Skip to content

Permission prompts auto-cancelled with "Session host did not acknowledge 'permission.requested' delivery within 5 seconds"; session gets stuck until exit and resume #5018

Description

@mandyallstars

Describe the bug

In an interactive session, tool calls that need a permission prompt sometimes fail instantly and no prompt is shown. The tool result is:

native tool permission flow failed: GenericFailure, permission host call failed: GenericFailure,
Session host did not acknowledge 'permission.requested' delivery within 5 seconds

The matching permission.completed event is:

{"result": {"kind": "cancelled", "reason": "permission_prompt_delivery_failed"}, "decisionSource": null}

When this starts, it keeps happening for the rest of the burst. Tool calls that don't need a prompt (reads, edits of already-approved paths, pre-approved shell commands) keep working. Any call that needs a prompt fails. The burst ends with a session.error:

Execution failed: Error: Request session.send failed with message: session event delivery failed:
Session host did not acknowledge 'permission.requested' delivery within 5 seconds

At that point the session doesn't accept any more input. The only way to recover is to exit and run copilot --resume. The failure is fail-closed, so it's safe, but work in progress is interrupted and the agent may be mid-task.

Affected version

1.0.88 (all failures observed). Now on 1.0.89; not yet re-observed.

Steps to reproduce

Not deterministic. The common factor we saw is several interactive CLI sessions open at the same time:

  1. Open 4–5 copilot sessions in separate VS Code integrated terminals (Windows, PowerShell 7).
  2. Work in one session for a long time (hours, several auto-compactions) with default permissions, so shell commands regularly prompt.
  3. Eventually a prompt fails as described above, and the failures repeat until session.error.

Evidence (from local events.jsonl, 3 affected sessions)

Session Prompts requested Auto-cancelled (permission_prompt_delivery_failed) Bursts Other CLI sessions active during each burst
A 137 39 2 4
B 114 13 2 4
C 218 13 2 3
  • In every burst, 3–4 other CLI sessions were active on the same machine within the preceding 10 minutes. Isolated one-off failures also happened when 0–2 other sessions were active.
  • Every burst ended with session.error (errorType: "query", then session.send failed), followed by a manual session.resume.
  • open-sessions-state.json still showed old sessions with "working": true days after they ended. This may be related if the host sends prompt delivery to the wrong or a stale session.
  • In the failure windows, calls that didn't need a prompt succeeded normally, e.g. 70 edit and 64 powershell calls in session A. That points to the prompt delivery/ack path, not the tool runtime.
  • Some bursts came right after an auto-compaction, but not all of them.

Expected behavior

  • The permission prompt is shown to the user, or
  • if delivery to the UI really fails, the CLI retries or re-attaches instead of permanently breaking session.send, so the session keeps working without an exit and resume.
  • A 5-second ack timeout seems short for a busy host with several sessions; making it configurable or retrying it would help.

Environment

  • OS: Windows 11 (10.0.26200)
  • Shell: PowerShell 7.6.6
  • Terminal: VS Code integrated terminal
  • Model: claude-opus-5.5 (also seen with claude-sonnet-5)
  • Multiple concurrent interactive sessions, same user and machine

Related

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:permissionsTool approval, security boundaries, sandbox mode, and directory restrictionsarea:sessionsSession management, resume, history, session picker, and session state

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions