What
A computer can serve a cloud session, meaning a session started in the cloud runs its commands on that machine. How settings apply in that situation changed.
- Project settings files are recorded when the session attaches, and later changes to them are held back. They apply only after you run
claude apply-project-settingsin a terminal in that folder to review them. The settings are applied again when the session ends. - Three new messages cover held-back settings, settings taken as found, and folder hooks and plugin settings not being used. The old message saying a change applies to the session now using this computer was removed.
- Command text now says that commands start in the project folder and that a
cdcarries over. - Behind
tengu_quiet_locket, your user settings are recorded at attach and merged in a way that can only restrict. Deny and ask rules and sandbox deny lists are added, while an allow rule is kept only if both sides have it. Restrictions that come from your settings, such asread_blockorauto_mode_off, are recorded. If the recorded settings cannot be read, the session stops with an error telling you to runclaude apply-project-settings. The flag server returned on for this site's account and for the anonymous baseline, but no reading has been taken under this release yet. - The MCP policy decided at attach now also receives those user settings (
userSettingsAtAttach). MCP servers are add-ons that give Claude extra tools.
Why
A cloud session can no longer change project settings and have them take effect on your own machine without your review. Your local permission rules can tighten what the session may do but cannot loosen it.
tengu_quiet_locket Gate removed from the codeThis release deleted the gate from the code while it was still reading on for the account this site reads, so the code path no longer asks a flag before running.
This account: on · anonymous baseline: on · compiled default in v2.1.288: not a boolean we can read
These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.
Read once, for one account on one subscription tier, against v2.1.288. It isn't a statement about your account. What a flag value here can and cannot tell you
The code path no longer asks a flag before it runs.
What the switch falls back to when the server sends nothing is not known.