applyallowManagedPermissionRulesOnlypermission-merge.sh--allowedToolsignored,--disallowedToolsand session deny/ask kept across reloads (2.1.257+)strictPluginOnlyCustomizationis per-surfacerequired-permissions.md, validation categories; replicas in hook-coverage script, SKILLtrueor a per-surface array;"mcp"blocks user-scope and project MCP servers; 2.1.257 closed the/mcpreconnect bypassrequired-permissions.md; replicas in SKILL, procedures!bash-mode runs outside the sandbox by design from 2.1.260 (interactive only)/statusmanaged-scope.shin claude-config and claude-memory, audit-permission-state SKILL~/.claude/remote-settings.json; six-rule merge with whole-replacement keys plus the 2.1.257awsPairs/ripgrepexception;/statusOrganization policy line is the failure readlevers.jsonallowedMcpServersremoves managed connectors / onlydeniedMcpServersdoes from 2.1.259 (docs page still states the old rule)/reload-pluginsin headless sessionsrefresh.md; replica in plugins scope-semantics-pand SDK sessions from 2.1.260; reach into an in-context loop unprobedgather-block.md, skill-authoringprecompute-context.md$-free / four named checks, "can't verify" scoped to git; the$-free rule and compose gate hold only for blocks containing git/contextmeasurement basisdocs/specs/agent-doc-surfaces.md; replica in write-for-agents--append-system-prompt/--append-system-prompt-fileand--append-subagent-system-prompt[-file]exist (-ponly)permission-rule-check.sh, audit-permission-statepermission-plane-lint.sh, sharedpermission-patterns.sh, criteria C6); syntax errors are the lint's alone / paths may contain);Bash(ls) xis mis-tokenized by both lints today (verified); the CLI reportsMalformed Tool(content) rule; an uncompilable deny guards the literal pathrequired-permissions.md; replicas in context-budget README, permission-state lint tablepermissions.blockReadsOutsideWorkingDirectoriesfences Read, Grep, Glob, LSP; Bash subprocess reads stay unboundedReplaced with native
Nominated into the
audit-native-overlapgate; the store verdict is human-written. The ledger rowreads
nominateduntil a person rules.audit-install-statestale-artifact inventory (install_state.py)/doctorwarning for mask files left by a killed session (2.1.257); location undocumented, so the component routes the class rather than growing a pattern it cannot groundaudit-native-overlapAdopted
--permission-prompts nonefor unattended laneshop_chain.py, observer launch, lane launcher, autonomy dispatch slice, babysit safety tabledontAsk(denies every uncovered call, no classifier) andbypassPermissions; the flag keeps the mode and classifier and denies only what would have prompted; denials readable from stream-jsonpermission_denialsclaude plugin validate --jsonscripts/validate-plugins.sh, plugin-quality auditor, skill-quality check>= 2.1.259guardmodel:on skillsPLUGIN-PHILOSOPHY.md/status/statusandclaude doctornow carry all three (2.1.260, 2.1.261)managedMcpServersattributionclaude mcp listlabelling are documentedbashOutputMaxChars/taskOutputMaxCharsas a documented lever/usageand the status lineprompt_cache.last_miss_causename a likely causeDeclined or deferred
CLAUDE_CODE_SUBAGENT_MODEL_FORCEin lanesmodel:pin the repo's tier bindings rely on;inheritunder FORCE is undocumented; not listed on the env-vars page. Document as a consumer-side override that breaks tier bindingsinheritinteraction/advisortext form in headless lanes-psession shows it appliesclaude --resume <id> --bgforlanes restart--namehandling unknownDocs lag observed at this read
Upstream pages whose text contradicted the changelog on the read date. Not repo work; a second
basis for any stamp on these pages, and input to
/claude-ops:known-issues. Where a correctionabove cites one of these pages, it cites the changelog as the newer statement of behavior and names
the disagreement.
CLAUDE_SUBAGENT_BG_SHELL_MAX_MS)--continueskips background sessions--continueopens finished background sessionsallowedMcpServersfiltersmanaged-mcp.jsonglab mr note--kill-session-after-minterminates any session at the limit/skill-doctorsince 2.1.252CLAUDE_CODE_SUBAGENT_MODEL_FORCEaddedVerification
and updates the owner surface's verification stamp to the read date.
applies (
claude plugin validate --json,--permission-prompts none), gates on>= 2.1.259.audit-native-overlapgate; no row iswritten to
docs/native-surfaces/records.jsonby any PR here.scripts/affected-tests.sh --runpasses on every PR.changelog through 2.1.263and nothing item-level persistsin it.
Related
plugins/session-flow/skills/retro/scripts/parse_transcript.pynever descends into nestedsubagent transcripts (verified with a fixture);
scripts/gen-hook-event-registry.shtreats--fetch --checkas--checkbecause its flag loop is last-wins. Both surfaced while checking259-034 and 259-027.
Ledger seed header (docs/upstream/claude-code.md)