6254b6e81b
Every native `pi_edit` failed after a session switched onto Cursor. The replace-mode `edit` instance the frame needs was built only for sessions CREATED on Cursor, and the tool roster is built once, at creation - a session that started elsewhere kept its configured-mode `edit` in the registry, which `executeTool` resolves before its fallback, so the frame's `old_text`/`new_text` pairs failed validation against a `hashline` schema. The instance is now built from the `edit` grant regardless of the initial provider, lazily so a session that never reaches Cursor never constructs one, and `pi_edit` asks for it through a dedicated `getEditReplaceTool` accessor rather than relying on Cursor sessions having deleted `edit` from the registry. A session that was never granted `edit` is still refused. That accessor also closes an escalation the previous wiring opened up. The session's device resolver is handed to the bridge as `getTool` and installed as the agent loop's `resolveFallbackTool`, which runs for ANY call outside the advertised set - so serving `edit` from it let a hallucinated call, or one naming a tool the session deselected after startup, execute a replace-mode edit the model was never offered. It is device-only again. Regressions cover both directions at the SDK level, driving a real unadvertised `edit` through the loop and asserting the surfaced `Tool edit not found`: an unchanged file alone would also pass if the fallback had resolved the tool and the edit then failed validation. (cherry picked from commit 11a28dcf7b995a9e94913269733b3199d6f4790d)