diff --git a/CHANGELOG.md b/CHANGELOG.md
index dccd1b049..835feec72 100644
--- a/CHANGELOG.md
+++ b/CHANGELOG.md
@@ -1,5 +1,48 @@
# Changelog
+## 2.1.216
+
+- Added `sandbox.filesystem.disabled` setting to skip filesystem isolation while keeping network egress control
+- Fixed a slowdown in long sessions where message normalization cost grew quadratically with the number of turns, causing multi-second stalls and slow resumes
+- Fixed auto mode denying commands with "HTTP 401" classifier errors after the OAuth token expired or rotated mid-session
+- Fixed AskUserQuestion telling Claude to continue even when your answer asked it to wait or explain first — free-text answers now get neutral wording
+- Fixed Claude Code on the web re-asking the same question and dropping your answer after the session sat idle for a few minutes
+- Fixed @-mentions silently attaching nothing after file-modifying hooks, vim dot-repeat of `c`-operators and paste, statusline running twice on resume, and resume-picker hangs on failure
+- Fixed resumed background agent sessions reverting to the default agent: the agent's prompt and tool restrictions are now restored
+- Fixed worktree-isolated subagents redirecting git into the shared checkout via `git -C`, `--git-dir`, or `GIT_DIR`/`GIT_WORK_TREE`
+- Fixed worktree sessions landing in another project's leftover worktree when the working directory did not match the selected project
+- Fixed background sessions whose worktree has no git repository being undeletable
+- Fixed `claude daemon stop --any` potentially terminating an unrelated process via a stale legacy daemon lockfile
+- Fixed Esc-Esc at an idle prompt not opening the rewind picker in long-running sessions with background tasks
+- Fixed Bash command permission checking for compound statements with redirects inside `&&` lists or negations
+- Fixed pressing Ctrl+X twice in the agent list failing to delete a session, and deleted sessions reappearing when their background worker had died
+- Fixed background subagents getting cancelled when a high-priority message arrives during their startup window
+- Fixed mouse and focus garbage in the terminal while a GUI editor from `/memory`, `/plan`, `/keybindings`, or Ctrl+G is open; `/memory` no longer waits for the editor to close
+- Fixed Claude-in-Chrome 403-looping on reconnect when the session's OAuth token lacks a required scope
+- Fixed workflow saves and scheduled-task writes following a symlink at `.claude`, which could redirect writes outside the project
+- Fixed MCP re-authenticate revoking working credentials before the new sign-in succeeds, and the reconnect needs-auth message in background sessions pointing at an unusable command
+- Fixed read-only commands on Windows accessing network paths without a permission prompt
+- Fixed Bash command parsing of non-ASCII characters to match real shell word boundaries
+- Fixed PowerShell tool permission validation of commands containing invisible Unicode characters
+- Fixed dialogs in fullscreen mode stretching past the right-hand edge of their panel
+- Fixed the `/config` settings list in fullscreen mode clipping its keyboard-hint footer
+- Fixed the transcript-mode (Ctrl+O) footer hint wrapping on terminals narrower than 104 columns
+- Fixed the Prometheus metrics endpoint (`OTEL_METRICS_EXPORTER=prometheus`) emitting invalid `# UNIT` lines
+- Fixed skills and commands changed during a session not appearing in the slash menu until restart
+- Fixed plugin skills with a `name` frontmatter field losing their plugin prefix in slash-command autocomplete
+- Fixed telemetry misreporting permission denials: failed permission-prompt requests no longer count as user rejections, and user interrupts are now reported as user aborts instead of rejections
+- Improved the `/fork` confirmation to one line with the new session's name, `claude attach` id, and a note when the copy shares your checkout
+- Improved validation of `git` and `gh` command arguments in the PowerShell tool
+- Improved the `/ultrareview` diff-too-large error to show configured limits, measured diff size, and largest contributing files
+- Improved `/code-review ultra` empty-diff message to name the exact base ref and suggest passing an explicit base
+- Improved the spend limit adjustment prompt to show the server's reason when a spend limit change is rejected
+- `/context` now shows an explicit warning when the conversation exceeds the context window, and a failed `/compact` displays as an error
+- `/rewind` no longer restores or deletes files through symlinks or hard links at tracked paths and reports how many paths it skipped
+- Background sessions: `/mcp` and `/install-github-app` now park a "needs input" request in the agent view when no client is attached
+- Updated the bundled dataviz skill: reordered the default chart palette and fixed guidance that suggested direct labels for four-series charts
+- [VSCode] Fixed right-to-left text (Arabic, Hebrew, Persian) rendering in the wrong order when mixed with English or code
+- Fixed cloud sessions dropping the in-flight message when the session's container restarts mid-turn — the interrupted turn now re-runs on resume instead of leaving the session unresponsive
+
## 2.1.215
- Claude no longer runs the `/verify` and `/code-review` skills on its own; invoke them with `/verify` or `/code-review` when you want them
diff --git a/feed.xml b/feed.xml
index efbec3615..5b91039a0 100644
--- a/feed.xml
+++ b/feed.xml
@@ -6,7 +6,53 @@
Anthropic
- 2026-07-19T02:55:54Z
+ 2026-07-20T22:13:53Z
+
+ https://github.com/anthropics/claude-code/releases/tag/v2.1.216
+ Claude Code v2.1.216
+
+ 2026-07-20T22:13:53Z
+ <p>• Added sandbox.filesystem.disabled setting to skip filesystem isolation while keeping network egress control</p>
+<p>• Fixed a slowdown in long sessions where message normalization cost grew quadratically with the number of turns, causing multi-second stalls and slow resumes</p>
+<p>• Fixed auto mode denying commands with "HTTP 401" classifier errors after the OAuth token expired or rotated mid-session</p>
+<p>• Fixed AskUserQuestion telling Claude to continue even when your answer asked it to wait or explain first — free-text answers now get neutral wording</p>
+<p>• Fixed Claude Code on the web re-asking the same question and dropping your answer after the session sat idle for a few minutes</p>
+<p>• Fixed @-mentions silently attaching nothing after file-modifying hooks, vim dot-repeat of c-operators and paste, statusline running twice on resume, and resume-picker hangs on failure</p>
+<p>• Fixed resumed background agent sessions reverting to the default agent: the agent's prompt and tool restrictions are now restored</p>
+<p>• Fixed worktree-isolated subagents redirecting git into the shared checkout via git -C, --git-dir, or GIT_DIR/GIT_WORK_TREE</p>
+<p>• Fixed worktree sessions landing in another project's leftover worktree when the working directory did not match the selected project</p>
+<p>• Fixed background sessions whose worktree has no git repository being undeletable</p>
+<p>• Fixed claude daemon stop --any potentially terminating an unrelated process via a stale legacy daemon lockfile</p>
+<p>• Fixed Esc-Esc at an idle prompt not opening the rewind picker in long-running sessions with background tasks</p>
+<p>• Fixed Bash command permission checking for compound statements with redirects inside && lists or negations</p>
+<p>• Fixed pressing Ctrl+X twice in the agent list failing to delete a session, and deleted sessions reappearing when their background worker had died</p>
+<p>• Fixed background subagents getting cancelled when a high-priority message arrives during their startup window</p>
+<p>• Fixed mouse and focus garbage in the terminal while a GUI editor from /memory, /plan, /keybindings, or Ctrl+G is open; /memory no longer waits for the editor to close</p>
+<p>• Fixed Claude-in-Chrome 403-looping on reconnect when the session's OAuth token lacks a required scope</p>
+<p>• Fixed workflow saves and scheduled-task writes following a symlink at .claude, which could redirect writes outside the project</p>
+<p>• Fixed MCP re-authenticate revoking working credentials before the new sign-in succeeds, and the reconnect needs-auth message in background sessions pointing at an unusable command</p>
+<p>• Fixed read-only commands on Windows accessing network paths without a permission prompt</p>
+<p>• Fixed Bash command parsing of non-ASCII characters to match real shell word boundaries</p>
+<p>• Fixed PowerShell tool permission validation of commands containing invisible Unicode characters</p>
+<p>• Fixed dialogs in fullscreen mode stretching past the right-hand edge of their panel</p>
+<p>• Fixed the /config settings list in fullscreen mode clipping its keyboard-hint footer</p>
+<p>• Fixed the transcript-mode (Ctrl+O) footer hint wrapping on terminals narrower than 104 columns</p>
+<p>• Fixed the Prometheus metrics endpoint (OTEL_METRICS_EXPORTER=prometheus) emitting invalid # UNIT lines</p>
+<p>• Fixed skills and commands changed during a session not appearing in the slash menu until restart</p>
+<p>• Fixed plugin skills with a name frontmatter field losing their plugin prefix in slash-command autocomplete</p>
+<p>• Fixed telemetry misreporting permission denials: failed permission-prompt requests no longer count as user rejections, and user interrupts are now reported as user aborts instead of rejections</p>
+<p>• Improved the /fork confirmation to one line with the new session's name, claude attach id, and a note when the copy shares your checkout</p>
+<p>• Improved validation of git and gh command arguments in the PowerShell tool</p>
+<p>• Improved the /ultrareview diff-too-large error to show configured limits, measured diff size, and largest contributing files</p>
+<p>• Improved /code-review ultra empty-diff message to name the exact base ref and suggest passing an explicit base</p>
+<p>• Improved the spend limit adjustment prompt to show the server's reason when a spend limit change is rejected</p>
+<p>• /context now shows an explicit warning when the conversation exceeds the context window, and a failed /compact displays as an error</p>
+<p>• /rewind no longer restores or deletes files through symlinks or hard links at tracked paths and reports how many paths it skipped</p>
+<p>• Background sessions: /mcp and /install-github-app now park a "needs input" request in the agent view when no client is attached</p>
+<p>• Updated the bundled dataviz skill: reordered the default chart palette and fixed guidance that suggested direct labels for four-series charts</p>
+<p>• [VSCode] Fixed right-to-left text (Arabic, Hebrew, Persian) rendering in the wrong order when mixed with English or code</p>
+<p>• Fixed cloud sessions dropping the in-flight message when the session's container restarts mid-turn — the interrupted turn now re-runs on resume instead of leaving the session unresponsive</p>
+ https://github.com/anthropics/claude-code/releases/tag/v2.1.215Claude Code v2.1.215
@@ -566,22 +612,4 @@
<p>• Remote Control is now disabled when ANTHROPIC_BASE_URL points at a non-Anthropic host, matching the existing behavior under CLAUDE_CODE_USE_BEDROCK/_VERTEX/_FOUNDRY</p>
<p>• Changed opening the agents view from a foreground session to require a single ← press instead of two, matching the behavior in background sessions</p>
-
- https://github.com/anthropics/claude-code/releases/tag/v2.1.195
- Claude Code v2.1.195
-
- 2026-06-26T21:29:36Z
- <p>• Added CLAUDE_CODE_DISABLE_MOUSE_CLICKS to disable mouse click/drag/hover in fullscreen mode while keeping wheel scroll</p>
-<p>• Fixed hook matchers with hyphenated identifiers (e.g. code-reviewer, mcp__brave-search) accidentally substring-matching — they now exact-match. Use mcp__brave-search__.* to match all tools from a hyphenated MCP server.</p>
-<p>• Fixed voice dictation on macOS capturing silence in long-running sessions after the default input device changes</p>
-<p>• Fixed voice dictation auto-submit never firing for languages written without spaces (Japanese, Chinese, Thai)</p>
-<p>• Fixed external plugins enabled only by project .claude/settings.json not requiring explicit install consent on every loader path</p>
-<p>• Fixed /plugin Enable/Disable not working when a plugin's plugin.json name differs from its marketplace entry name</p>
-<p>• Fixed background jobs disappearing from claude agents or losing data when written by a newer Claude Code version</p>
-<p>• Fixed reopening a crashed background task showing a blank screen for up to 5 seconds instead of its restart</p>
-<p>• Fixed background agent daemons running unreachable when the control socket fails to start, blocking restarts</p>
-<p>• Improved voice mode on Linux: now distinguishes "no microphone" from "SoX not installed" when SoX is present but no audio capture device exists</p>
-<p>• Improved claude agents completed list to fill available vertical space; on short terminals the header compacts so live sessions stay visible</p>
-<p>• Improved Remote session startup with a provisioning checklist while the container starts</p>
-