Follow Discord
Sweep 08 Oct 2026 · 18:53Z Build v2.1.295 516 read Stable v2.1.286 Latest v2.1.295 Next v2.1.295 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.290 ·

Bash permission checks give new, more specific reasons for refusing wrapper commands

Bash permission checks drop an old table about bare shell launchers and add specific refusal reasons for deep wrapping, env -P and wrappers with no command

Group of 2 You'll notice Improvements
JSON All of v2.1.290
You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
PermissionsArea: what it touches
ImprovementsKind: in v2.1.290,
ImprovementsSection of the release

Unclear Whether these commands are blocked outright or you are asked to approve them, and whether this is switched on everywhere, is not clear.

What

Before Claude runs a shell command, Claude Code checks whether it needs your permission. Some commands wrap another command, such as sudo or find -exec, and these are judged more carefully. The reasons given changed:

  • Old table removed: the table that explained why parallel, script, su, runuser and sudo with no command of their own read commands from their input is gone. The same symbol is now a pattern that matches control characters.
  • New refusal reasons: commands are now refused with a specific reason when they wrap a command in more than four layers of commands such as find -exec or parallel, when they use env -P with a relative directory, or when a shell wrapper (parallel, script, su, runuser, sudo/doas) is given no command of its own.

Why

When a wrapped command is refused or needs approval, the message now says which pattern triggered it, which makes it easier to understand and rewrite the command.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtWhether these commands are blocked outright or you are asked to approve them, and whether this is switched on everywhere, is not clear.

See this entry in the whole of v2.1.290 →

Feedback