Repository navigation
fix(server): retry Cursor text generation without sandboxing - #13863
Conversation
|
Macroscope has since reviewed this pull request. An earlier review was skipped by a cost limit; a review has now completed, so that notice no longer applies. |
ApprovabilityVerdict: Not approved Macroscope's review found this PR not approvable — The production text-generation path now falls back to disabling Cursor's OS sandbox, so a temporary working directory does not prevent access to the host filesystem, network, shell, or environment. This materially changes the security posture and has an unresolved critical concern requiring human review. Adjust the Minimum Blocking Severity for this repo — including turning it Off — in Settings. You can add or adjust custom eligibility rules. Learn more. |
|
Reopening so CI runs against t3code/codex-turn-mapping. The pull request was opened against main, which skipped pull_request workflows while the merge was conflicted. |
Thread transfer impact✅ Thread transfer remains within every enforced ceiling.
Baseline: unavailable · PR result: Scenario and decoded snapshot size10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.
Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed. |
What Changed
Retry Cursor text generation without sandboxing when the sandboxed attempt fails.
Why
Cursor can fail to generate text in a sandboxed run. Retrying without sandboxing lets the run recover from that failure.
UI Changes
Not applicable.
Checklist