{"version":"2.1.290","anchor":"own-made-delete-rm-of-files-the-session-just-created-can-be","canonical_anchor":"own-made-delete-rm-of-files-the-session-just-created-can-be","heading":"Cloud sessions can delete files they created themselves without asking","tier":"notice","area":"Permissions","scope":"individual","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290\/e\/own-made-delete-rm-of-files-the-session-just-created-can-be","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290","markdown":"### Cloud sessions can delete files they created themselves without asking\n\nRemote tool serving gains an own-made delete check so an rm of files the session itself just created can skip the prompt, plus a new trust message\n\n**Unclear.** What switches this on, and whether it applies outside remote sessions, is unclear.\n\n**What**\n\nClaude Code can let a cloud session use tools on your own computer. This is called remote tool serving. A new check, `ownMadeDelete`, lets such a session remove files and folders it created itself without asking you first. The session keeps a record of what it made with `mkdir`, `touch` or the Write tool, the tool Claude uses to create files. A later delete can go ahead only if Claude Code can prove the delete touches nothing else.\n\n- Only a single `rm` command qualifies, and only with the flags `-r`, `-f`, `-d` and `-v`.\n\n- Every target must be on the session's record and unchanged since it was created. The removal runs through a folder that was held open in advance, so the folder cannot be swapped out in the meantime.\n\n- The check declines in a sandbox (a walled-off area that limits what commands can touch), when owner rules apply, when the session is busy, on Windows, for masked paths, and in other cases.\n\n- Several new refusal messages explain a decline. One says the files could not be checked again just before removal, so nothing was removed, and asks for the command to be sent again.\n\n- In permission handling, a delete that would otherwise be blocked can be let through when `ownMadeDelete` is on and the check agrees. An approved delete is then recorded.\n\n- The `own_record` unattended setting now gives a \"consent\" answer. Unattended means nobody is present to answer permission prompts.\n\n- Permission prompts gain new text, `ask.settings_person_only`, for shell commands whose writes could not be worked out. A shell command is a command typed into a terminal.\n\n- Two new internal names, `mcpPathWhy` and `serverAskUnderPlanFloor`, were added. What they do was not traced.\n\n- The `not_marked` repository-trust refusal changed. It used to tell Claude to start a new session or use one with nothing attached. It now tells Claude to call a trust tool once and put the question to you.\n\nThe serving path sits behind `tengu_remote_tool_serve`. Nothing has been read about that gate.\n\n**Why**\n\nA cloud session that cleans up its own scratch files no longer needs to stop and ask each time. The proof is narrow, so files the session did not make, or that changed after it made them, still go through the normal permission checks. A trust refusal now leads to one question for you instead of telling Claude to start over.\n\n- Area: Permissions\n- Tier: You'll notice\n- Useful: 3\/5\n- Signal: 2\/5\n- Scope: individual\n- Heads-up: no"}