{"version":"2.1.290","anchor":"bash-permission-checks-name-new-refusal-reasons","canonical_anchor":"bash-permission-checks-name-new-refusal-reasons","heading":"Bash permission checks give new, more specific reasons for refusing wrapper commands","tier":"notice","area":"Permissions","scope":"individual","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290\/e\/bash-permission-checks-name-new-refusal-reasons","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290","markdown":"### Bash permission checks give new, more specific reasons for refusing wrapper commands\n\nBash permission checks drop an old table about bare shell launchers and add specific refusal reasons for deep wrapping, env -P and wrappers with no command\n\n**Unclear.** Whether these commands are blocked outright or you are asked to approve them, and whether this is switched on everywhere, is not clear.\n\n**What**\n\nBefore Claude runs a shell command, Claude Code checks whether it needs your permission. Some commands wrap another command, such as `sudo` or `find -exec`, and these are judged more carefully. The reasons given changed:\n\n- Old table removed: the table that explained why `parallel`, `script`, `su`, `runuser` and `sudo` with no command of their own read commands from their input is gone. The same symbol is now a pattern that matches control characters.\n\n- New refusal reasons: commands are now refused with a specific reason when they wrap a command in more than four layers of commands such as `find -exec` or `parallel`, when they use `env -P` with a relative directory, or when a shell wrapper (`parallel`, `script`, `su`, `runuser`, `sudo`\/`doas`) is given no command of its own.\n\n**Why**\n\nWhen a wrapped command is refused or needs approval, the message now says which pattern triggered it, which makes it easier to understand and rewrite the command.\n\n- Area: Permissions\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5\n- Scope: individual\n- Heads-up: no"}