Skip to content

agentHost: integrate managed network boundaries and sandbox preferences - #340162

Closed
Ross Wollman (rwoll) wants to merge 5 commits into
mainfrom
rwoll/limitto-04-sandbox-preferences
Closed

Ross Wollman (rwoll) wants to merge 5 commits into
mainfrom
rwoll/limitto-04-sandbox-preferences

Conversation

@rwoll

@rwoll Ross Wollman (rwoll) commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

Draft. Includes the SDK/runtime prerequisite for now; rebase out that bump once it lands independently on main. Cross-platform acceptance remains pending.

Adopt the SDK's new permissions.limitTo directive (github/copilot-agent-runtime#23922) and bridge VS Code's policy-managed chat.agent.sandbox.network.allowedDomains to it when chat.agent.networkFilter is policy-enabled.

Policy examples

Native managed-settings JSON:

An admin wants to hard-block native agent access to unapproved destinations, while permitting internal documentation and a package mirror.

{
  "permissions": {
    "limitTo": [
      "Domain(docs.corp.example)",
      "Domain(packages.corp.example)"
    ]
  }
}

The agent can request internal docs and mirror downloads, subject to normal approvals. Fetching a public registry or an arbitrary upload endpoint is denied, even in Allow All. These are illustrative exact hosts; admins must include any additional required download/redirect hosts.

The admin also wants users to approve each HTTPS fetch of internal documentation, without letting approval bypass the boundary.

Add "ask": ["Domain(https://docs.corp.example)"] under permissions above. Documentation fetches require human approval even in Allow All; the package mirror keeps normal approval behavior. Unapproved hosts remain blocked rather than offered an override.

An admin wants local-only maintenance: inspect code and run local commands, but hard-block network access by native runtime tools.

{
  "permissions": {
    "limitTo": []
  }
}

Native fetches are denied and the runtime applies a mandatory sandbox network floor. Local file and shell work remain subject to other permissions; commands that need network access cannot complete. This is not an offline model mode. Omitting limitTo instead contributes no boundary from this field; other policies still apply.

Upcoming

  • Agent Host integrated-browser enforcement, once the runtime exposes a URL decision/projection contract.
  • Local-harness browser enforcement using the same runtime-owned policy contract.
  • Cross-platform and shared-host acceptance coverage, diagnostics, and rollout readiness.

🤖 Authored with GitHub Copilot on behalf of Ross Wollman (@rwoll).

Ross Wollman (rwoll) and others added 4 commits October 6, 2026 11:51
Update desktop and remote to SDK 1.0.17-preview.8 / runtime 1.0.93-2. Preserve the new account MCP provenance and exercise limitTo through the bundled runtime on create, resume, removal, and Allow All.

🤖 Authored with GitHub Copilot on behalf of @rwoll.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Translate eligible legacy allowlists to limitTo and intersect client boundaries semantically. Preserve empty/default and personal-setting behavior, validate the bridge subset, and diagnose unsupported lists.

Project the runtime sandbox floor and fail closed for custom terminal commands and stdin. Cover protocol ownership, removal, real SDK create/resume, Allow All, disjoint boundaries, and runtime sandbox-conflict handling. Browser and broader native-source parity remain separate milestones.

🤖 Authored with GitHub Copilot on behalf of @rwoll.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Probe settings-derived sandbox updates against native, bridged, and disjoint domain boundaries on create and cold resume. Preserve the existing replacement-conflict regression and verify explicit session disable cannot bypass the mandatory floor.

🤖 Authored with GitHub Copilot on behalf of @rwoll.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Forward settings-derived sandbox sources on create, resume, and live updates so the runtime can preserve managed host boundaries while applying host preferences. Keep session choices explicit and disabled updates strict to avoid publishing a disabled state when runtime policy kept sandboxing enabled.

🤖 Authored with GitHub Copilot on behalf of @rwoll.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 6, 2026 22:19
export type McpServerSource =
| 'user' // Defined in user-level configuration.
| 'account' // Supplied by the signed-in account.
| 'workspace' // Defined in workspace-level configuration.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This diff should go away when I rebase-ish off of main (post SDK roll). This PR includes an SDK roll simply for me to make progress while the normal SDK roll automation plays out.

@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Screenshot Changes

Base: 1d25d5df Current: 4b0cab06

Changed (2)

sessions/chatCompositeBar/MixedStatuses/Light
Before After
before after
sessions/chatCompositeBar/OverflowingTabs/Light
Before After
before after

Use settings-derived sandbox provenance when policy already requires sandboxing, including policy-promoted session selections. Propagate rejected updates instead of continuing with unapplied host restrictions.

Cover explicit On and promoted Off, create/resume, live default and peer updates, and real-runtime filesystem denials.

*🤖 Authored with GitHub Copilot on behalf of @rwoll.*

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@rwoll

Copy link
Copy Markdown
Member Author

Follow-up e3b617a fixes the review finding: mandatory sandbox floors now compose user filesystem restrictions, and rejected updates stop execution instead of leaving those restrictions unapplied.

The new real-runtime regression failed before the fix (a denied file was readable) and passes afterward, including cold resume. Local validation: 1,015 unit tests and 8 runtime integration tests passed; client typecheck and targeted lint passed. Opus 5.5 and Astra independently re-reviewed the follow-up with no actionable findings; this is AI review, not signed human approval.

Windows/Linux/macOS acceptance is running: https://dev.azure.com/monacotools/Monaco/_build/results?buildId=481402 . Keeping this PR in draft pending that validation and the independent SDK roll on main.

🤖 Authored with GitHub Copilot on behalf of Ross Wollman (@rwoll).

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Security-sensitive enforcement, stale Policy Diagnostics text, and pending cross-platform acceptance require maintainer validation.

Review effort: Balanced
Findings: 1 Low severity

Open (1)
What changed in this PR

Integrates policy-managed network boundaries with Copilot runtime sandbox enforcement.

Changes:

  • Bridges policy-owned domain allowlists to permissions.limitTo.
  • Enforces mandatory sandbox floors and blocks incompatible custom terminals.
  • Updates SDK/runtime dependencies, MCP account provenance, tests, and policy guidance.
File Description
src/​vs/​workbench/​contrib/​chat/​test/​browser/​aiCustomization/​mcpListWidget.test.ts Tests account-sourced MCP presentation.
src/​vs/​workbench/​contrib/​chat/​test/​browser/​aiCustomization/​customizationsTelemetryService.test.ts Tests account-source telemetry.
src/​vs/​workbench/​contrib/​chat/​browser/​aiCustomization/​mcpListWidget.ts Presents account MCP provenance.
src/​vs/​workbench/​contrib/​chat/​browser/​aiCustomization/​customizationsTelemetryService.ts Groups account MCP telemetry.
src/​vs/​platform/​agentHost/​test/​node/​sessionSandbox.test.ts Tests mandatory sandbox composition.
src/​vs/​platform/​agentHost/​test/​node/​providerIntegration/​copilotManagedPermissions.integrationTest.ts Exercises runtime boundary enforcement.
src/​vs/​platform/​agentHost/​test/​node/​protocolServerHandler.test.ts Tests boundary validation and transport.
src/​vs/​platform/​agentHost/​test/​node/​copilotShellTools.test.ts Tests custom-terminal blocking.
src/​vs/​platform/​agentHost/​test/​node/​copilotSessionLauncher.test.ts Tests launcher sandbox enforcement.
src/​vs/​platform/​agentHost/​test/​node/​copilotAgentSession.test.ts Tests sandbox provenance and failures.
src/​vs/​platform/​agentHost/​test/​node/​agentHostManagedSettingsService.test.ts Tests client-boundary intersection.
src/​vs/​platform/​agentHost/​test/​electron-browser/​agentHostProtocolClient.test.ts Tests local-host policy forwarding.
src/​vs/​platform/​agentHost/​test/​common/​agentMetaReaders.test.ts Tests account MCP metadata.
src/​vs/​platform/​agentHost/​test/​common/​agentHostManagedSettings.test.ts Tests policy allowlist translation.
src/​vs/​platform/​agentHost/​test/​common/​agentHostManagedRules.test.ts Tests boundary construction and intersection.
src/​vs/​platform/​agentHost/​node/​sessionSandbox.ts Exposes raw session sandbox selection.
src/​vs/​platform/​agentHost/​node/​copilot/​copilotShellTools.ts Fails custom terminals closed.
src/​vs/​platform/​agentHost/​node/​copilot/​copilotSessionLauncher.ts Applies resolved sandbox boundaries.
src/​vs/​platform/​agentHost/​node/​copilot/​copilotSandboxPolicy.ts Projects runtime boundary policy.
src/​vs/​platform/​agentHost/​node/​copilot/​copilotAgentSession.ts Propagates sandbox update failures.
src/​vs/​platform/​agentHost/​node/​agentHostManagedSettingsService.ts Intersects client boundaries.
src/​vs/​platform/​agentHost/​common/​meta/​vscode/​mcpCustomizationMeta.ts Adds account MCP source.
src/​vs/​platform/​agentHost/​common/​agentHostPolicySupport.ts Updates policy coverage notes.
src/​vs/​platform/​agentHost/​common/​agentHostManagedSettings.ts Bridges managed domain allowlists.
src/​vs/​platform/​agentHost/​common/​agentHostManagedRules.ts Implements canonical boundaries.
src/​vs/​platform/​agentHost/​browser/​agentHostProtocolClient.ts Supplies logging to policy resolution.
remote/​package.json Updates remote SDK/runtime versions.
remote/​package-lock.json Locks remote dependency updates.
package.json Updates SDK/runtime versions.
package-lock.json Locks dependency updates.
.github/​skills/​policy-and-managed-settings/​sdk-runtime-policy.md Documents boundary invariants.
.github/​skills/​policy-and-managed-settings/​legacy-permission-policy.md Documents legacy translation.
Files not reviewed (1)
  • remote/package-lock.json: Generated file

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +62 to +63
// Policy-owned allowlists reach native shell containment through limitTo; the custom
// terminal fails closed. URL-aware denies and browser coverage are not full host parity.
@rwoll

Copy link
Copy Markdown
Member Author

Closing for now while we align permissions.limitTo semantics with upstream.

The intended contract is that limitTo constrains permissions without changing sandbox behavior; sandboxing has its own policy. This draft couples the two, so we will revisit the integration once the upstream semantics are settled.

🤖 Authored with GitHub Copilot on behalf of Ross Wollman (@rwoll).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants