Set CLAUDE_CODE_TOOL_MEMORY_LIMIT for Bash tool cgroups on Linux
Opt into Linux memory cgroups for Claude Code Bash tool commands so runaway builds cannot stall the session, and wire related v2.1.233 controls (identity forwarding, WebFetch cache TTL, GitLab MR worktrees) into daily agent workflows.Why this loop
v2.1.233 adds opt-in Linux memory cgroups for Bash tool commands via CLAUDE_CODE_TOOL_MEMORY_LIMIT so a runaway build cannot stall the session. The same release adds GitLab merge-request URLs on --worktree (shown as !N in claude agents), opt-in forward_user_identity on Anthropic apps-gateway upstreams (signed-in user identity as headers for per-user spend attribution), and CLAUDE_CODE_WEBFETCH_CACHE_TTL_MS for the WebFetch session URL cache (default still 15 minutes). Reliability fixes around permission-wait cloud sessions, MCP v2 listen-stream reopen loops, idle Linux 100% CPU with sandboxing, Notification hooks under Desktop/VS Code, and the Windows ??\ UNC bypass make these controls safer to enable. Todo/task tools (TaskCreate/Get/Update/List, TodoWrite) are off on Opus 4.8, Sonnet 5, Fable 5, Mythos 5, and newer unless CLAUDE_CODE_ENABLE_TODO_TOOLS=1.
Proposed actions
- On Linux Claude Code hosts, export CLAUDE_CODE_TOOL_MEMORY_LIMIT in the process environment (byte cap, e.g. 4294967296) so Bash tool commands run under a memory cgroup and a runaway build cannot stall the session.
- For GitLab work, launch with claude --worktree <gitlab-merge-request-url> and confirm claude agents lists that MR as !N.
- On Anthropic apps-gateway upstreams, enable the opt-in forward_user_identity setting so the signed-in user's identity is sent as headers and the proxy behind the gateway can attribute spend per user.
- If WebFetch session URL cache lifetime should not stay at the unchanged 15-minute default, set CLAUDE_CODE_WEBFETCH_CACHE_TTL_MS in the agent environment.
- If agents on Opus 4.8, Sonnet 5, Fable 5, Mythos 5, or newer still need TaskCreate/Get/Update/List or TodoWrite, export CLAUDE_CODE_ENABLE_TODO_TOOLS=1; otherwise drop those tool calls from prompts and skills.
Agent prompt
Paste into your agent or query via MCP (get_agent_prompt) — free, no extra AI costPaste into Claude Code / CLAUDE.md task
DevAgentRadar → Claude Code
You are helping me adopt a real coding-assistant change. Work only from the facts below. Do not invent features.
Context
Assistant: Claude Code Proposal: Set CLAUDE_CODE_TOOL_MEMORY_LIMIT for Bash tool cgroups on Linux Summary: Opt into Linux memory cgroups for Claude Code Bash tool commands so runaway builds cannot stall the session, and wire related v2.1.233 controls (identity forwarding, WebFetch cache TTL, GitLab MR worktrees) into daily agent workflows. Primary source: https://github.com/anthropics/claude-code/releases/tag/v2.1.233
Why it matters
v2.1.233 adds opt-in Linux memory cgroups for Bash tool commands via CLAUDE_CODE_TOOL_MEMORY_LIMIT so a runaway build cannot stall the session. The same release adds GitLab merge-request URLs on --worktree (shown as !N in claude agents), opt-in forward_user_identity on Anthropic apps-gateway upstreams (signed-in user identity as headers for per-user spend attribution), and CLAUDE_CODE_WEBFETCH_CACHE_TTL_MS for the WebFetch session URL cache (default still 15 minutes). Reliability fixes around permission-wait cloud sessions, MCP v2 listen-stream reopen loops, idle Linux 100% CPU with sandboxing, Notification hooks under Desktop/VS Code, and the Windows ??\ UNC bypass make these controls safer to enable. Todo/task tools (TaskCreate/Get/Update/List, TodoWrite) are off on Opus 4.8, Sonnet 5, Fable 5, Mythos 5, and newer unless CLAUDE_CODE_ENABLE_TODO_TOOLS=1.
Suggested actions
- On Linux Claude Code hosts, export CLAUDE_CODE_TOOL_MEMORY_LIMIT in the process environment (byte cap, e.g. 4294967296) so Bash tool commands run under a memory cgroup and a runaway build cannot stall the session.
- For GitLab work, launch with claude --worktree <gitlab-merge-request-url> and confirm claude agents lists that MR as !N.
- On Anthropic apps-gateway upstreams, enable the opt-in forward_user_identity setting so the signed-in user's identity is sent as headers and the proxy behind the gateway can attribute spend per user.
- If WebFetch session URL cache lifetime should not stay at the unchanged 15-minute default, set CLAUDE_CODE_WEBFETCH_CACHE_TTL_MS in the agent environment.
- If agents on Opus 4.8, Sonnet 5, Fable 5, Mythos 5, or newer still need TaskCreate/Get/Update/List or TodoWrite, export CLAUDE_CODE_ENABLE_TODO_TOOLS=1; otherwise drop those tool calls from prompts and skills.
Config surfaces this release may change
- permission rules (high confidence) — check your repo before applying
- settings files — check your repo before applying
- MCP servers — check your repo before applying
- skills — check your repo before applying
After you finish
Do not report this as applied to DevAgentRadar. You cannot write the visitor's loop.
Tell the human: open https://devagentradar.com/proposals/claude-code-v2-1-233-set-claude-code-tool-memory-limit-for-bash-tool-cgr and mark Applied, Skipped, or Failed. Proposal id: 3e3be498-2006-4174-b6ff-b9693789818a
Your job
- Restate the change in one sentence.
- Propose a minimal plan for my repo (or a throwaway pilot).
- Implement only what I approve; prefer small diffs and tests.
- Call out risks (permissions, breaking APIs, cost).
Start by confirming you understood the proposal.
Your loop
This browser · no sign-in · not shared as “you”After you run the prompt
Only you can mark this. Agents cannot write your loop.
Your decision stays on this device. A public tally appears after a few votes.