Retain Cursor pack proof after credential and receipt review fixes

Record the exact reviewed runtime source, clean dependency resolution, pack and native closure digests, and a credential-free launch through the generic installation registry. Keep authenticated and Daytona qualification explicitly pending.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
This commit is contained in:
DottaandPaperclip committed 2026-09-28 15:16:00 -05:00
1 parent eb0f43c45a
commit e5fa1cff1f
3 files changed
+16 -16

No files matched your search

@@ -51,7 +51,7 @@ The documentation calls todo/task/image methods notifications. The pinned presen
Question and plan requests lack a session ID. The shared hook binds them to the retained connection, active execution/session/turn and originating request ID; it rejects stale/duplicate answers, cancels on turn termination, persists requests before exposing them, and awaits exact JSON-RPC pipe-write delivery before recording a resolved interaction. This proves transport handoff, not an additional provider application-level acknowledgement. The provider module does not substitute a best-guess session.
Fixed launch arguments are `--disable-project-configs --disable-auto-update acp`, using the verified bundled Node and absolute verified `index.js`. Private HOME/XDG roots are required together with CURSOR_CONFIG_DIR, CURSOR_DATA_DIR, a private compile cache, `AGENT_CLI_CREDENTIAL_STORE=memory`, and `NO_OPEN_BROWSER=1`. Only explicitly bound CURSOR_API_KEY or CURSOR_AUTH_TOKEN may enter; never inherit shell credentials. Do not use `--force`, `--trust`, or `--approve-mcps` to paper over governance.
Fixed launch arguments are `--disable-project-configs --disable-auto-update acp`, using the verified bundled Node and absolute verified `index.js`. Private HOME/XDG roots are required together with CURSOR_CONFIG_DIR, CURSOR_DATA_DIR, disabled compilation caching, `AGENT_CLI_CREDENTIAL_STORE=memory`, and `NO_OPEN_BROWSER=1`. Only explicitly bound CURSOR_API_KEY or CURSOR_AUTH_TOKEN may enter. The controller creates a provider/session-scoped credential-name binding from the explicit task environment, ignoring inherited or caller-supplied markers. Rust forwards it through the closed sidecar environment boundary. Before host admission, the sidecar rejects missing, stale, wrong-provider or unbound credentials and removes the marker before provider launch. Tests cover this full boundary and preserve legacy credential behavior. Do not use `--force`, `--trust`, or `--approve-mcps` to paper over governance.
`--disable-project-configs` only suppresses `.cursor/cli.json`. It does not suppress project MCP, Cursor/Claude hooks, or installed plugins. `assertCursorWorkspacePolicy` refuses ambient project execution config from the workspace through its nearest Git root, including symlinks and unreadable configuration. Ordinary Claude settings with neither hooks nor plugins remain admissible. Enterprise system hooks are checked too. The host repeats admission checks before native launch. Continuous protection of these config paths during execution remains a qualification requirement. Admission alone cannot prevent a concurrent file mutation. Team-provided remote hooks are another upstream boundary and remain unqualified under restrictive execution.
@@ -80,20 +80,20 @@ Pinned source creates a separate session-update presenter for every child and ca
Child assistant/reasoning text, plan steps and tool lifecycle are displayed in each child's activity summary. The 4,000-character activity surface retains a clearly marked tail when it fills; this is a summary, not a complete nested transcript. Child tool raw input/output, locations, diffs, media content and other child update fields are not rendered by this summary surface and produce explicit partial-detail notices. Adding canonical child transcript/tool surfaces is the next priority for these meaningful exposed fields. Native `capabilities:{}` currently carries no populated child capability fields; `_meta.cursor.agentId` and `toolCallId` are retained internally for immutable origin checks. Nested parent identity is represented in activity metadata because canonical delegation has no parent-child relation field. Native `disconnected` now yields a failed child with a visible explanation, never a successful completion.
Three real ACP stream tests prove child lifecycle/transcript preservation before SDK parsing, nested parent attribution, standard parent parsing, and old-stream/turn/connection fences. Existing nine shared extension and Pi receipt package tests pass unchanged against the resulting patched package. Three native factory cases verify all platform pins, exact profiles, and rejection of unsupported distributions; native assets resolve only from the runner-owned package authority.
Three real ACP stream tests prove child lifecycle/transcript preservation before SDK parsing, nested parent attribution, standard parent parsing, and old-stream/turn/connection fences. Shared extension, reply-delivery and Pi receipt package cases pass against the resulting patched package; the current totals are recorded below. Three native factory cases verify all platform pins, exact profiles, and rejection of unsupported distributions; native assets resolve only from the runner-owned package authority.
## Integrated pack and offline launch evidence
The full `build-provider-pack.mjs --candidate-providers=cursor` path passed on source `1055c13f8cffd8c06070eb6403d3beff83e64374` (foundation includes upstream master `14795136f56c11ed83dc754791945bb5a0b8f7fd`). It used standalone Node, pnpm 9.15.4, a fresh production deployment and the pinned vendor archive. The build checked portable Node relocation, fresh ACPX import and complete Cursor materialization. The retained manifest is `packages/paperclip-runner/test/fixtures/cursor-acp/provider-pack-darwin-arm64.json`; it contains only relative paths and digests.
The full `build-provider-pack.mjs --candidate-providers=cursor` path passed on source `1324437f4ce4031e646738aae5a09c314f51e21e` (foundation includes upstream master `14795136f56c11ed83dc754791945bb5a0b8f7fd`). It used standalone Node, pnpm 9.15.4, a fresh production deployment and the pinned vendor archive. The build checked portable Node relocation, fresh ACPX import and complete Cursor materialization. The retained manifest is `packages/paperclip-runner/test/fixtures/cursor-acp/provider-pack-darwin-arm64.json`; it contains only relative paths and digests.
- Pack digest: `sha256:480ae2eaa7a61852533286648911304fa1e47d2e40e80dcc19f0cce0149cb77e`.
- Pack digest: `sha256:0631f2e7541b03e0becd15fd9ea51be1f913faa3f5350c2e207827f692176675`.
- Cursor declaration: `sha256:1157a5d071abbd57ab132f22bace75c65e84cc47a045b0023475488755e14899`.
- macOS ARM64 closure: `sha256:77394184a89b0e7384971181da19c3c82d83a399b04e7944b3f94fe3d7e62b25`.
- Resolved dependency lock: `sha256:774e3070ecba7bedaf70502a1a85bc05df535db1b34462b389de49031b6b8232`, also the reviewed Daytona build digest for this branch. CI regenerates the lock from source-owned patches and rejects a different digest before execution.
- Resolved dependency lock: `sha256:ec689ad9c31aa2004c7c2c39889764d55897ac2e6d899c8f059d9c23b082c2c8`, also the reviewed Daytona build digest for this branch. This digest was resolved from the clean tracked lock with the exact Docker resolution-only command. The frozen install retained it. Image creation rejects a different digest before execution.
`provider-pack-offline-proof.json` records a real launch through the generic profile installation registry from the pack’s verified native closure and retained snapshot, using private directories and no credentials. ACP v1 initialize succeeds. The correct `cursor/list_available_models`, `session/list` and `session/new` methods return authentication-required; `session/fork` and `session/resume` return method-not-found. The process produced no stderr, was explicitly terminated after these probes, and its lease closed. The earlier discovery fixture’s `_cursor/list_available_models` probe used an incorrect method prefix; this later probe corrects that uncertainty without changing the original evidence.
At the initial integration checkpoint, 17 Cursor Vitest cases, 28 installed ACPX/materializer Node cases, and 6 Daytona image-content cases passed. After the final foundation rebase to `5aeebb20c`, TypeScript/verified-sidecar build, all 17 Cursor cases, and 11 installed extension-hook/materializer Node cases passed again. The fresh pack/probe above binds this final runtime source. Its explicit offline factory model sentinel is not an authenticated model selection; no ACP prompt was sent. Daytona content identity includes the candidate selection, Cursor materializer and distribution manifest. This is local macOS ARM64 packaging/initialization evidence only. It does not qualify Linux execution, a Daytona image build/run, authenticated model work, permissions, or dollar accounting. No screenshot is claimed for these headless tests. Total billable prompts and spend remain zero.
At the initial integration checkpoint, 17 Cursor Vitest cases, 28 installed ACPX/materializer Node cases, and 6 Daytona image-content cases passed. After review fixes and the final foundation rebase to `f80c312cd`, TypeScript/verified-sidecar build, all 30 Cursor/credential cases, 29 installed ACPX/materializer Node cases, and 6 Daytona image-content cases passed. This source includes provider/session credential bindings and preservation of actual usage receipts on terminal provider failure. The fresh pack/probe above binds these final runtime bytes; previous pack evidence remains in Git history. Its explicit offline factory model sentinel is not an authenticated model selection; no ACP prompt was sent. Daytona content identity includes the candidate selection, Cursor materializer and distribution manifest. This is local macOS ARM64 packaging/initialization evidence only. It does not qualify Linux execution, a Daytona image build/run, authenticated model work, permissions, or dollar accounting. No screenshot is claimed for these headless tests. Total billable prompts and spend remain zero.
## Exact remaining field audit
@@ -1,6 +1,6 @@
{
"schema": "paperclip-runner/remote-provider-pack/v1",
"digest": "sha256:480ae2eaa7a61852533286648911304fa1e47d2e40e80dcc19f0cce0149cb77e",
"digest": "sha256:0631f2e7541b03e0becd15fd9ea51be1f913faa3f5350c2e207827f692176675",
"payload": {
"pins": {
"nodeMinimum": "24.11.0",
@@ -14,9 +14,9 @@
"platform": "darwin",
"architecture": "arm64"
},
"runnerSourceRevision": "1055c13f8cffd8c06070eb6403d3beff83e64374",
"distDigest": "sha256:4f7303572ec9f64a54b9fc8d766c007c88119711b601a0294b54a81367ddd888",
"bridgeDigest": "sha256:acc33db0c5c261aa4e9792f8cbbf8b7edff5ff6234555c20d72ea12c1388d8d9",
"runnerSourceRevision": "1324437f4ce4031e646738aae5a09c314f51e21e",
"distDigest": "sha256:779d392f23d47cde795143dcf2df4e36a3a0c04d1ee983d1a19b8bdbfb7f3220",
"bridgeDigest": "sha256:19d8ae1df8c87e97d2abba0a7249e400e64218a71a3ffe99e7baf886d8b85ff2",
"acpxProfileDigests": {
"claude": "sha256:9d73d1f0f121fb96cc8badb28c22d5bff02d8582eb2e40360a81c189e1b9422a",
"codex": "sha256:c4538599d1ab767db5dff50934f13bb5ba313a59d9c4a83e993fac4617ea63d3"
@@ -38,7 +38,7 @@
},
"productionLock": {
"path": "pnpm-lock.yaml",
"sha256": "sha256:e0c928a494f90ddad3c00791e83f09315ee8c82df2a0418a809dcf93649a8ab3"
"sha256": "sha256:ec689ad9c31aa2004c7c2c39889764d55897ac2e6d899c8f059d9c23b082c2c8"
},
"opencodeCommand": {
"path": "node_modules/.bin/opencode",
@@ -54,7 +54,7 @@
},
"acpxSidecar": {
"path": "dist/cli/acpx-runtime-sidecar.cjs",
"sha256": "sha256:731d577d16afb6eccc03328261ec7bc9e21f302e9154c99185cc2410283facfa"
"sha256": "sha256:b0c2c42374f8f6dc7a9a4b3a31f3cc94cd8e9e74a5934441188c2ec1fc33e9f9"
}
}
}
@@ -1,8 +1,8 @@
{
"schema": "paperclip-cursor-offline-pack-proof/v1",
"capturedAt": "2026-09-28T17:33:30.123Z",
"runnerSourceRevision": "1055c13f8cffd8c06070eb6403d3beff83e64374",
"packDigest": "sha256:480ae2eaa7a61852533286648911304fa1e47d2e40e80dcc19f0cce0149cb77e",
"capturedAt": "2026-09-28T18:04:33.552Z",
"runnerSourceRevision": "1324437f4ce4031e646738aae5a09c314f51e21e",
"packDigest": "sha256:0631f2e7541b03e0becd15fd9ea51be1f913faa3f5350c2e207827f692176675",
"target": {
"platform": "darwin",
"architecture": "arm64"
@@ -15,7 +15,7 @@
"path": "provider-assets/cursor/darwin-arm64",
"sha256": "sha256:3b6de19114d4df62f648604025a0d71937dfa7c2b15b397cce5da2c5da268994"
},
"productionLock": "sha256:e0c928a494f90ddad3c00791e83f09315ee8c82df2a0418a809dcf93649a8ab3",
"productionLock": "sha256:ec689ad9c31aa2004c7c2c39889764d55897ac2e6d899c8f059d9c23b082c2c8",
"launch": {
"entrypoint": "verified bundled node + index.js",
"arguments": [