anthropics / anthropics/claude-code

[BUG] git diff --unified=0 / -U0 triggers a permission prompt despite being read-only

Offen
#92,484 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
area:bash area:permissions bug platform:vscode platform:windows
Vorherrschende Sprache
Python
Sterne
145k
Forks
23.1k
PR-Merge-Kennzahlen
PR-Kennzahlen ausstehend

Beschreibung

### Preflight Checklist

- [x] I have searched [existing issues](https://github.com/anthropics/claude-code/issues?q=is%3Aissue%20state%3Aopen%20label%3Abug) and this hasn't been reported yet
- [x] This is a single bug report (please file separate reports for different bugs)
- [x] I am using the latest version of Claude Code

### What's Wrong?

With no Bash permission rules configured, `git diff` is auto-approved as read-only, but adding a context-count flag escalates it to a prompt.

Prompts:
```
git diff --cached -U0
git diff --cached --unified=0
```
Does not prompt:
```
git diff --cached
```
-U / --unified= only controls how many context lines are printed around each hunk. It has no side effects — it cannot write to the worktree or index, and doesn't change which command runs. It looks like an unconditionally safe formatting flag that the read-only classifier doesn't recognize.

Env: Claude Code VS Code extension 2.1.261, Windows 11, no permissions block in user or project settings.

### What Should Happen?

`git diff -U` should be whitelisted similarly to `git diff`

### Error Messages/Logs

```shell

```

### Steps to Reproduce

Ask claude to run `git diff` and `git diff -U0` from a chat tab in VS Code, and observe how only the latter prompts for permission.

### Claude Model

_No response_

### Is this a regression?

No, this never worked

### Last Working Version

_No response_

### Claude Code Version

2.1.261 (VS Code extension)

### Platform

Anthropic API

### Operating System

Windows

### Terminal/Shell

Other

### Additional Information

_No response_

Beitragsleitfaden

Für dieses Repository ist kein Beitragsleitfaden indexiert

Rechercherichtung

Start from the Bash permission classifier used when Claude Code runs commands from a VS Code chat tab, and compare how it handles `git diff --cached` with `git diff --cached -U0` and `--unified=0`. Trace the argument parsing and existing read-only allowlist, then verify that both unified-context forms avoid a prompt without changing protection for other commands.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
git, vscode
Bereich
cli, security
Issue-Typ
Bug
Schwierigkeit
3/5
Geschätzter Aufwand
1-2 Tage
Aktivitätsstatus
Aktiv
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
55/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.