{"version":"2.1.296","anchor":"permission-answers-denyask-rule-changes-that-cant-be-full","canonical_anchor":"permission-answers-denyask-rule-changes-that-cant-be-full","heading":"Permission answers whose rule changes cannot be fully applied now block the call","tier":"notice","area":"Agents","scope":"individual","heads_up":true,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.296\/e\/permission-answers-denyask-rule-changes-that-cant-be-full","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.296","markdown":"### Permission answers whose rule changes cannot be fully applied now block the call\n\nIf an allow answer's updatedPermissions are too large or malformed and might hide a deny or ask rule, the call is now refused\n\n**What**\n\nA permission answer can allow a call and also send `updatedPermissions`, which are changes to the permission rules. If those changes go over the size limit, or are malformed, they might hide a deny or ask rule. In that case Claude Code now refuses the call instead of running it. Before, extra or malformed changes were cut down or ignored without notice, and the call still ran.\n\nAn oversized list is cut short, and a deny rule is added at the cut point. The refusal message says the call was not run because the answer allowed it and also asked for rule changes.\n\n**Why**\n\nBefore, an answer could let a call through while some of its own deny rules quietly failed to take effect. Refusing the call means a blocked action cannot slip through that way.\n\n- Area: Agents\n- Names: `updatedPermissions`\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 2\/5\n- Scope: individual\n- Heads-up: yes"}