Repository navigation
Conversation
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 72afcbf1b8561fb4609b6de49c8f067bb03957d7. Configure here.
ApprovabilityVerdict: Not approved Macroscope's review found this PR not approvable — The production change alters every Cursor metadata request by changing its workspace and prompt handling, with tests covering isolation and cleanup. The PR also adds a line-level static-analysis suppression in the test suite, so human review is required. You can add or adjust custom eligibility rules. Learn more. |
b82facd to
2ac9bfe
Compare
|
Macroscope has since reviewed this pull request. An earlier review was skipped by a cost limit; a review has now completed, so that notice no longer applies. |
a7c97c9 to
fd2851c
Compare
|
This PR is too large for Bugbot to review. It changes 99,173 lines and 4,020,811 characters. Split the change into smaller pull requests to get a review. |
04bfcb7 to
de8aa56
Compare
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: pingdotgg/t3code/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: 📥 CommitsReviewing files that changed from the base of the PR and between d6e595c7c1684daeadb8511a39a584f955c76b9a and c0d980a. 📒 Files selected for processing (1)
Included review availability: Your plan provides up to 10 included reviews per hour; 6 remain after this review. 📝 WalkthroughWalkthroughCursor ACP generation now runs in a temporary metadata workspace. Relative binary paths resolve from the source directory. Prompts restrict processing to the supplied input and request JSON-only output. Tests cover workspace isolation, cancellation cleanup, and cleanup failures. ChangesCursor metadata isolation
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Bug fix Sequence Diagram(s)sequenceDiagram
participant TextGeneration
participant FileSystem
participant CursorACP
TextGeneration->>FileSystem: Create temporary metadata workspace
TextGeneration->>CursorACP: Start with isolated cwd and JSON prompt
CursorACP-->>TextGeneration: Return generated metadata
TextGeneration->>FileSystem: Remove workspace on release
Merge Risk: ⚪ Minimal · up to The workspace isolation change has no identified merge-blocking issue after normal checks. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
Independent automated first-pass review (Amp/Astra agent mode) of head de8aa56ba against upstream/main: no findings. Correctness, invariants, edge cases, Effect conventions, and performance all checked; temp-workspace scoping, relative binary-path resolution, and cleanup-on-failure semantics verified sound against the source. Nothing to address, no commits pushed. |
|
Friendly review nudge @juliusmarminge @maria-rcks — this is mergeable and hasn't had a maintainer pass yet. Independent bot/agent reviews have run with findings triaged in-commit (see receipts in earlier comments). Full queue context and status: #10688. |
de8aa56 to
4c68cf2
Compare
d6e595c to
c0d980a
Compare
|
Thanks for working on this. We merged the orchestrator V2 rewrite in #2829, and we are closing this PR as part of that transition. The patch conflicts with the rewrite in apps/server/scripts/acp-mock-agent.ts, apps/server/src/textGeneration/CursorTextGeneration.ts. Even where the conflict is small enough to rebase, we are asking for fresh PRs against the new base so we can review and verify the behavior in V2. Sorry for the extra work this creates. If the change is still needed on V2, please rebuild it on current main, verify it there, and open a new PR linking back here. We're closing the current implementation without assuming the underlying request is resolved. |

Cursor starts metadata requests in the project directory even though their prompts already contain the required input. This exposes title, branch-name, commit-message and PR-text generation to project files and instructions they do not need.
Each request now uses an empty temporary workspace, following the Claude change in #4169. Relative executable paths resolve from the original project. The workspace is removed when the ACP request scope closes, including cancellation; cleanup errors are logged without discarding generated output. This is workspace isolation, not an OS sandbox.
Verified after integrating upstream main 35be904, using Node 24.13.1:
Tests use the mock ACP agent; no live Cursor request or Windows runtime was exercised. No visual UI change.
Fresh independent read-only GPT-6.1 Sol review in the Codex harness found no actionable findings in the complete contribution. The reviewer independently repeated all 13 focused tests.
Earlier preparation: Claude Opus 5 in Claude Code via T3 Code. Current integration and verification: GPT-6 Astra in the Codex harness, via T3 Code.
Independent review: GPT-6.1 Sol in the Codex harness via T3 Code.