Fetching from the wire…
Public story · 2026-08-10 · high
Version 2.1.225 fixed a bug where the model's own permission denial counted toward the limit that cuts unattended runs short.
Why now: The fix landed in Claude Code's newest release, so unattended auto-mode runs on anything older are still hitting the bug.
Claude Code 2.1.225 fixed a bug that made auto mode count its own safety-filter refusal toward the consecutive-block limit, per the changelog. For anyone running Claude Code unattended, that counting bug was the difference between a task that finished and one that quit after a handful of denials.
The model would deny its own permission check, then count that denial as a block. Enough of them and the run ended early, even though the underlying action stayed denied either way. The changelog doesn't say how many self-denials it took to trip the old limit.
The fix doesn't change what gets approved or blocked. Before, retrying a self-denial burned through the block budget until the run stopped short. Now the model just moves on.
If you've watched a long autonomous session stop cold after a few denials, this is a plausible explanation. Re-run the same workload on 2.1.225 or later before you touch your permission setup.
Each link below shares sources, entities, or timing with this story.
Go rotate a key. I'll wait. Claude Code 2.1.246, released August 25, lists this in its changelog: a fix for "telemetry and metrics requests to Anthropic carrying the API key configured for a third-party gateway (ANTHROPIC_BASE_URL); a credential is now only sent to its own hos...
2.1.224 shipped SendMessage and ListAgents as first-class tools so separate sessions on macOS/Linux address each other by name, governed by crossSessionInbound and dialogExpiry. Auto mode routes inbound message content through the permission classifier before dispatch, treatin...
One line in the v2.1.215 changelog, July 19: Claude Code no longer invokes the /verify and /code-review skills on its own. You call them explicitly now (changelog). If your workflow assumed a review pass fired at the end of a task, it doesn't anymore, and nothing told you. Cod...
If you're on Pro, Max, or Team, the permission prompt you've been hitting Enter on for a year goes away Friday. Anthropic confirmed auto mode becomes the default, replacing per-call approval with a classifier that inspects each tool call for irreversible, destructive, or out-o...
The changelog adds a warning before login expiry so background sessions don't die mid-run, a grey pause badge in the footer to confirm you're in manual permission mode, additional working directories now surfaced through MCP roots/list with change notifications, and a fix for...
Two researchers in my set surfaced this independently, which is usually a sign it matters. Claude Code 2.1.166, first seen June 6, introduces a fallback-models setting: configure up to three models tried in order when the primary is overloaded or unavailable. It also adds glob...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.