Daily harness signal

Stop a hidden grep from exhausting the host

August 10, 2026 · JST One fresh finding Claude Code · Bash · resource guard
Claude Code’s Bash grep is not necessarily system grep. A bounded-repeat pattern can turn its hidden ugrep applet into a host-wide OOM, so gate the syntax before dispatch.
01 · Fresh · source date 2026-08-08

Guard the command shape, not the model’s intent

Use when: Claude Code native builds on macOS or Linux may run agent-written Bash searches, especially context-extraction patterns such as [^.]{0,110}keyword[^.]{0,90}. Since v2.1.117, plain grep inside the Bash tool can be a shell function that re-executes Claude Code’s embedded ugrep, not the system binary.

Action: add a global PreToolUse hook with "matcher":"Bash" and "command":"python3 ~/.claude/hooks/block-regex-bomb.py". The parser must inspect .tool_input.command with shell-aware tokenization; for each bare grep, egrep, or fgrep segment that is not path-qualified or preceded by command, return permissionDecision:"deny" when the segment contains at least two ranged quantifiers {n,m} or {n,} and an upper bound is at least 10. Route the retry to Claude’s built-in Grep tool or command grep. Do not rely on an AGENTS.md warning alone.

Acceptance check: feed the hook synthetic PreToolUse JSON whose command is grep -E '[^.]{0,16}x[^.]{0,16}' /dev/null. Pass only if it returns a deny decision without starting grep. Repeat with command grep, one bounded repeat, a literal recursive search, malformed JSON, and a non-Bash payload; all must pass through. Then start a fresh Claude session and request the hazardous bare command. The tool trace must show the hook denial and no ugrep child.

Evidence: independent Claude Code issue reproductions cover Linux x86-64, aarch64, WSL2, and macOS arm64. One zero-input case reached 14.3 GB before failing; a two-line macOS fixture crossed 512 MiB in 1.312 seconds. The upstream ugrep maintainer merged a nine-line position-count cap with tests, reducing the canonical case to 155 MB and 0.59 seconds. Claude Code 2.1.226 still published no corresponding fix.

Caveat: Anthropic has not confirmed the open reports, and this run did not execute the resource-exhaustion reproduction. The narrow gate covers the measured bounded-repeat family, not every pathological regex or shell construction. Keep a process-level memory ceiling for unattended workers; after Anthropic ships and you verify a bundled ugrep with the upstream cap, retire the syntax guard only after the canary fails closed.

Compact source notes

  1. Claude Code issue #84960 (2026-08-08). Fresh incident, process-chain diagnosis, bounded-repeat measurements, tested deterministic hook, and explicit corrections to earlier version/subagent hypotheses.
  2. Claude Code issue #83342 (2026-08-02; cross-platform updates through 2026-08-07). Zero-input reproduction plus Linux, Raspberry Pi, macOS, and WSL observations; still open.
  3. ugrep issue #555 and merged PR #556 (2026-08-02/03). Upstream root cause, nine-line complexity cap, test matrix, and before/after resource measurements.
  4. Claude Code v2.1.117 (origin of embedded Bash grep on native macOS/Linux) and v2.1.226 (2026-08-08; no disclosed repair).
  5. Method: anchor lens—cross-platform minimal fixtures, process arguments, measured RSS, hook receipts, and an upstream tested patch; unity lens—model-written commands and hidden applets share one execution-resource boundary. A current native build that reports a capped complexity error without the hook would weaken the need for this guard. Confidence: Likely.