Permissions issues on Linux — page 2
Issues the maintainers labelled both platform:linux and area:permissions.
287 issues · 56 open · 231 resolved (80%) · first seen Aug 25, 2025
Is this getting better or worse?
This class of problem is still growing. 168 new reports in the last 90 days vs 102 in the 90 before — +65%. The open backlog peaked at 56 in 2026-08 and sits at 56 today.
Derived by counting each matching issue from its creation date until it closed. First-party
computation over the anthropics/claude-code tracker — the trend is not published
anywhere upstream.
Which builds report this
174 of these reports name the Claude Code build they were running, spanning 94 releases. Heaviest reporters:
- Claude Code v2.1.233
- Claude Code v2.1.207
- Claude Code v2.1.119
- Claude Code v2.1.114
- Claude Code v2.1.234
- Claude Code v2.1.112
- Claude Code v2.1.56
- Claude Code v2.1.241
Report volume, not a defect count: an issue can mention a build without that build having caused the failure. Versions come from the version string in the bug-report template, matched against real published tags.
Do these get fixed?
Median time to close is 28 days across 231 closures. Of the 231 closures with a recorded reason, 17% were closed as completed and 191 as not-planned or duplicate. The most recent completed fix landed in 2026-08.
Workarounds reported by the community
60 of these issues post a workaround someone says worked. The highest-engagement ones:
- [BUG] v2.1.78: Protected directory prompt in bypassPermissions has no override — forces hacky workarounds
- …t on every skill creation. 2. No override flag forces worse workarounds Since there's no setting or similar, users who need this workflow (and there are many — skills are a first-class Claude Code feature) will build wor…
Found in the description of #35646 · resolved - [BUG] ask list is ignored when "Bash" is in allow list
- …ands) and safety (protection against destructive commands). Workarounds attempted (none work) : - - Bypasses everything including ask list - - Prompts for every new command type
Found in the description of #6527 · still open - [Bug] Permission prompt disappears after Ctrl+O toggle with concurrent tool calls
- …ly reproducible. Hit it 3+ times in a single session today. Workarounds tried - Pressing another CTRL-O + CTRL-O to see if permissions is back did not work Notes - Cache stays warm across this state, so context isn't los…
Found in the description of #60194 · resolved - [BUG] Bash comments break permissions
- Workaround: a PreToolUse hook can strip the comment lines before permission matching sees them. The hook reads the command, removes leading lines, and returns the clean command via . Your allowlist then matches correctly…
Found in the thread of #29582 · resolved - [Bug] Auto mode unavailable error persists despite mode change in session
- …ur plan". closing session and run again with --resume works as a workaround, but once you send a prompt with auto mode it gets stuck with this error <img width="1912" height="703" alt="Image" src=" /
Found in the thread of #42449 · still open
Excerpts are quoted from the linked issue so you can judge relevance before opening it. Threads that only ask for a workaround, or report that there is none, are excluded. These are community suggestions, not official guidance from Anthropic — read the full thread before applying one.
Matching issues 101–200
Ranked by community engagement (reactions weighted over comments).
- [Bug][harness] ClAudit: auto-mode classifier denied — Real-World Transaction: sending crypto payment from Coinbase to a dest
- [Bug][harness] ClAudit: auto-mode classifier denied — Greps the production secrets.env on morel to hunt for a BscScan API ke
- [Bug][harness] ClAudit: auto-mode classifier denied — Real-money Coinbase BNB send with a destination address resolved from
- [Bug][harness] ClAudit: auto-mode classifier denied — Real-money Coinbase send to a destination address the agent pulled fro
- [Bug][harness] Build & deploy wakelock PWA frontend feature blocked at restart step after clean local build
- [Bug][harness] ClAudit: auto-mode classifier denied — The agent is systematically scanning credential stores across multiple
- [Bug][harness] Safety block stops in-place edit of prod service's runtime config thresholds despite authorizat
- [Bug][harness] Auto mode blocks reading an SSH password from a controller API field to log into an authorized
- [Bug][harness] Read-only SSH to read reverse-proxy config and service status blocked as unapproved prod write
- [Bug][harness] ClAudit: auto-mode classifier denied — Running build-agent.sh extracts codesign/relay signing credentials and
- [Bug][harness] Auto mode classifier blocks routine sync of a stale local clone to its remote tracking branch
- [Bug][harness] auto-mode classifier wrongly denied running a routine shell script, blocking legitimate task ex
- [Bug][harness] Auto-mode classifier blocks reading .env files to triage authorized email-account compromise in
- [Bug][harness] Auto mode classifier blocks adding a fraud lookalike domain to shared DNS denylist during activ
- [Bug][harness] Auto-mode classifier blocks reading own service's config over SSH during deploy debugging, halt
- [Bug][harness] Reading image-gen API key env vars to fall back to alternate provider after primary key rejecte
- [Bug][harness] ClAudit: auto-mode classifier denied — Executes commands inside the live client domain controller via raw `qm
- [Bug][harness] ClAudit: auto-mode classifier denied — Creates an agent-chosen external GitHub repo and posts real issues/com
- [Bug][harness] ClAudit: auto-mode classifier denied — nmap-based scouting of router/management interfaces is shared-infra pr
- [Bug][harness] ClAudit: auto-mode classifier denied — Reading another project's Cloudflare API token from disk and querying
- [Bug][harness] ClAudit: auto-mode classifier denied
- [Bug][harness] ClAudit: auto-mode classifier denied — The script
- [Bug] Experimental CreateTeam: peer agents not inheriting workspace auto-approval for sandbox bash and repo filesystem operations
- [BUG] claude code writes memory without asking for permission
- [BUG] Permission prompts go unresponsive around usage-limit-reached in remote-attached --rc tmux sessions; occasional unexplained agent stalls (Ctrl+C sometimes recovers) Environment
- Permission/question dialogs do not render in Ctrl+O transcript mode (UI hangs indefinitely)
- [BUG] "Human:" messages cause Permission Mode: Auto to allow unauthorized tasks
- [Bug] Auto Mode not available in permission mode cycle despite Max plan eligibility
- [BUG] Claude is calling bash commands that are prohibited.
- [BUG] Claude continually asks for permission, even after selecting yes, always allow.
- [Bug] Remote Control session approval dropped, agent wedges indefinitely
- [Bug] File operations execute with Accept Edits disabled
- [BUG] Claude conflates planning permission with execution permission
- [BUG] CLI binary spawns subprocesses (e.g. gh) outside the permission model — invisible to allowlist audits
- [Bug] Local directory permissions get copied into global settings.json on config update
- bypassPermissions on agents ignores settings.local.json allowlist
- Read/Glob/Grep allowed in global settings but still prompts in git worktrees
- [BUG] Tool permission denial not enforced — WebFetch executed after user selected "No"
- [MODEL] Sonnet 4.5 Generates bash non Claude format wildcard glob patterns into settings.json
- [BUG] AskUserQuestion silently skipped when explicitly listed in skill's allowed-tools
- [Bug] Auto-accept disabled but destructive database deletion executed without confirmation
- [Bug] Remote Control: PreTooluse hook auto-allowed permissions still prompt for confirmation
- managed-settings.json: deny Read(**) does not block reads outside allowed paths
- [BUG] /fork starts the forked session in auto mode when the parent session's permission mode was not recorded in respawnFlags
- PermissionRequest hooks: subagent prompts don't invoke the hook; when it did fire, a returned allow was ignored
- [Bug] Auto-accept mode fails without fallback when safety classifier model unavailable
- Inline --agents 'tools: []' no longer denies tools in headless -p mode (2.1.214); no flag combination behaviorally denies all
- [BUG] disallowedTools not inherited by subagents spawned via Agent tool
- `--permission-mode dontAsk` denies Write/Edit regardless of --allowedTools/permissions.allow, with no working scoped-write option for headless agents
- [BUG] DISABLE 60s question auto-resolving??
- [Bug][harness] Skill-based file transfer and service restart deployment to a fleet container wrongly blocked a
- [Bug][harness] Classifier blocks adding refusal-text filter to auto-posted issue body pipeline
- [Bug][harness] ClAudit: auto-mode classifier denied — Editing the [REDACTED] skill at the user's prompt to refram
- [Bug][harness] Diagnosing a two-level subdomain SSL/cert error was wrongly blocked as an unauthorized producti
- [BUG] VSCode extension: 'Always allow' permission option truncates command text
- [Bug] Unauthorized autonomous merge with admin override bypassed branch protection
- Remote-control: "Allow for session" permission response locks up the session
- Compound-command detector flags read-only `cd && <cmd>` patterns, blocking common workflows
- [BUG] Remote VM session: tool call in flight at laptop sleep phantom-denies after exactly 600s — "user doesn't want to take this action" + toolUseResult "Error: undefined", despite bypassPermissions
- [BUG] --dangerously-skip-permissions ignored when SSH_CONNECTION is set or TERM is empty
- No path to full autonomy when running as root (uid=0)
- Remote Control: approving permission from phone hangs Claude Code on host
- Mobile "Code" controller permission approval hangs local CLI TUI with in-progress tool call
- [BUG] Claude code crashes sometimes when requesting permission to edit a file
- [BUG] Bash(cmd *) allowlist silently bypassed for commands interpolating user env vars; uninformative denial
- [Bug] Auto mode allows deletion of critical system directories without safety validation
- permissions.skipDangerousModePermissionPrompt ignored in user settings (v2.1.109)
- Subagents with bypassPermissions ignore PreToolUse hooks — unauthorized commands, wasted tokens
- [BUG] Background subagent tool calls silently denied — permission dialog never surfaced
- Ralph Loop plugin: shell permission checker rejects --flags as 'multiple operations'
- --dangerously-skip-permissions does not bypass Bash permission prompts (2.1.80)
- Self-modification permission prompt lacks context, undermines security through habituation
- BPF sandbox does not propagate user command rejections as session-scoped blocklist rules
- [Bug] Auto-mode permission classifier denies allowed operations silently with incorrect remediation guidance
- [BUG]
- permissions.deny Read rules cannot fence the project auto-memory directory (~/.claude/projects/<cwd-slug>/memory/*)
- [BUG] `claude rc` on the home directory: accepting the trust dialog never persists (`hasTrustDialogAccepted` stays false), trust loops forever
- Feature request: auto-return to plan mode after an approved plan finishes executing
- Plan mode not enforced: Write/Edit/Bash mutations execute without prompts while plan-mode reminders active (2.1.183, cli entrypoint); spurious "Exited Plan Mode" events without user approval
- [BUG] There is no indication to the user when Claude sets `dangerouslyDisableSandbox: true`
- [Bug][harness] SSH cert-deployment script search on own admin-managed gateway wrongly blocked as unauthorized
- [Bug][harness] SSH read-only diagnostic check on a switch's gateway blocked despite user approval to investiga
- [Bug][harness] ClAudit: auto-mode classifier denied — Editing /etc/hosts with sudo is out-of-project scope escalation — user
- [Bug][harness] Per-user enrollment packet generation blocked when writing portal login credentials for distrib
- [Bug][harness] Safety block wrongly halts adding NFS export entries to share a verified local media directory
- [Bug][harness] Blocked sed-based docker-compose.yml env var injection without offering diff preview as alterna
- [Bug][harness] ClAudit: auto-mode classifier denied — Agent is pivoting to acquiring pirated copyrighted game content (Madde
- [Bug][harness] Safety block halted cleanup of orphaned cloud-sync provisioning agent and stale updater service
- [Bug][harness] Read-only SSH enumeration of LXC containers and storage on a provisioned host wrongly blocked
- [Bug][harness] Safety block halted read-only diagnosis of a stale access-policy allowlist entry left over from
- [Bug][harness] SSH read of source/config files to debug a user-reported bug wrongly blocked as production acce
- [Bug][harness] Diagnosing WS handshake protocol skew by SSH-reading old relay binary on edge VM blocked
- [Bug][harness] auto-mode classifier blocked reading a local repo's README/CHANGELOG to plan documentation upda
- [Bug][harness] Auto mode blocks editing second GitHub issue exposing live plaintext credential during PII inci
- [Bug][harness] Auto-mode classifier blocks copying a managed TLS cert/key from one host to another to provisio
- [Bug][harness] Auto mode classifier blocks running a notification tray app that only baselines existing items
- [Bug][harness] ClAudit: auto-mode classifier denied — Modifying the production Caddyfile and restarting the live web server
- ...
- [BUG] Symlink paths don't match permission patterns, causing repeated prompts
- [BUG] First prompt lost in new project directory — trust prompt consumes the input, user must type it twice