return 'approved';
}
const rules = this._compileRules(options?.autoApproveRules);
Frontier kind: Code frontier
unlabeled · c_3b2969a78438
25 tests · 8617 LOC · 40 files · introduces 0 tests · 51 LOC · 1 file
The orange circle is the focus. Violet and green circles are every ancestor and descendant, broader and narrower, at any distance; blue squares and pink diamonds are the introduced files and exact introduced tests of every visible concept, not only the focus's. Arrows point from broader to narrower concepts and bridge only concepts omitted from this view. Undirected links show source or test introduction. Concept and file size follows LOC; exact test nodes use test-count units.
Introduced files, introduced tests, and structurally relevant concept specialization
In the embedded map, ordinary wheel input scrolls the page; use the visible controls to zoom and drag to pan. Open the full-screen map for canvas navigation: wheel pans, Ctrl/Command plus wheel zooms, and arrow keys pan when this region is focused. On touch screens, open the full-screen map to pan or pinch. If JavaScript or WebGL is unavailable, use the native relationship evidence on this page.
Graph controls are ready.
Interactive rendering requires JavaScript and WebGL. Use the native relationship evidence on this page while the interactive map is unavailable.
Every exact file and test below is linked only from the concept that introduces it.
mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/commandAutoApprover.test|title=CommandAutoApprover shouldAutoApprove handles find with blocked args|occurrence=1mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/commandAutoApprover.test|title=CommandAutoApprover shouldAutoApprove handles sed with blocked args|occurrence=1mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/commandAutoApprover.test|title=CommandAutoApprover shouldAutoApprove PowerShell case-insensitive rules work|occurrence=1mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/commandAutoApprover.test|title=CommandAutoApprover shouldAutoApprove approves allowed PowerShell commands|occurrence=1mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/commandAutoApprover.test|title=CommandAutoApprover shouldAutoApprove approves allowed git sub-commands|occurrence=1mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/commandAutoApprover.test|title=CommandAutoApprover shouldAutoApprove approves allowed npm commands|occurrence=1mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/commandAutoApprover.test|title=CommandAutoApprover shouldAutoApprove approves allowed readonly commands|occurrence=1mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/commandAutoApprover.test|title=CommandAutoApprover shouldAutoApprove denies denied PowerShell commands|occurrence=1mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/commandAutoApprover.test|title=CommandAutoApprover shouldAutoApprove denies denied commands|occurrence=1mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/commandAutoApprover.test|title=CommandAutoApprover shouldAutoApprove denies denied git operations|occurrence=1mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/base/test/common/lifecycle.test|title=Lifecycle Action bar has broken accessibility #100273|occurrence=1mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/base/test/common/lifecycle.test|title=Lifecycle dispose disposable array|occurrence=1Every collected test enters the hierarchy at exactly one concept.
No tests are introduced at this concept. Its intent tests are introduced by other concepts.
Every collected source range enters the hierarchy at exactly one concept.
1 file ranked by introduced lines: 51 introduced LOC across 17 ranges. Expand a file to inspect source; the > gutter marks introduced lines.
return 'approved';
}
const rules = this._compileRules(options?.autoApproveRules);
return 'noMatch';
}
if (this._matchesRule(trimmed, rules.denyCommandLineRules)) {
return 'denied';
}
let result = this._matchSubCommands(parsed.subCommands, rules);
if (result !== 'denied' && this._matchesRule(trimmed, rules.allowCommandLineRules)) {
result = 'approved';
private _matchSubCommands(subCommands: string[], rules: IAutoApproveRules): CommandApprovalResult {
for (const subCommand of subCommands) {
// Deny transient env var assignments
if (transientEnvVarRegex.test(subCommand)) {
return 'denied';
}
allApproved = false;
}
return allApproved ? 'approved' : 'noMatch';
}
private _matchSingleCommand(command: string, rules: IAutoApproveRules): CommandApprovalResult {
private _matchesRule(command: string, rules: readonly IAutoApproveRule[]): boolean {
if (rule.regex.test(command)) {
return true;
}
}
}
// ---- Tree-sitter --------------------------------------------------------
private _extractSubCommands(commandLine: string): { subCommands: string[]; unsafeWriteDests: (string | undefined)[] } | undefined {
return undefined;
}
try {
this._parser.setLanguage(this._bashLanguage);
const tree = this._parser.parse(commandLine);
if (!tree) {
return undefined;
}
try {
const query = new this._queryClass(this._bashLanguage, '(command) @command (file_redirect) @file_redirect (heredoc_redirect) @heredoc_redirect (herestring_redirect) @herestring_redirect');
const captures: QueryCapture[] = query.captures(tree.rootNode);
const subCommands: string[] = [];
const unsafeWriteDests: (string | undefined)[] = [];
for (const capture of captures) {
if (capture.name === 'command') {
subCommands.push(capture.node.text);
} else if (capture.name === 'file_redirect') {
// Writes to known-safe sinks (e.g. `> /dev/null`) and
// file-descriptor duplications (e.g. `2>&1`) are allowed.
// files, so they are not treated as write redirects here.
}
query.delete();
return subCommands.length > 0 || unsafeWriteDests.length > 0 ? { subCommands, unsafeWriteDests } : undefined;
} finally {
tree.delete();
}
} catch (err) {
this._logService.warn('[CommandAutoApprover] Tree-sitter parsing failed', err);
return undefined;
}
private async _initTreeSitter(): Promise<void> {
private _compileRules(ruleConfig: AgentHostTerminalAutoApproveRules | undefined): IAutoApproveRules {
if (!this._fallbackRules) {
this._fallbackRules = this._compileRuleEntries(DEFAULT_TERMINAL_AUTO_APPROVE_RULES);
}
return this._cachedRules;
}
this._cachedRules = this._compileRuleEntries(ruleConfig);
return this._cachedRules;
private _compileRuleEntries(ruleConfig: Readonly<Record<string, AgentHostTerminalAutoApproveRuleValue>>): IAutoApproveRules {
const denyRules: IAutoApproveRule[] = [];
const allowCommandLineRules: IAutoApproveRule[] = [];
const denyCommandLineRules: IAutoApproveRule[] = [];
for (const [key, value] of Object.entries(ruleConfig)) {
const regex = convertAutoApproveEntryToRegex(key);
if (value === true) {
}
}
return { allowRules, denyRules, allowCommandLineRules, denyCommandLineRules };
}
}