Skip to content

[BUG] v2.1.210 regression: PreToolUse prompt-hook deny stops the entire turn (hook_stopped_continuation) instead of returning a tool error #78527

Description

@tehlowkeywiz

Environment: Claude Code 2.1.210 / 2.1.211, macOS (darwin 25), interactive sessions.

Setup: a type: "prompt" PreToolUse hook on Bash (LLM security judge using the documented {ok, reason} contract from https://code.claude.com/docs/en/hooks).

Before (≤2.1.209): judge ok:false denials fed back to the model as is_error tool_results; the model reacted in-turn. Our session transcripts show 74 such denials from 2.1.179 → 2.1.209 with 100% turn survival (the latest just hours before upgrading to 2.1.210).

After (2.1.210+): the same denial emits attachment.type: "hook_stopped_continuation" and ends the turn:

  • no feedback reaches the model;
  • the Stop-hook chain is skipped (no stop_hook_summary; Stop-hook notification sounds/commands don't fire), so the stall is silent;
  • unattended sessions and subagents hang until external input arrives (subagents have no user-input rescue path at all — only an incoming teammate message revives them).

7/7 such events in our transcripts occur on 2.1.210/211; zero on any version ≤2.1.209 (~1,800 transcript files scanned for the exact marker).

Expected: per the hooks docs, prompt-hook ok:false "maps to permissionDecision: "deny" … blocks the action" — the action, not the turn. Command hooks (exit 2 and permissionDecision: "deny") still behave correctly on 2.1.211 — deny feeds back, turn continues.

Suspected change: 2.1.210's "Fixed a hook callback timeout being misreported to the model as a user rejection…" touching the hook-result path; possibly re-engaging the v2.1.92 "restored preventContinuation:true semantics for non-Stop prompt-type hooks" behavior.

Repro: interactive session; PreToolUse type: "prompt" hook on Bash instructed to deny destructive patterns; run a command the judge blocks (e.g. a recursive delete of a nonexistent path). The turn ends with "PreToolUse:Bash hook stopped continuation". Instructing the judge model to emit "preventContinuation": false in its JSON changes nothing — the stop appears to be harness-asserted, independent of the judge's response.

Secondary observation (possibly its own issue): in headless -p mode, prompt hooks appear to fail open — the judge model returns generic ok:true even when the hook prompt explicitly instructs an unconditional ok:false, so prompt-hook enforcement seems absent in headless runs.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:hooksbugSomething isn't workinghas reproHas detailed reproduction stepsplatform:macosIssue specifically occurs on macOSregressionreproducedBug reproduced by maintainers on a released buildstaleIssue is inactive

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions