Skip to content

Isolate cursor MCP identity per seat (provider-config overlay) - #26

Open
Florious95 wants to merge 4 commits into
feature/pi-provider-c-teammatefrom
feat/cursor-per-seat-mcp
Open

Isolate cursor MCP identity per seat (provider-config overlay)#26
Florious95 wants to merge 4 commits into
feature/pi-provider-c-teammatefrom
feat/cursor-per-seat-mcp

Conversation

@Florious95

@Florious95 Florious95 commented Aug 22, 2026

Copy link
Copy Markdown
Owner

Goal

Isolate Cursor MCP identity per seat with a provider-config overlay while preserving the Pi and Grok launch and restart paths from the stacked provider PRs.

0.5.68 replay identity

Old to new replay mapping:

  1. cc9cd2ef0e5a26d36a88116e77e0742ab0206fb9 -> e3349eb3f9d113c3bc67e1a27831a1abeba4178e
  2. 0bd7ebb37fbd043f5a3831febe34a9ae5153a3fe -> 4251c557f135e4a895bf29c6de3a7d6c3aad5530

The replay then contains two explicitly reviewed test-only new-base corrections:

  • 84613482e0560440c901cea1d9284358d84b2881: named Cursor isolation serial clique for the 13 tests that read or write the process-global isolation key; no product timeout or retry change.
  • 5db401db941ea9c7aae44c0b56e2b4fd4ee02d3e: causal bounded-diagnostic secret oracle while preserving the 512-byte cap and redaction assertions.

Per-seat identity remains under .team/runtime/provider-config/<id>/cursor/.cursor/mcp.json; HOME is unchanged, the physical workspace remains --add-dir, shared identity is scrubbed, and failure diagnostics remain fail-closed and bounded.

Evidence status

Local replay records: frontier/replay/p26.md, frontier/replay/p26-review-grok.md, and frontier/replay/replay-manifest.md.

Historical evidence retained only for provenance:

  • old parked head 0bd7ebb3
  • cursor-teammate-isolation/g17-precompiled-team-two-seat.md
  • cursor-teammate-isolation/g18-final-independent-audit.md

The old real Cursor campaign, checks, and evidence remain historical only; they do not accept the rewritten remote history.

Acceptance boundary

This update installs the reviewed local replay identity only. It does not claim taskbook sections 10-12 combined acceptance, a new real Cursor campaign, repository-wide or full-suite green, merge readiness, release, or publish authorization. PR #102 remains the dependent Grok layer. Keep this PR open and unmerged.

@Florious95
Florious95 force-pushed the feat/cursor-per-seat-mcp branch from 0bd7ebb to 5db401d Compare August 30, 2026 12:20
@Florious95
Florious95 changed the base branch from integration/0.5.x to feature/pi-provider-c-teammate August 30, 2026 12:21
Stop writing TEAM_AGENT_ID into the shared project mcp.json (and do not
fork HOME). Point --workspace at provider-config/<id>/cursor and --add-dir
at the real workspace, matching grok's shared-file vs per-seat split.

Co-authored-by: Cursor <cursoragent@cursor.com>

Replay-From: cc9cd2e

Replay-Old-Parent: f0afc7a
Replay-From: 0bd7ebb

Replay-Old-Parent: cc9cd2e
Keep the default-thread Cursor MCP module deterministic by placing its 13 tests in the dedicated cursor_mcp_isolation serial clique. Preserve the separate env clique for HTTPS_PROXY and isolation-off mutators.

Ruling: frontier/replay/p26-env-race-ruling.md
Place the synthetic secret line before the >512-byte benign padding so disabling the redaction filter reaches the existing no-secret assertions. Keep the 512-byte boundary and total-length assertions unchanged.
@Florious95
Florious95 force-pushed the feature/pi-provider-c-teammate branch from 5e4872d to 2fe347e Compare August 30, 2026 14:29
@Florious95
Florious95 force-pushed the feat/cursor-per-seat-mcp branch from 5db401d to e3039c5 Compare August 30, 2026 14:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant