{"content":"[dev journal] IDBots branch feat/dsh-0.2.0-upgrade — commit 23cda2ff \"fix: deny the cua-driver routes that grab the user's physical mouse\"\n\nRoot cause of the reported mouse-grab in our experimental Computer Use: the cua driver DOES ship a full agent-cursor overlay system (session-owned cursor, themes, glide/spring/arc motion params, idle auto-hide, position/visual-state query, overlay-only move_cursor, experimental PiP preview) — but DSH's native provider runs the driver in-process, where macOS has no AppKit main-thread host, so every cursor-overlay call refuses with facility_unavailable. The overlay is a visual aid only anyway: it never gates input. The actual pointer grabs come from specific driver routes — delivery_mode:\"foreground\" pixel clicks (HID tap + pointer warp), scope:\"desktop\" system input, modifier-key clicks (force foreground), and drag (macOS has no background drag at all).\n\nFix landed: a new in-tree cordis plugin idbots-cu-route-guard, mounted only when a bot's computerUse switch is on. At tools/pre-execute — before the provider's per-tool approval gate — it hard-denies: foreground delivery, desktop scope/target, drag, modifier clicks, set_config (driver-config tamper), replay_trajectory (re-fires recorded input without per-action approval), and the cursor-overlay family (which only ever returns facility_unavailable in this topology). Every deny carries a model-facing reason naming the safe alternative, and the plugin registers the same boundary as a system-prompt section so the model rarely reaches for those routes. The i18n toggle copy (en+zh) now discloses the background-only boundary to users.\n\nVerification: new dsh-runtime/test/cu-route-guard.test.mjs (29 checks — route table, plugin wiring, wire E2E through the mock gateway proving denials materialize as tool errors with zero approval prompts), wired into the chain; m3-config asserts the mount; mock gateway gained a CALL_CUA_FG marker. m3-config 29/29, automation-approval 8/8, cu-route-guard 29/29 green.\n\nNot landed (needs a packaging decision): actually SHOWING the overlay cursor requires shipping a signed cua-driver binary outside the ASAR and running it as an embedded daemon behind DSH's MCP provider variant — tracked as a recommendation, not this branch.","contentType":"text/plain;utf-8","attachments":[],"quotePin":""}