Permissions issues on Linux
Issues the maintainers labelled both platform:linux and area:permissions.
287 issues · 56 open · 231 resolved (80%) · first seen Aug 25, 2025
Is this getting better or worse?
This class of problem is still growing. 168 new reports in the last 90 days vs 102 in the 90 before — +65%. The open backlog peaked at 56 in 2026-08 and sits at 56 today.
Derived by counting each matching issue from its creation date until it closed. First-party
computation over the anthropics/claude-code tracker — the trend is not published
anywhere upstream.
Which builds report this
174 of these reports name the Claude Code build they were running, spanning 94 releases. Heaviest reporters:
- Claude Code v2.1.233
- Claude Code v2.1.207
- Claude Code v2.1.119
- Claude Code v2.1.114
- Claude Code v2.1.234
- Claude Code v2.1.112
- Claude Code v2.1.56
- Claude Code v2.1.241
Report volume, not a defect count: an issue can mention a build without that build having caused the failure. Versions come from the version string in the bug-report template, matched against real published tags.
Do these get fixed?
Median time to close is 28 days across 231 closures. Of the 231 closures with a recorded reason, 17% were closed as completed and 191 as not-planned or duplicate. The most recent completed fix landed in 2026-08.
Workarounds reported by the community
60 of these issues post a workaround someone says worked. The highest-engagement ones:
- [BUG] v2.1.78: Protected directory prompt in bypassPermissions has no override — forces hacky workarounds
- …t on every skill creation. 2. No override flag forces worse workarounds Since there's no setting or similar, users who need this workflow (and there are many — skills are a first-class Claude Code feature) will build wor…
Found in the description of #35646 · resolved - [BUG] ask list is ignored when "Bash" is in allow list
- …ands) and safety (protection against destructive commands). Workarounds attempted (none work) : - - Bypasses everything including ask list - - Prompts for every new command type
Found in the description of #6527 · still open - [Bug] Permission prompt disappears after Ctrl+O toggle with concurrent tool calls
- …ly reproducible. Hit it 3+ times in a single session today. Workarounds tried - Pressing another CTRL-O + CTRL-O to see if permissions is back did not work Notes - Cache stays warm across this state, so context isn't los…
Found in the description of #60194 · resolved - [BUG] Bash comments break permissions
- Workaround: a PreToolUse hook can strip the comment lines before permission matching sees them. The hook reads the command, removes leading lines, and returns the clean command via . Your allowlist then matches correctly…
Found in the thread of #29582 · resolved - [Bug] Auto mode unavailable error persists despite mode change in session
- …ur plan". closing session and run again with --resume works as a workaround, but once you send a prompt with auto mode it gets stuck with this error <img width="1912" height="703" alt="Image" src=" /
Found in the thread of #42449 · still open
Excerpts are quoted from the linked issue so you can judge relevance before opening it. Threads that only ask for a workaround, or report that there is none, are excluded. These are community suggestions, not official guidance from Anthropic — read the full thread before applying one.
Matching issues 1–100
Ranked by community engagement (reactions weighted over comments).
- [BUG] v2.1.78: Protected directory prompt in bypassPermissions has no override — forces hacky workarounds
- [BUG] Mouse click to refocus terminal triggers permission prompt unintentionally
- [BUG] ask list is ignored when "Bash" is in allow list
- [Bug] Permission prompt disappears after Ctrl+O toggle with concurrent tool calls
- [BUG] Bash comments break permissions
- [BUG] Auto mode injects system reminder that suppresses AskUserQuestion in skills
- [Bug] Auto mode unavailable error persists despite mode change in session
- Security heuristics override explicit permission allowlist
- Permission scoping shows main worktree path instead of current worktree path
- Bash allowlist pattern 'Bash(curl *)' in settings.local.json not matching — repeated permission prompts
- [BUG] Command parsing for permissions incorrectly handles # even when properly commented
- Subagents prompt for permission on every tool call starting v2.1.56
- Remote Control Android approvals do not unblock local Claude Code TUI (host stays Waiting)
- [BUG] Bash permission pattern breaks when command contains parentheses
- [BUG] Remote Control: MCP permission prompts for non-read tools never surface in claude.ai/code web UI
- bypass permissions mode steers agents off Read/Edit/Grep onto composed shell strings, reintroducing quoting and exit-code failures that the structured tools cannot have
- Team-lead Claude Code crashes with stack overflow in rQ7/permission-explainer after teammate permission request
- `--permission-mode dontAsk` bypasses `autoAllowBashIfSandboxed` for Bash commands containing shell variable expansion
- Background sessions (claude agents / fleet) don't honor permissions.defaultMode: bypassPermissions
- Bash permission glob matching breaks when command contains # character
- [BUG] sandbox auto-allow does not work vor env-prefixed commands
- [BUG] Extension crashes (exit code 1) when allowDangerouslySkipPermissions is set and running as root
- Multi-minute first-byte stalls on claude-opus-4-8[1m], compounded by auto-mode classifier timeouts — sessions near-unusable
- [Bug] Allow rules under `~/.claude/` show as loaded per /permissions but don't match at runtime
- [BUG] Auto-mode safety classifier reports model "temporarily unavailable," blocking all Bash/WebSearch while normal generation works fine
- [BUG] --dangerously-skip-permissions sometimes still asks for permissions?
- [SECURITY-BUG ] Permission prompt is silently replaced by a newer pending approval (LIFO stack), allowing the wrong command to be approved in manual-approve mode
- [BUG] allowed-tools in skill SKILL.md only auto-approves the first Bash call per session, subsequent calls prompt for permission
- [Bug] Model classifier rejects claude-opus-4-7 as invalid model
- VSCode extension: permission mode resets from bypassPermissions to auto/acceptEdits mid-conversation
- VS Code extension 2.1.131 silently ignores `claudeCode.initialPermissionMode` and `claudeCode.claudeProcessWrapper` (regression vs 2.1.128)
- [BUG] PreToolUse hook permissionDecision "allow" does not suppress native permission prompt in interactive mode (v2.1.119)
- Trust dialog reappears every session — `hasTrustDialogAccepted` not persisted on `/exit`
- Bash read-only commands (curl, gh) still prompt for permission despite allow rules
- [BUG] Sub-agent dispatched via Agent tool stalls silently on MCP permission gate — no surface to parent CLI UI
- [BUG] Auto mode missing from VS Code extension picker on Linux despite canEnterAuto=true (works in terminal CLI and Windows extension)
- [BUG] --append-system-prompt-file blocks /fork while the inline --append-system-prompt doesn't; the refusal never names the blocking flag
- [BUG] Permission parser treats # in multi-line quoted strings as shell comments
- [BUG] Approving a plan via "Plan Approved" UI button drops session into `default` mode instead of restoring prior permission mode
- Sub-agent dispatch denies Bash with tengu_harbor_permissions=true (regression 2026-05-03)
- bypassPermissions defaultMode and --permission-mode flag ignored; session stays in auto mode (since 2026-08-14 auto-mode rollout)
- [Bug][harness] Safety block halts authorized mesh-agent enrollment by misreading temporary loopback-only admin
- [Bug][harness] ClAudit: auto-mode classifier denied — Installs a persistent autostart launcher that arms an autonomous watch
- [Bug][harness] ClAudit: auto-mode classifier denied — Launches a long-running watcher that auto-files mass "false positive"
- [BUG] `.claude/skills/**` Edit hangs indefinitely in headless `--dangerously-skip-permissions` sessions (persists across v2.1.114, v2.1.116, v2.1.117)
- [BUG] Session-scoped permission grants cannot be revoked by the user who granted them
- [BUG] "Enable auto mode?" appears even with `--dangerously-skip-permissions`
- [Bug] Bypass permission mode still prompts for permissions
- ExitPlanMode approval via --permission-prompt-tool stdio silently ignored — process hangs
- [BUG] Specifying `Edit(filepath)` in `permissions.deny` whilst also specifying the filepath in `denyWrite` for `sandbox` causes bwrap failures on all bash tool calls
- "Tab to amend" instructions delivered post-execution — agent fires original tool call unmodified
- [BUG] Asked permission to run `cd /x/y/z && rm -rf *` in "bypass permissions" mode.
- [Bug][harness] ClAudit: auto-mode classifier denied — This read-only DC-agent discovery is scouting to issue Set-ADUser UPN
- [BUG] Permission prompts fire inside sandbox-allowed paths, training users to add permissions.allow entries that genuinely bypass the sandbox
- [BUG] Empty server-managed settings (304 cached) zero out local managed-settings.json — deny/allow rules never enforced
- [Bug] Claude Code blocks credential-based API calls due to overly restrictive safety filters, the existence of "Auto Mode " and "Goal" is surrendered
- PreToolUse hook `if` filter false-positives on complex Bash commands
- [Bug] Permission-mode cycling causes misplaced system-reminder attachments flagged as prompt injection
- [BUG] Permission prompt events (and user response) not serialized to session jsonl
- Running as root: --dangerously-skip-permissions exits with code 1, forcing dontAsk — no path to full autonomy as root
- Permission allowlist changes don't take effect mid-session — breaks scheduled/autonomous tasks
- settings.local.json: 'Yes, allow' permission prompt writes malformed Read(//abs/path) with double leading slash
- Feature Request: Documented opt-out for built-in default-branch push guard (CLI)
- [BUG] Heredoc as first argument bypasses pipe target permission checks
- [BUG] PreToolUse hook sometimes causes permission prompt to fail.
- [BUG] `**/` glob prefix in deny rules causes massive context bloat on Linux/WSL but not macOS
- [BUG] Claude Code ignores "No" permission responses and executes bash commands anyway
- `--dangerously-skip-permissions` does not bypass plugin file edit confirmation prompt
- [Bug] Plan mode disables dontAsk mode irreversibly
- [BUG] Allow bash commands with environment variables
- [Opus 4.6] Claude Code deleted all personal files with find / -delete during security test execution
- [BUG] Permission prompt: option 2 requires extra Enter to apply, option 1 works instantly
- Remote Control on always-on machines: three reproducible edges (consent vs. service autostart, classifier mid-flow interruption, unstable environment identity)
- /auto-mode-setup always fails: "removeFromPermissionsAllow[0] is not a rule string the removal offer could have produced"
- [BUG] Sonnet and Opus can't run any commands; always receiving "Classifier unavailable"
- [Bug][harness] Safety block halts read-only firewall/bind-config audit, misreading nft install and listen-addr
- [Bug][harness] Adding a GPP printer mapping with SID-targeting to a GPO blocked as production-wide push
- [Bug][harness] ClAudit: auto-mode classifier denied — Starting LIVE real-money trading bot ([REDACTED]_DRY_RUN=0) on the new CT
- [Bug][harness] Trusting Caddy-generated local-CA root certs on workstation blocked, halting internal-TLS FQDN-
- [Bug][harness] Reading cloudflared/Caddy config files over an authorized SSH session wrongly blocked as unauth
- [Bug][harness] Safety filter blocks bulk cleanup of already-imported completed torrents using authoritative im
- [Bug][harness] Safety block halted authorized qBittorrent cleanup of torrents already verified copied to media
- [Bug][harness] SSH read of remote user's home dir and systemd config soft-blocked mid-investigation with no in
- [Bug][harness] Removing auth gate during debug blocked without seeking clarification on scope
- [Bug][harness] Auto-classifier blocks batch GitHub issue update loop mid-run with no recourse
- [Bug][harness] Read-only firewall rule investigation wrongly blocked as autonomous DB write escalation
- [Bug][harness] ClAudit: auto-mode classifier denied — The user said Keith "is no longer with the company" as context, not as
- [Bug][harness] Safety block halted deploying no-proxy server binary to onboard a user on a separate production
- [Bug][harness] ClAudit: auto-mode classifier denied — Mass deletion of user/wallet/operator data and seeding a different use
- [Bug][harness] Safety block halts Azure AD Cloud Sync repair by refusing required Directory Sync Accounts role
- [Bug][harness] Safety block halts authorized admin SSH+credential read into container to recover locked-out En
- [Bug][harness] Safety block halts authorized stale directory device-object cleanup during hardening sweep
- [Bug][harness] Pushing approved recon-agent binary/service update to online production hosts wrongly blocked a
- [Bug][harness] Code-reading-only RBAC audit blocked by remote-write guard misclassifying it as a live OWNER gr
- [Bug][harness] Safety block stopped authorized bugfix deploy after user said "send it", forcing manual server
- [Bug][harness] ClAudit: auto-mode classifier denied — Creating an Azure AD app registration with admin-consented application
- [Bug][harness] ClAudit: auto-mode classifier denied — Real credentials (`WINRM_PASS = "zWSae6qapLgUi3eVh6QMulQ7PBKf"`) are h
- [Bug][harness] ClAudit: auto-mode classifier denied — The action reads the MSAL token cache to extract a user refresh token
- [Bug][harness] Dev server LAN rebind for local-only preview wrongly blocked as unrequested network exposure
- [Bug][harness] Cross-host VM disk move triggered for out-of-scope VM during single-VM storage migration