Permission denied errors — page 2
Issues 201–400 of the 2,494 matching this topic. The trend chart and topic overview are on page 1.
- [BUG] Sub-agent Write tool operations don't persist to filesystem - Partial sandboxing (v2.0.14)
- [BUG] BUG: Cowork Linux sandbox fails to start on Windows — persists after all Hyper-V service fixes
- [FEATURE] Claude Code on the web: allow read access to public GitHub repositories via user OAuth (no GitHub App install required)
- Claude Code web sandbox proxy allowlist blocks user-owned custom domains
- [BUG] Cowork EXDEV: cross-device link not permitted — rename within same directory (Windows 11 Pro, OneDrive present)
- Sandbox sets TMPDIR to non-existent directory, causing child processes to hang
- sandbox.enabled: false setting ignored — bwrap still wraps all Bash commands
- dangerouslyDisableSandbox bypasses sandbox without user approval prompt
- [BUG] VS code Claude Code extension fails - Bedrock API Compatibility Issue - `eager_input_streaming` Parameter
- [BUG] Cowork workspace bricked after Chrome automation task on Windows 11 Home, no recovery path
- cannot send any message, error 500 (San Francisco Mission)
- `claude-api` skill dumps entire ~784KB SKILL.md into context for a simple usage-limit question, burning huge Pro-plan usage
- [BUG] Sandbox git-internals write-protection resolves paths against the worktree root, not `.git/` — collaterally blocks a project's top-level `config/` dir
- Read tool PDF support broken on Windows — sandbox rejects pdftoppm from all locations
- claude.ai MCP-Apps host silently drops `_meta.ui.csp.frameDomains`, blocking all third-party inline iframe embeds (YouTube, Salesforce, etc.)
- [BUG] Claude Code crashes with "exited with code 1" on multi-user macOS due to shared /tmp/claude-settings-<hash>.json
- [BUG] Preview server cannot read files from ~/Desktop on macOS despite Full Disk Access
- [BUG] bwrap sandbox completely broken — "Can't create file at .zshrc: Read-only file system" kills ALL Bash tool calls
- sandbox.filesystem.denyWrite/denyRead silently ignore relative paths; only absolute paths work
- [FEATURE] Make OAuth/admin base URL configurable like ANTHROPIC_BASE_URL
- Sandbox crashes when auto-denied file paths traverse symlinks
- [BUG] disableBypassPermissionsMode in managed-settings.json has no effect (v2.1.92)
- [BUG] bwrap fails in a worktree when .claude/skills is a symlink in a repository
- CUA save_to_disk screenshots not accessible from filesystem
- [Bug] Claude Code performance degradation and compilation failures
- [BUG] Hook error messages shown on every tool call even when hooks exit 0
- [BUG] Claude Code makes high-frequency version polling requests (~2-4/min) to GCS
- [BUG] Regression in 2.1.72 (VS Code, Bedrock): `400 tools.0.custom.eager_input_streaming: Extra inputs are not permitted`
- Add sandbox status to status line JSON input
- Cowork VM: EXDEV error when installing marketplace plugins
- [BUG] git commit fails inside sandbox on macos
- [Bug] Permission denied error on every Bash command after macOS upgrade
- Streaming output in `--verbose --print`
- [BUG] Extensions settings tab stuck on "Loading extensions..." — EventEmitter memory leak in IPC listeners
- [FEATURE] Browser view / browser tools in Claude Code cloud sessions (Claude Code on the web)
- Linux sandbox: recursive Read() deny globs expand to per-file bwrap binds → E2BIG on every command (incl. echo hello) when a denied directory holds many files
- Refuses all credential / sign-in / account-creation work even when intentional and authorized — used to work, ignores bypass-permissions
- Bash sandbox (bubblewrap) corrupts `!` to `\!` in commands, making the sandbox unusable for agentic workflows
- [BUG] Plugin install no longer copies symlinked skills to cache (regression in v2.1.117)
- Sandbox TLS verification fails for gh CLI despite github.com in allowedHosts
- excludedCommands glob matching unsandboxes entire shell invocation, enabling sandbox escape via command chaining
- [BUG] Cloud scheduled tasks: gRPC/HTTP2 blocked by sandbox TLS proxy to googleapis.com
- Cowork VM: HCS 0x80070005 (Access Denied) on Win11 25H2 - MSIX SYSTEM ACL missing
- [BUG] Claude Code Destructive Action + Repeated User Interaction Failures
- [BUG] claude sometimes wants to use /tmp even though CLAUDE_CODE_TMPDIR is set in the environment
- [BUG] Claude code for VSCode v2.1.72 gives 400 to every input
- [FEATURE] Sandbox should isolate all tool execution, not just Bash
- [Bug] Sibling tool call errored regression since v2.1.19
- [BUG] Network requests outside of sandbox don't trigger `PermissionRequest` hook
- EACCES: permission denied on Termux/Android - hardcoded /tmp path ignores $TMPDIR
- tmpclaude-xxxx-cwd are left littering project
- [BUG] Claude Code hangs entirely when /dev/stdin is read using Bash tool in a sandbox
- [BUG] React Hydration Error Prevents Claude Code Web Session Startup
- [BUG] Node.js error when `ps` is unavailable
- [Suggestion] Alternative for per-user NPM configuration so that `claude` does not want user to install into `/usr` as superuser.
- Desktop rewind fails on conversation-only sessions: not on active chain (chain size 2/N)
- claude.ai code-execution sandbox: HTTP 503 'DNS cache overflow' on egress to Vercel-hosted host
- MCP connections return 503 DNS cache overflow from sandbox egress proxy (web/mobile)
- [BUG] sandbox auto-allow does not work vor env-prefixed commands
- v2.1.98 regression: rw bind mounts inside ~/.claude shadowed by parent ro mount
- RTL (Right-to-Left) support for Hebrew/Arabic in VSCode extension chat
- [BUG] Cowork: FUSE mount of selected folder does not expose pre-existing files (Windows, non-home-dir path)
- [BUG] [VSCode Extension 2.1.72] Bedrock integration broken - eager_input_streaming error
- [Feature Request] excludedCommands should also bypass Mach port / IPC restrictions for local app CLIs
- You've hit your limit · resets 11pm (America/Anchorage)
- Security: dangerouslyDisableSandbox bypasses permission prompts when tool is auto-approved
- Image Upload Exceeds Size Limit: Base64 Image Too Large (6.2 MB > 5 MB)
- [BUG] 2.1.216 sandbox regression: "bwrap: Can't mkdir /opt/.claude" — ancestor-walk denyWrite mountpoints fail-closed on non-root installs under root-owned dirs
- [FEATURE] Transfer session to another claude code instance
- CCR routine sessions can't reach GitHub — outbound traffic appears routed through a broken internal proxy
- [BUG] Postgres network egress blocked even with full network permissions
- [Feature Request] Support GPG commit signing in sandboxed environment
- Add sandbox mode/status to statusline data fields
- [Bug] Claude Desktop VM workspace startup failure: path mismatch between AppData\Roaming and AppData\Local
- [BUG] Cowork sandbox disk at 100% capacity — base image too large for allocated disk
- [BUG] Remote SSH sessions fail with EACCES on shared Linux host — /tmp/claude-settings-<static-hash>.json collision between users
- Feature: Preview tool should support rendering MCP Apps (ext-apps)
- Backslash-escaped whitespace check is too aggressive — flags legitimate paths with spaces
- [BUG] sandbox.enabled: false does not disable bwrap when working directory is ~/.claude/
- Bash tool returns exit code 1 with no stdout/stderr on CachyOS (Arch Linux)
- Bug: claude-plugins-official - learning/explanatory-output-style hook scripts missing execute permission
- [FEATURE] Apply user-level CLAUDE.md and rules to cloud sessions (web / mobile)
- [FEATURE] Support wildcard/regex for `sandbox.network.allowUnixSockets` on macOS
- [BUG] Bash tool fails on Windows when user profile path contains apostrophe
- [BUG] Cowork Windows: sandbox-helper fails to unmount host share, VM service won't start (Win 11 Pro)
- [BUG] Cowork on Windows fails at startup: "sandbox-helper: failed to unmount host share (tried both virtiofs and Plan9): invalid argument"
- [FEATURE] Sandbox denial should stop agent, not auto-retry with bypass prompt
- [Bug] Claude Code hangs indefinitely on Windows PowerShell until keyboard input
- [BUG] excludedCommands in sandbox settings doesn't bypass sandbox
- Background agents fail on Termux - hardcoded /tmp path
- [BUG] Sandbox fails with "bwrap: loopback: Failed RTM_NEWADDR: Operation not permitted"
- [BUG] claude code web sandbox: .NET NuGet Package Restore Fails Due to Proxy Authentication
- gh write commands execute without permission prompt despite Bash not being in allow list
- [Bug] /clear Command Fails to Actually Reset Conversation Context
- Agent Discovery Failure: Generated Agents Not Recognized or Loadable
- [BUG] Claude crashed while running a bash command
- [BUG] Perhaps another flag for --dangerously-skip-permissions that is OK with root
- [BUG] Code tab writes UI render metadata (start_timestamp/stop_timestamp/flags) into transcript JSONL, causing unrecoverable API 400 that recurs after full sanitization
- sandbox: filesystem reads are unrestricted, and the agent can silently break its own sandbox enforcement by editing settings.json
- Auto mode classifier persistently unavailable — 2+ weeks, reproduces across accounts, machines, OSes, and CLI versions
- [BUG] Windows Desktop app: Read tool PDF fails with 'pdftoppm is not installed' while poppler is installed, on PATH, and resolvable by the same session's shells
- Cloud environments (routines): headless Chromium gets ERR_CONNECTION_RESET on all sites even with Network access = Full (curl works)
- [BUG] No hook event fires for sandbox network permission popup in v2.1.120 (regression from v2.1.76)
- [BUG] macOS: Claude Desktop can't run hooks/git in TCC-protected folders (~/Documents) — `disclaimer` disclaims TCC responsibility, git getcwd() → "Operation not permitted"
- [Bug] Linux sandbox unavailable: bash hard failure preventing tool execution
- [Bug] Anthropic API Error: Permission Denied (403) on Login
- Claude Desktop (Electron) causes NTFS NonPaged Pool kernel memory leak on Windows (~0.5GB/min)
- Cowork installation fails at 80% on Windows - EXDEV cross-device link error
- You've hit your limit · resets 10pm (Europe/Istanbul)
- [FEATURE] Better tooling for binary file operations (JAR patching, large file handling)
- [BUG] [Linux] Bundled ripgrep binary missing execute permission — silently breaks all user commands/skills
- [BUG] macOS plist managed settings no longer override user settings in v2.1.80
- [BUG] "Don't ask again" on unsandboxed prompt is a no-op
- [Bug] Sandbox blocks cwd-tracking writes on macOS, causing all bash commands to exit with code 1
- [BUG] Version 2.1.69 breaks AWS Bedrock compatibility with `eager_input_streaming` error
- dangerouslyDisableSandbox: true does not prompt for user confirmation
- [Bug] Claude in Chrome WebSocket bridge fails behind Zscaler/corporate TLS proxy (unable to get local issuer certificate)
- Local dev server screenshot tool for visual QA
- [BUG] Sandbox mode generates ~607k token system prompt with large permissions.deny list
- Bug: unquoted TMPDIR path with spaces causes 'Permission denied' on every bash command (Windows)
- [BUG] messages.37.content.0.thinking.valid: Extra inputs are not permitted
- Crash: EPERM error when killing background shell process
- [BUG] TMPDIR not set in sandbox mode if bubblewrap is installed setuid root
- [Bug] Task Tool Isolation Prevents Real File Modifications
- [BUG] Daemon-hosted background worker deletes `~/.claude/settings.json` when it is a symlink into a read-only directory (nix/home-manager) — all user settings silently lost
- Sandbox filesystem protection leaves stray placeholder files / bind mounts in project working tree
- Claude config path should be configurable (security/sandboxing blocker)
- [BUG] Cloud routines / Claude Code on the web have no non-interactive way to trust a project-scoped `.mcp.json` MCP server - daily routine broke after the untrusted-workspace gate
- [BUG] Cowork stale-cache corruption reproduced under Claude Fable 5 — host writes are clean on disk, the sandbox read view truncates (full diagnosis + fix)
- [Tahoe 26.x] terminal process tree EPERM in ~/Documents — root cause analysis & data
- [BUG] Ink rendering crash "<Box> can't be nested inside <Text>" when teammate requests sandbox bypass permission
- [BUG] WSL2: Bash tool fails with E2BIG because Claude wraps bubblewrap in single /bin/bash -c string exceeding Linux MAX_ARG_STRLEN
- [BUG] Claude Desktop (Windows Store / MSIX): Code sessions silently fail to persist due to EXDEV error inside MSIX sandbox, even when everything is on C: — resolved by switching to Win32 installer
- MCP destructive tools silently denied without prompt in acceptEdits mode — misleading error message
- [BUG] MSIX: Code sessions lost on restart — EXDEV error in session save (fs.rename across VFS reparse point)
- [BUG] Session not logging into Subscription, using API credits instead.
- sandbox filesystem denyRead not enforced for Read tool or Bash commands
- Sandbox: allowedDomains not enforced for plain HTTP — only HTTPS CONNECT is filtered
- [BUG] Permissions error with git fsmonitor
- [BUG] Code mode broken after v2.1.78 update — .app bundle binary not spawnable by desktop SDK
- [BUG] Claude Code crashes on Windows Enterprise - EPERM: operation not permitted, uv_spawn 'reg'
- Allow configuring terminal tab/window title
- [BUG] sandbox denyRead seems ineffective
- [BUG] Cowork Windows - Downloads folder fails to mount: "sandbox-helper: failed to unmount host share (virtiofs and Plan9): invalid argument"
- [BUG] Background agents cannot run Bash commands - auto-denied without prompting user
- [BUG] add_dirs Grants Filesystem Access to Read/Write Tools but Not to Bash Tool
- [Feature Request] Improve Flatpak Chrome integration to support automatic detection and configuration
- [Bug] Claude in Chrome tool not available despite extension installed
- cant login to Max plan: OAuth Request Failed
- [FEATURE] Better error messages for tools (some existing ones are generic and or misleading)
- [BUG] Claude Code is adding "(project, gitignored)" to system prompt even if the skills are installed on user level
- [BUG] EPERM on long commands still crashing Claude Code
- Cowork cloud sessions cannot access any GitHub repository, and the git proxy instructs the agent to call a nonexistent add_repo tool
- [BUG] ENV_SCRUB=1 sandbox leaves persistent 0-byte placeholder files in cwd AND $HOME (.netrc, .bashrc, .gitconfig) — still in v2.1.211
- [Bug] Claude Code fails to launch with EPERM error on macOS
- Claude Desktop Code tab ignores NODE_EXTRA_CA_CERTS on Windows MSIX install behind corporate SSL proxy
- Feature request: Hard workspace boundary enforcement for project isolation
- [BUG] Sandbox blocks writes to `.vscode/` and `.idea/` inside `node_modules/`, breaking `pnpm install`
- [BUG] PowerShell tool fails Exit 1, empty stdout/stderr on Windows 10 DE-locale (v2.1.142, all environmental causes ruled out)
- [BUG] Critical: sandbox.filesystem.denyRead does not prevent credential exposure
- Claude-3p + Bedrock: managed-settings allowedDomains not honored, sandbox pinned to 4 hosts
- Catastrophic data loss from `cmd /c rd /s /q` via PowerShell tool with broken quoting on Unicode/space path
- [BUG] Routines /run endpoint returns HTTP 400 "trigger_id: Extra inputs are not permitted" — both web UI and RemoteTrigger tool affected
- [BUG] Sandbox startup error on Linux shows unrendered `${j$}` instead of the failing sandbox component
- [BUG] v2.1.120 — (fix inside) ERROR g9H is not a function. (In 'g9H(K)', 'g9H' is undefined)
- Worktree UX: session keying, multi-repo isolation, and gitignored files
- Bash tool silently returns empty output when `/tmp/claude-$UID/` exceeds tmpfs quota
- [BUG] bun install fails with 503 on private GitHub Packages (sandbox proxy rejects redirect with Authorization header)
- [Bug] virtiofs mount serves truncated file contents to sandboxed environment while host files are clean
- [BUG] Continuously getting API Error: 400 {"error":{"message":"{"message":"context_management: Extra inputs are not permitted"}. Received Model Group=bedrock-sonnet-4.5\nAvailable Model Group Fallbacks=None","type":"None","param":"None","code":"400"}}
- [BUG] Sandbox fails inside Docker containers: nested user namespace in apply-seccomp causes EACCES on /proc/self/setgroups
- Managed Agents: gmail.googleapis.com blocked by egress proxy even with explicit allowed_hosts
- Cowork: launch virtiofsd with cache=none on workspace mounts to fix stale .git/index.lock
- Ultraplan remote session offers 'implement here' but cannot push code
- [BUG] Cowork VM guest connection timeout on Windows 10 Pro — 60s timeout too short for HDD systems, Linux guest stalls after add_plan9_shares
- [Bug] Claude Opus Max performance degradation in code generation quality
- Edit/Write tools fail with EPERM on Windows drive root paths (e.g. D:\)
- sandbox.network.allowedDomains does not work for Node.js processes (DNS resolution blocked)
- [Bug] Escape key not working in /status submenu on Ubuntu
- Sandbox silently disabled when ripgrep not installed — no warning to user
- [BUG] Pipes silently broken in sandbox: shell-quoted "<" in oAD passes literal argument to eval instead of redirect
- Git worktrees of the same repo share the same project identity, causing cross-worktree path confusion
- [BUG] plugin install / marketplace add silently clears sandbox.filesystem configuration
- Windows: .claude.json corruption from concurrent writes causes repeated OAuth login
- Claude in Chrome: Extension crashes when executing javascript_tool or read_page on certain pages
- [FEATURE] Cowork: Allow folder selection outside home directory (custom allowed paths)
- Subagents cannot use Bash despite parent Bash(*) allow rule
- Sandbox filesystem allowlist doesn't resolve symlinks, causing "Operation not permitted" for Bash tools
- [BUG] Sandbox CWD tracking uses CLAUDE_CODE_TMPDIR which is not in sandbox allow list
- [Bug] rm -rf command deletes unintended parent directory contents
- Sandbox creates phantom dotfiles in project directory instead of protecting home directory files
- URGENT: My claude.code terminal crashed again: Usafe limits exhaused.. 2.1.2 is totally unstable
- [BUG] Sandbox permission error after update: EACCES permission denied mkdir /tmp/claude/.../tasks
- [BUG] `/sandbox` Sandbox mode is useless
- spawn pgrep ENOENT crash on macOS
- [MODEL] "Do you want to make this edit to....." --> overwhelming repetitive prompts after "2.Yes,allow...."
- [DOCS] Comprehensive Documentation Update for Claude Code v2.0.0 Release
- [Bug] Security Vulnerability: Permissions Bypass via ExitPlanMode Workflow Exploit
- Low Context Management in Claude Code CLI
- [Feature Request] Allow a user to specify an arbitrary command prepended to every bash command.