{"version":"2.1.295","anchor":"self-hosted-runner-can-forward-server-auto-mode-lists-into-s","canonical_anchor":"self-hosted-runner-can-forward-server-auto-mode-lists-into-s","heading":"Self-hosted runners can pass server auto-mode rules into sessions","tier":"notice","area":"Self-Hosted Runners","scope":"org","heads_up":true,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.295\/e\/self-hosted-runner-can-forward-server-auto-mode-lists-into-s","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.295","markdown":"### Self-hosted runners can pass server auto-mode rules into sessions\n\nSelf-hosted runners can now write server-supplied `autoMode` allow, environment and soft-deny lists into sessions, with allow lists withheld by default\n\n**What**\n\nAuto mode lets a classifier (an automatic checker) decide whether Claude may use a tool without asking you, and `autoMode` settings add your own allow and deny rules to it. A self-hosted runner, the program that starts Claude Code sessions on your own machines, can now forward these rules from the server:\n\n- A new `--server-auto-mode-lists` option takes `all`, `no-allow` or `none`. The default `no-allow` withholds the server's allow list. The runner sends this choice when it registers (`server_auto_mode_lists`) and logs it when it differs from the default.\n\n- The server's `autoMode` block (allow, environment and soft_deny lists) is written into `launcher-settings.json` for the session. Before, that file held only hooks.\n\n- It is only applied when `CCR_AUTO_MODE_APPLY` is `1`. Entries that are blank or contain control characters are refused, and the whole block is dropped if it would go over the `--settings` size limit.\n\n- The runner logs whether the server asked it to apply the lists, and when it is not applying them.\n\n- The session started by the runner now has `CCR_AUTO_MODE_APPLY`, `CCR_AUTO_MODE_ALLOW`, `CCR_AUTO_MODE_ENVIRONMENT` and `CCR_AUTO_MODE_SOFT_DENY` cleared, so inherited or server-supplied values for them cannot reach it.\n\n- Starting a session now reports whether writing to its input succeeded, and the runner sets up a watch that is fed by the health server and stopped on exit.\n\n**Why**\n\nAdmins of self-hosted runners can push auto-mode rules into sessions, while allow rules, which let actions through without checks, are held back unless chosen. Clearing the variables keeps the runner's own environment from slipping rules into sessions.\n\n- Area: Self-Hosted Runners\n- Names: `autoMode`\n- Tier: You'll notice\n- Useful: 3\/5\n- Signal: 3\/5\n- Scope: org\n- Heads-up: yes"}