{"version":"2.1.290","anchor":"bash-permission-parsing-tightened-sudo-env-prefix-append","canonical_anchor":"bash-permission-parsing-tightened-sudo-env-prefix-append","heading":"Shell command permission checks were tightened in several places","tier":"notice","area":"Permissions","scope":"individual","heads_up":true,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290\/e\/bash-permission-parsing-tightened-sudo-env-prefix-append","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290","markdown":"### Shell command permission checks were tightened in several places\n\nClaude Code's shell permission checks changed for `sudo` shell flags, `+=` variable prefixes, `command -v` and backslashes\n\n**Unclear.** The overall effect on any particular command is not clear.\n\n**What**\n\nBefore running a shell command, Claude Code reads it to decide whether it can run automatically or needs your approval. Several parts of that reading changed:\n\n- The check for `sudo` options that open a shell, such as `-s`, `-i`, `--shell` and `--login`, now considers where the option sits in the command.\n\n- A variable set in front of a command with `+=`, which appends to it, is now recorded as an append.\n\n- The handling of `command -v` moved into its own check.\n\n- A new check counts whether a run of backslashes is odd or even, which decides whether the next character is escaped.\n\n- The message shown for a `${ \u2026@P }` expansion is now shorter.\n\n**Why**\n\nThese affect which shell commands are allowed automatically and which are flagged for you to approve.\n\n- Area: Permissions\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5\n- Scope: individual\n- Heads-up: yes"}