Environment: Claude Code 2.1.210 / 2.1.211, macOS (darwin 25), interactive sessions.
Setup: a type: "prompt" PreToolUse hook on Bash (LLM security judge using the documented {ok, reason} contract from https://code.claude.com/docs/en/hooks).
Before (≤2.1.209): judge ok:false denials fed back to the model as is_error tool_results; the model reacted in-turn. Our session transcripts show 74 such denials from 2.1.179 → 2.1.209 with 100% turn survival (the latest just hours before upgrading to 2.1.210).
After (2.1.210+): the same denial emits attachment.type: "hook_stopped_continuation" and ends the turn:
- no feedback reaches the model;
- the Stop-hook chain is skipped (no
stop_hook_summary; Stop-hook notification sounds/commands don't fire), so the stall is silent;
- unattended sessions and subagents hang until external input arrives (subagents have no user-input rescue path at all — only an incoming teammate message revives them).
7/7 such events in our transcripts occur on 2.1.210/211; zero on any version ≤2.1.209 (~1,800 transcript files scanned for the exact marker).
Expected: per the hooks docs, prompt-hook ok:false "maps to permissionDecision: "deny" … blocks the action" — the action, not the turn. Command hooks (exit 2 and permissionDecision: "deny") still behave correctly on 2.1.211 — deny feeds back, turn continues.
Suspected change: 2.1.210's "Fixed a hook callback timeout being misreported to the model as a user rejection…" touching the hook-result path; possibly re-engaging the v2.1.92 "restored preventContinuation:true semantics for non-Stop prompt-type hooks" behavior.
Repro: interactive session; PreToolUse type: "prompt" hook on Bash instructed to deny destructive patterns; run a command the judge blocks (e.g. a recursive delete of a nonexistent path). The turn ends with "PreToolUse:Bash hook stopped continuation". Instructing the judge model to emit "preventContinuation": false in its JSON changes nothing — the stop appears to be harness-asserted, independent of the judge's response.
Secondary observation (possibly its own issue): in headless -p mode, prompt hooks appear to fail open — the judge model returns generic ok:true even when the hook prompt explicitly instructs an unconditional ok:false, so prompt-hook enforcement seems absent in headless runs.
Environment: Claude Code 2.1.210 / 2.1.211, macOS (darwin 25), interactive sessions.
Setup: a
type: "prompt"PreToolUse hook on Bash (LLM security judge using the documented{ok, reason}contract from https://code.claude.com/docs/en/hooks).Before (≤2.1.209): judge
ok:falsedenials fed back to the model asis_errortool_results; the model reacted in-turn. Our session transcripts show 74 such denials from 2.1.179 → 2.1.209 with 100% turn survival (the latest just hours before upgrading to 2.1.210).After (2.1.210+): the same denial emits
attachment.type: "hook_stopped_continuation"and ends the turn:stop_hook_summary; Stop-hook notification sounds/commands don't fire), so the stall is silent;7/7 such events in our transcripts occur on 2.1.210/211; zero on any version ≤2.1.209 (~1,800 transcript files scanned for the exact marker).
Expected: per the hooks docs, prompt-hook
ok:false"maps topermissionDecision: "deny"… blocks the action" — the action, not the turn. Command hooks (exit 2 andpermissionDecision: "deny") still behave correctly on 2.1.211 — deny feeds back, turn continues.Suspected change: 2.1.210's "Fixed a hook callback timeout being misreported to the model as a user rejection…" touching the hook-result path; possibly re-engaging the v2.1.92 "restored
preventContinuation:truesemantics for non-Stop prompt-type hooks" behavior.Repro: interactive session; PreToolUse
type: "prompt"hook on Bash instructed to deny destructive patterns; run a command the judge blocks (e.g. a recursive delete of a nonexistent path). The turn ends with "PreToolUse:Bash hook stopped continuation". Instructing the judge model to emit"preventContinuation": falsein its JSON changes nothing — the stop appears to be harness-asserted, independent of the judge's response.Secondary observation (possibly its own issue): in headless
-pmode, prompt hooks appear to fail open — the judge model returns genericok:trueeven when the hook prompt explicitly instructs an unconditionalok:false, so prompt-hook enforcement seems absent in headless runs.