Where does the bug appear (feature/product)?
Cursor IDE
Describe the Bug
Version: 3.15.6 (user setup)
VS Code Extension API: 1.128.0
Commit: a1f686545fd0ce8917bbd2449f733551a9bce420
Date: 2026-08-06T01:41:03.876Z
Layout: Agent Window
Build Type: Stable
Release Track: Default
Electron: 40.10.3
Chromium: 144.0.7559.236
Node.js: 24.15.0
V8: 14.4.258.32-electron.0
xterm.js: 6.1.0-beta.291
OS: Windows_NT x64 10.0.26200
July 31 is not the root cause. That outage was ~1.4 hours and resolved. What keeps freezing this seat is a five-layer local+product class measured here from 08-05 onward.
Full write-up: dgl/state/reviews/Soft-DIAG-cursor-Operator-freeze-since-0731-five-layers-diagnosis-and-fix-plan-cursor-2026-08-09.md
What’s actually breaking
Layer What happens Who fixes it
A Soft-token generation loop
Packets/chats fill with repeated Soft until the IDE hangs
Lane SOP + Cursor product stop-sequences
B Poison files on disk
Grep/Read over state/reviews stalls on bloated Soft blobs
Lane quarantine (cleaned Soft-CONSENSUS ~81KB→1KB this turn)
C Ghost metronome load
Extra draft/liveness junk
Already deleted 08-08
D Windows Shell sandbox hardfail
Terminal never starts; looks frozen
Host config (mostly done)
E Renderer memory leak
Long agent sessions kill the window
Cursor Inc. (known forum class)
This sitting just demonstrated A: the first DIAG write blew to ~85KB of token-loop and had to be overwritten clean.
Fix plan (what gets you a working agent)
You (minutes)
Agents → Auto-Run: plain Allowlist / Auto-review — not a “…with Sandbox” mode → Reload Window.
Confirm both C:\dfd-repo.cursor\sandbox.json and ~.cursor\sandbox.json are “type”:“insecure_none”.
After any freeze: new chat — don’t resume a mid-stream Soft-loop chat.
Cap concurrent agent fleets / very long single-chat tool history (layer E).
Cursor support / product (the $60 gap)
Bug: Soft Soft Soft generation runaway (no stop-sequence).
Bug: Windows workspace_readwrite sandbox hardfail (no FS isolation backend).
Track: renderer memory leak on long agent workflows.
Until A+E land upstream: this seat can stay honest as a static claim-shape lens. It is not yet a safe full Shell/battery autonomous agent. Calling four-lane lands “COMPLETE” while Cursor goes dark mid-rung is overclaim — three Claude + Cursor postland is the honest label.
Already true here: Soft FIX SOP in rules, sandbox insecure_none, legacy terminal tool, Soft-CONSENSUS quarantined, DFD-CousinHarness Ready, COUSIN_API_KEY set. Event-wake re-arm was Auto-review blocked this turn (Soft-BLOCKED-…-2026-08-09.md) — Allow that Shell once if you want the in-chat doorbell live.
Steps to Reproduce
Simply running cursor. Every run has this happen
The Soft ACK write hit the token-loop again. Overwriting it clean, then answering in chat.
Avoiding the Soft Soft Soft phrase in the file write — that phrase is what triggers the loop.
-
Good — Agent Auto-Run/Allowlist is already correct. That closes the UI half of layer D.
-
sandbox.json is not a Settings toggle. It’s a config file on disk. Yours are already correct:
Expected Behavior
Not freeze in a Soft ACK loop
Operating System
Windows 10/11
Version Information
Version: 3.15.6 (user setup)
VS Code Extension API: 1.128.0
Commit: a1f686545fd0ce8917bbd2449f733551a9bce420
Date: 2026-08-06T01:41:03.876Z
Layout: Agent Window
Build Type: Stable
Release Track: Default
Electron: 40.10.3
Chromium: 144.0.7559.236
Node.js: 24.15.0
V8: 14.4.258.32-electron.0
xterm.js: 6.1.0-beta.291
OS: Windows_NT x64 10.0.26200
For AI issues: which model did you use?
Cursor Grok 4.5
GPT 5.6 SOL
Composer 2.5
Additional Information
Cursor is running an adversarial review lane by reviewing the build cycles of other agents. This is a review lane only; no Bash, no write permissions other than communicating on the bus.
Does this stop you from using Cursor
Sometimes - I can sometimes use Cursor