-
Notifications
You must be signed in to change notification settings - Fork 3
plat 376
| Coordination | Value |
|---|---|
| State | fixed on main; RTS deploy pending |
| Severity | P1 (admins could not inspect or check the server's Cursor account) |
| Date | 2026-10-03 |
| Owner | security-sandbox |
| Related | personal-account terminal confinement (provider_setup_confine.go, docs/DECISIONS.md 2026-10-01) |
On RTS, Providers → Cursor → Admin-managed account → open the terminal printed
SANDBOX_UNAVAILABLE: enter working directory: chdir : no such file or directory.
The RTS log shows cursor-cli inspect for server account (HOME service HOME).
Only personal accounts are meant to be confined to their private home; the
server's own account (admin-managed) keeps its service home. The start code
decided "personal" with bindingID != provider, but the admin-managed account's
binding is global:cursor-cli, so it counted as personal and was started under
the Landlock launcher with no working folder.
providerSetupIsPersonalBinding treats a global: binding as the server
account, so it is not confined. Personal accounts are unchanged.
Test: TestProviderSetupConfinesOnlyPersonalAccounts.
Auto-synced from docs/ on main. Edit there, not here.