Skip to content

[BUG] 2.1.284 freezes on first Enter: new sandbox glob expander synchronously walks all of ~ for "~/**/…" denyRead patterns (follows symlinks, unbounded memory); 2.1.280 fine #98023

Description

@PrinceGarth

What's Wrong?

On 2.1.284, the TUI starts normally and slash commands (e.g. /plugin) work, but the moment I press Enter to send a message the session freezes permanently. No response, no redraw, Ctrl-C and SIGTERM do nothing; only SIGKILL ends it. 2.1.280 on the same machine, same config, same directory works normally.

Environment

  • Claude Code 2.1.284, native install (2.1.280 is good; 2.1.284 is the first version I've seen this in)
  • Linux x86_64, kernel 6.8.0
  • Home directory is eCryptfs-encrypted (lower dir /home/.ecryptfs/<user>/.Private)
  • kitty terminal, fish shell
  • Same result with default model and with --model claude-opus-5-5, fresh session and --resume, and when launched from inside $HOME or from /tmp

Evidence (captured from the frozen process)

  1. Main thread is doing filesystem work, not deadlocked. ps -L shows the main thread in D/R state with CPU time growing (~40% of a core); /proc/<pid>/task/<pid>/wchan shows __wait_on_buffer (block-device metadata reads). All other threads are idle (futex_wait_queue, ep_poll).
  2. It is walking the raw eCryptfs lower directory. The only non-socket/pipe fd open is a directory five levels deep in /home/.ecryptfs/<user>/.Private/ECRYPTFS_FNEK_ENCRYPTED.…/…. Claude Code has no reason to be in there.
  3. The walk starts from / (or /home), not from cwd ancestors. Launched from /tmp, it still ends up inside /home/.ecryptfs/….
  4. Memory grows without bound. RSS ~296 MB at startup → 3.16 GB → 3.69 GB about a minute later (system has free RAM, majflt ~0, so not swapping). syscr climbs ~500/s.
  5. The Enter path never begins. On 2.1.280, pressing Enter logs LSP Diagnostics: getLSPDiagnosticAttachments called → prompt.context settled → [API REQUEST] … source=repl_main_thread. On 2.1.284 none of these appear; the debug log simply stops and there is never a session.end / Released PID lock. The event-loop-stall detector never reports the final stall (it never ends).
  6. Signals ignored: SIGTERM and Ctrl-C have no effect once frozen (the handler needs the blocked main thread). Only SIGKILL works.

What Should Happen?

Pressing Enter should send the message. Whatever 2.1.284 walks on submit should be bounded to the project directory (or cwd ancestors, like 2.1.280's $.fs.ancestors check for CLAUDE.md/AGENTS.md, "found 0 of 6 directories"), should not recurse from /, and should skip other mount points such as the eCryptfs lower dir.

Steps to Reproduce

  1. Linux machine with an eCryptfs-encrypted home (probably any large tree under /home or / would reproduce, just more slowly)
  2. Run claude 2.1.284 from any directory ($HOME/... or /tmp)
  3. Type hi, press Enter
  4. UI freezes; ls -l /proc/<pid>/fd shows a directory inside /home/.ecryptfs/...; RSS keeps growing

Is this a regression?

Yes. Last working version: 2.1.280. Broken: 2.1.284 (2.1.281–2.1.283 not tested).

Possibly related

Workaround

Stay on 2.1.280 with the auto-updater disabled.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workinghas reproHas detailed reproduction stepsplatform:linuxIssue specifically occurs on Linuxregression

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions