Repository navigation
agentHost: integrate managed network boundaries and sandbox preferences - #340162
Ross Wollman (rwoll) wants to merge 5 commits into
Conversation
Update desktop and remote to SDK 1.0.17-preview.8 / runtime 1.0.93-2. Preserve the new account MCP provenance and exercise limitTo through the bundled runtime on create, resume, removal, and Allow All. 🤖 Authored with GitHub Copilot on behalf of @rwoll. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Translate eligible legacy allowlists to limitTo and intersect client boundaries semantically. Preserve empty/default and personal-setting behavior, validate the bridge subset, and diagnose unsupported lists. Project the runtime sandbox floor and fail closed for custom terminal commands and stdin. Cover protocol ownership, removal, real SDK create/resume, Allow All, disjoint boundaries, and runtime sandbox-conflict handling. Browser and broader native-source parity remain separate milestones. 🤖 Authored with GitHub Copilot on behalf of @rwoll. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Probe settings-derived sandbox updates against native, bridged, and disjoint domain boundaries on create and cold resume. Preserve the existing replacement-conflict regression and verify explicit session disable cannot bypass the mandatory floor. 🤖 Authored with GitHub Copilot on behalf of @rwoll. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Forward settings-derived sandbox sources on create, resume, and live updates so the runtime can preserve managed host boundaries while applying host preferences. Keep session choices explicit and disabled updates strict to avoid publishing a disabled state when runtime policy kept sandboxing enabled. 🤖 Authored with GitHub Copilot on behalf of @rwoll. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
| export type McpServerSource = | ||
| | 'user' // Defined in user-level configuration. | ||
| | 'account' // Supplied by the signed-in account. | ||
| | 'workspace' // Defined in workspace-level configuration. |
There was a problem hiding this comment.
This diff should go away when I rebase-ish off of main (post SDK roll). This PR includes an SDK roll simply for me to make progress while the normal SDK roll automation plays out.
Use settings-derived sandbox provenance when policy already requires sandboxing, including policy-promoted session selections. Propagate rejected updates instead of continuing with unapplied host restrictions. Cover explicit On and promoted Off, create/resume, live default and peer updates, and real-runtime filesystem denials. *🤖 Authored with GitHub Copilot on behalf of @rwoll.* Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
|
Follow-up e3b617a fixes the review finding: mandatory sandbox floors now compose user filesystem restrictions, and rejected updates stop execution instead of leaving those restrictions unapplied. The new real-runtime regression failed before the fix (a denied file was readable) and passes afterward, including cold resume. Local validation: 1,015 unit tests and 8 runtime integration tests passed; client typecheck and targeted lint passed. Opus 5.5 and Astra independently re-reviewed the follow-up with no actionable findings; this is AI review, not signed human approval. Windows/Linux/macOS acceptance is running: https://dev.azure.com/monacotools/Monaco/_build/results?buildId=481402 . Keeping this PR in draft pending that validation and the independent SDK roll on main. 🤖 Authored with GitHub Copilot on behalf of Ross Wollman (@rwoll). |
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Security-sensitive enforcement, stale Policy Diagnostics text, and pending cross-platform acceptance require maintainer validation.
Review effort: Balanced
Findings: 1
What changed in this PR
Integrates policy-managed network boundaries with Copilot runtime sandbox enforcement.
Changes:
- Bridges policy-owned domain allowlists to
permissions.limitTo. - Enforces mandatory sandbox floors and blocks incompatible custom terminals.
- Updates SDK/runtime dependencies, MCP account provenance, tests, and policy guidance.
| File | Description |
|---|---|
src/vs/workbench/contrib/chat/test/browser/aiCustomization/mcpListWidget.test.ts |
Tests account-sourced MCP presentation. |
src/vs/workbench/contrib/chat/test/browser/aiCustomization/customizationsTelemetryService.test.ts |
Tests account-source telemetry. |
src/vs/workbench/contrib/chat/browser/aiCustomization/mcpListWidget.ts |
Presents account MCP provenance. |
src/vs/workbench/contrib/chat/browser/aiCustomization/customizationsTelemetryService.ts |
Groups account MCP telemetry. |
src/vs/platform/agentHost/test/node/sessionSandbox.test.ts |
Tests mandatory sandbox composition. |
src/vs/platform/agentHost/test/node/providerIntegration/copilotManagedPermissions.integrationTest.ts |
Exercises runtime boundary enforcement. |
src/vs/platform/agentHost/test/node/protocolServerHandler.test.ts |
Tests boundary validation and transport. |
src/vs/platform/agentHost/test/node/copilotShellTools.test.ts |
Tests custom-terminal blocking. |
src/vs/platform/agentHost/test/node/copilotSessionLauncher.test.ts |
Tests launcher sandbox enforcement. |
src/vs/platform/agentHost/test/node/copilotAgentSession.test.ts |
Tests sandbox provenance and failures. |
src/vs/platform/agentHost/test/node/agentHostManagedSettingsService.test.ts |
Tests client-boundary intersection. |
src/vs/platform/agentHost/test/electron-browser/agentHostProtocolClient.test.ts |
Tests local-host policy forwarding. |
src/vs/platform/agentHost/test/common/agentMetaReaders.test.ts |
Tests account MCP metadata. |
src/vs/platform/agentHost/test/common/agentHostManagedSettings.test.ts |
Tests policy allowlist translation. |
src/vs/platform/agentHost/test/common/agentHostManagedRules.test.ts |
Tests boundary construction and intersection. |
src/vs/platform/agentHost/node/sessionSandbox.ts |
Exposes raw session sandbox selection. |
src/vs/platform/agentHost/node/copilot/copilotShellTools.ts |
Fails custom terminals closed. |
src/vs/platform/agentHost/node/copilot/copilotSessionLauncher.ts |
Applies resolved sandbox boundaries. |
src/vs/platform/agentHost/node/copilot/copilotSandboxPolicy.ts |
Projects runtime boundary policy. |
src/vs/platform/agentHost/node/copilot/copilotAgentSession.ts |
Propagates sandbox update failures. |
src/vs/platform/agentHost/node/agentHostManagedSettingsService.ts |
Intersects client boundaries. |
src/vs/platform/agentHost/common/meta/vscode/mcpCustomizationMeta.ts |
Adds account MCP source. |
src/vs/platform/agentHost/common/agentHostPolicySupport.ts |
Updates policy coverage notes. |
src/vs/platform/agentHost/common/agentHostManagedSettings.ts |
Bridges managed domain allowlists. |
src/vs/platform/agentHost/common/agentHostManagedRules.ts |
Implements canonical boundaries. |
src/vs/platform/agentHost/browser/agentHostProtocolClient.ts |
Supplies logging to policy resolution. |
remote/package.json |
Updates remote SDK/runtime versions. |
remote/package-lock.json |
Locks remote dependency updates. |
package.json |
Updates SDK/runtime versions. |
package-lock.json |
Locks dependency updates. |
.github/skills/policy-and-managed-settings/sdk-runtime-policy.md |
Documents boundary invariants. |
.github/skills/policy-and-managed-settings/legacy-permission-policy.md |
Documents legacy translation. |
Files not reviewed (1)
- remote/package-lock.json: Generated file
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| // Policy-owned allowlists reach native shell containment through limitTo; the custom | ||
| // terminal fails closed. URL-aware denies and browser coverage are not full host parity. |
|
Closing for now while we align permissions.limitTo semantics with upstream. The intended contract is that limitTo constrains permissions without changing sandbox behavior; sandboxing has its own policy. This draft couples the two, so we will revisit the integration once the upstream semantics are settled. 🤖 Authored with GitHub Copilot on behalf of Ross Wollman (@rwoll). |

Draft. Includes the SDK/runtime prerequisite for now; rebase out that bump once it lands independently on
main. Cross-platform acceptance remains pending.Adopt the SDK's new
permissions.limitTodirective (github/copilot-agent-runtime#23922) and bridge VS Code's policy-managedchat.agent.sandbox.network.allowedDomainsto it whenchat.agent.networkFilteris policy-enabled.Policy examples
Native managed-settings JSON:
An admin wants to hard-block native agent access to unapproved destinations, while permitting internal documentation and a package mirror.
{ "permissions": { "limitTo": [ "Domain(docs.corp.example)", "Domain(packages.corp.example)" ] } }The agent can request internal docs and mirror downloads, subject to normal approvals. Fetching a public registry or an arbitrary upload endpoint is denied, even in Allow All. These are illustrative exact hosts; admins must include any additional required download/redirect hosts.
The admin also wants users to approve each HTTPS fetch of internal documentation, without letting approval bypass the boundary.
Add
"ask": ["Domain(https://docs.corp.example)"]underpermissionsabove. Documentation fetches require human approval even in Allow All; the package mirror keeps normal approval behavior. Unapproved hosts remain blocked rather than offered an override.An admin wants local-only maintenance: inspect code and run local commands, but hard-block network access by native runtime tools.
{ "permissions": { "limitTo": [] } }Native fetches are denied and the runtime applies a mandatory sandbox network floor. Local file and shell work remain subject to other permissions; commands that need network access cannot complete. This is not an offline model mode. Omitting
limitToinstead contributes no boundary from this field; other policies still apply.Upcoming
🤖 Authored with GitHub Copilot on behalf of Ross Wollman (@rwoll).