codexGuardianReview.ts ×9

Frontier kind: Code frontier

unlabeled · c_3c2dfa89dd35

18 tests · 3486 LOC · 20 files · introduces 0 tests · 81 LOC · 1 file

Introduces — evidence that enters the hierarchy at this concept

Code
9 ranges81 lines · 1 files
Tests
0 tests

Contains — complete concept membership

All code (extent)
491 ranges3486 lines · 20 files · Browse complete extent
All tests (intent)
18 testsBrowse complete intent

Neighbourhood graph

The orange circle is the focus. Violet and green circles are every ancestor and descendant, broader and narrower, at any distance; blue squares and pink diamonds are the introduced files and exact introduced tests of every visible concept, not only the focus's. Arrows point from broader to narrower concepts and bridge only concepts omitted from this view. Undirected links show source or test introduction. Concept and file size follows LOC; exact test nodes use test-count units.

Introduced files, introduced tests, and structurally relevant concept specialization

In the embedded map, ordinary wheel input scrolls the page; use the visible controls to zoom and drag to pan. Open the full-screen map for canvas navigation: wheel pans, Ctrl/Command plus wheel zooms, and arrow keys pan when this region is focused. On touch screens, open the full-screen map to pan or pinch. If JavaScript or WebGL is unavailable, use the native relationship evidence on this page.

Introduced files, introduced tests, and structurally relevant concept specializationcodexAgent.ts ×13 · 83 introduced LOCcodexAgent.ts ×13codexSessionConfigKeys.test|title=codexSessionConfigKeys resolveSessionConfig preserves legacy read-only permissions on restore|occurrence=1 · 0 introduced LOCcodexSessionConfigKeys.t…codexSessionConfigKeys.test|title=codexSessionConfigKeys resolveSessionConfig exposes a single permissions-preset chip|occurrence=1 · 0 introduced LOCcodexSessionConfigKeys.t…codexAgent.ts ×1 · 27 introduced LOCcodexAgent.ts ×1codexAgent.ts ×24 · 89 introduced LOCcodexAgent.ts ×24codexSessionConfigKeys.ts ×1 · 7 introduced LOCcodexSessionConfigKeys.t…codexSessionConfigKeys.ts ×1 · 2 introduced LOCcodexSessionConfigKeys.t…codexSessionConfigKeys.ts ×7 · 49 introduced LOCcodexSessionConfigKeys.t…codexSessionConfigKeys.ts ×1 · 11 introduced LOCcodexSessionConfigKeys.t…codexSessionConfigKeys.ts ×1 · 2 introduced LOCcodexSessionConfigKeys.t…codexSessionConfigKeys.ts ×2 · 4 introduced LOCcodexSessionConfigKeys.t…codexSessionConfigKeys.ts ×3 · 18 introduced LOCcodexSessionConfigKeys.t…codexSessionConfigKeys.ts ×3 · 19 introduced LOCcodexSessionConfigKeys.t…codexSessionConfigKeys.ts ×2 · 3 introduced LOCcodexSessionConfigKeys.t…codexSessionConfigKeys.ts ×2 · 2 introduced LOCcodexSessionConfigKeys.t…codexSessionConfigKeys.ts ×6 · 23 introduced LOCcodexSessionConfigKeys.t…codexAgent.ts ×1 · 2 introduced LOCcodexAgent.ts ×1codexAgent.ts ×1 · 2 introduced LOCcodexAgent.ts ×1codexAgent.ts ×3 · 7 introduced LOCcodexAgent.ts ×3codexAgent.ts ×1 · 2 introduced LOCcodexAgent.ts ×1codexAgent.ts ×1 · 2 introduced LOCcodexAgent.ts ×1codexAgent.ts ×1 · 2 introduced LOCcodexAgent.ts ×1codexAgent.ts ×1 · 10 introduced LOCcodexAgent.ts ×1codexAgent.ts ×8 · 19 introduced LOCcodexAgent.ts ×8codexAgent.ts ×158 · 1640 introduced LOCcodexAgent.ts ×158codexGuardianReview.ts ×5 · 15 introduced LOCcodexGuardianReview.ts ×…codexGuardianReview.ts ×2 · 16 introduced LOCcodexGuardianReview.ts ×…codexGuardianReview.ts ×13 · 36 introduced LOCcodexGuardianReview.ts ×…codexGuardianReview.ts ×2 · 8 introduced LOCcodexGuardianReview.ts ×…codexGuardianReview.ts ×1 · 1 introduced LOCcodexGuardianReview.ts ×…codexGuardianReview.ts ×7 · 9 introduced LOCcodexGuardianReview.ts ×…codexGuardianReview.ts ×2 · 25 introduced LOCcodexGuardianReview.ts ×…codexShellCommand.ts ×2 · 27 introduced LOCcodexShellCommand.ts ×2utils.ts ×3 · 9 introduced LOCutils.ts ×3lifecycle.ts ×2 · 4 introduced LOClifecycle.ts ×2lifecycle.ts ×4 · 8 introduced LOClifecycle.ts ×4lifecycle.ts ×6 · 16 introduced LOClifecycle.ts ×6lifecycle.ts ×1 · 2 introduced LOClifecycle.ts ×1lifecycle.ts ×1 · 2 introduced LOClifecycle.ts ×1lifecycle.ts ×1 · 3 introduced LOClifecycle.ts ×1map.ts ×97 · 3334 introduced LOCmap.ts ×97src/vs/base/common/arrays.ts · 949 LOCcommon/arrays.tssrc/vs/base/common/arraysFind.ts · 226 LOCcommon/arraysFind.tssrc/vs/base/common/assert.ts · 91 LOCcommon/assert.tssrc/vs/base/common/charCode.ts · 450 LOCcommon/charCode.tssrc/vs/base/common/collections.ts · 176 LOCcommon/collections.tssrc/vs/base/common/errors.ts · 357 LOCcommon/errors.tssrc/vs/base/common/functional.ts · 32 LOCcommon/functional.tssrc/vs/base/common/iterator.ts · 194 LOCcommon/iterator.tssrc/vs/base/common/lifecycle.ts · 974 LOCcommon/lifecycle.tssrc/vs/base/common/map.ts · 1016 LOCcommon/map.tssrc/vs/base/common/marshallingIds.ts · 33 LOCcommon/marshallingIds.tssrc/vs/base/common/path.ts · 1589 LOCcommon/path.tssrc/vs/base/common/platform.ts · 281 LOCcommon/platform.tssrc/vs/base/common/process.ts · 76 LOCcommon/process.tssrc/vs/base/common/types.ts · 410 LOCcommon/types.tssrc/vs/base/common/uri.ts · 754 LOCcommon/uri.tssrc/vs/base/test/common/utils.ts · 107 LOCcommon/utils.tssrc/vs/nls.ts · 244 LOCvs/nls.tssrc/vs/platform/agentHost/common/codexSessionConfigKeys.ts · 114 LOCcommon/codexSessionConfi…src/vs/platform/agentHost/node/codex/codexAgent.ts · 4389 LOCcodex/codexAgent.tssrc/vs/platform/agentHost/node/codex/codexGuardianReview.ts · 201 LOCcodex/codexGuardianRevie…src/vs/platform/agentHost/node/codex/codexSessionConfigKeys.ts · 197 LOCcodex/codexSessionConfig…src/vs/platform/agentHost/node/codex/codexSessionMetadataStore.ts · 112 LOCcodex/codexSessionMetada…src/vs/platform/agentHost/node/codex/codexShellCommand.ts · 42 LOCcodex/codexShellCommand.…codexGuardianReview.test|title=codexGuardianReview formatGuardianDenialNotification renders the action summary and rationale as a distinct blockquote|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexGuardianReview.test|title=codexGuardianReview formatGuardianDenialNotification renders the action summary and rationale as a distinct blockquote|occurrence=1codexGuardianReview.test…codexGuardianReview.test|title=codexGuardianReview summarizeGuardianReviewAction labels denied network access clearly|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexGuardianReview.test|title=codexGuardianReview summarizeGuardianReviewAction labels denied network access clearly|occurrence=1codexGuardianReview.test…codexGuardianReview.test|title=codexGuardianReview summarizeGuardianReviewAction unwraps the OS shell wrapper so the card matches the terminal pill|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexGuardianReview.test|title=codexGuardianReview summarizeGuardianReviewAction unwraps the OS shell wrapper so the card matches the terminal pill|occurrence=1codexGuardianReview.test…codexGuardianReview.test|title=codexGuardianReview toGuardianAssessmentEventJson converts network review payloads to snake_case|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexGuardianReview.test|title=codexGuardianReview toGuardianAssessmentEventJson converts network review payloads to snake_case|occurrence=1codexGuardianReview.test…codexGuardianReview.test|title=codexGuardianReview toGuardianAssessmentEventJson snake_cases the requestPermissions profile|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexGuardianReview.test|title=codexGuardianReview toGuardianAssessmentEventJson snake_cases the requestPermissions profile|occurrence=1codexGuardianReview.test…codexModelRefresh.test|title=CodexAgent model refresh keeps the last known-good models when a periodic refresh fails|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexModelRefresh.test|title=CodexAgent model refresh keeps the last known-good models when a periodic refresh fails|occurrence=1codexModelRefresh.test|t…codexPackagePaths.test|title=codex package paths codexBinaryTriple every suffix produced by codexPackageSuffix maps to a rust target triple|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexPackagePaths.test|title=codex package paths codexBinaryTriple every suffix produced by codexPackageSuffix maps to a rust target triple|occurrence=1codexPackagePaths.test|t…codexPackagePaths.test|title=codex package paths codexBinaryTriple returns undefined for unknown suffixes|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexPackagePaths.test|title=codex package paths codexBinaryTriple returns undefined for unknown suffixes|occurrence=1codexPackagePaths.test|t…codexPackagePaths.test|title=codex package paths codexPackageSuffix every supported (platform, arch) returns the npm optionalDependencies suffix|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexPackagePaths.test|title=codex package paths codexPackageSuffix every supported (platform, arch) returns the npm optionalDependencies suffix|occurrence=1codexPackagePaths.test|t…codexPackagePaths.test|title=codex package paths codexPackageSuffix never returns a -musl suffix on Linux (Codex is statically musl-linked)|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexPackagePaths.test|title=codex package paths codexPackageSuffix never returns a -musl suffix on Linux (Codex is statically musl-linked)|occurrence=1codexPackagePaths.test|t…codexPackagePaths.test|title=codex package paths codexPackageSuffix returns undefined for unsupported platforms and architectures|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexPackagePaths.test|title=codex package paths codexPackageSuffix returns undefined for unsupported platforms and architectures|occurrence=1codexPackagePaths.test|t…codex resolves|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexPackagePaths.test|title=codex package paths resolveCodexDevSdkRoot returns the directory containing node_modules when @openai/codex resolves|occurrence=1codex resolves|occurrenc…codexPackagePaths.test|title=codex package paths resolveCodexDevSdkRoot returns undefined when resolution throws (e.g. built product without the devDependency)|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexPackagePaths.test|title=codex package paths resolveCodexDevSdkRoot returns undefined when resolution throws (e.g. built product without the devDependency)|occurrence=1codexPackagePaths.test|t…codexSessionConfigKeys.test|title=codexSessionConfigKeys expands permissions presets and falls back to legacy axes|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexSessionConfigKeys.test|title=codexSessionConfigKeys expands permissions presets and falls back to legacy axes|occurrence=1codexSessionConfigKeys.t…codexSessionConfigKeys.test|title=codexSessionConfigKeys inverts presets and migrates legacy axes without escalating|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexSessionConfigKeys.test|title=codexSessionConfigKeys inverts presets and migrates legacy axes without escalating|occurrence=1codexSessionConfigKeys.t…codexSessionConfigKeys.test|title=codexSessionConfigKeys narrows valid values and rejects invalid values|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexSessionConfigKeys.test|title=codexSessionConfigKeys narrows valid values and rejects invalid values|occurrence=1codexSessionConfigKeys.t…codexSessionConfigKeys.test|title=codexSessionConfigKeys resolveSessionConfig exposes a single permissions-preset chip|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexSessionConfigKeys.test|title=codexSessionConfigKeys resolveSessionConfig exposes a single permissions-preset chip|occurrence=1codexSessionConfigKeys.t…codexSessionConfigKeys.test|title=codexSessionConfigKeys resolveSessionConfig preserves legacy read-only permissions on restore|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexSessionConfigKeys.test|title=codexSessionConfigKeys resolveSessionConfig preserves legacy read-only permissions on restore|occurrence=1codexSessionConfigKeys.t…Focused concept · codexGuardianReview.ts ×9 · 81 introduced LOCcodexGuardianReview.ts ×…

Graph controls are ready.

Interactive rendering requires JavaScript and WebGL. Use the native relationship evidence on this page while the interactive map is unavailable.

Native relationship evidence

Every exact file and test below is linked only from the concept that introduces it.

Introduced tests

Every collected test enters the hierarchy at exactly one concept.

No tests are introduced at this concept. Its intent tests are introduced by other concepts.

Introduced code

Every collected source range enters the hierarchy at exactly one concept.

1 file ranked by introduced lines: 81 introduced LOC across 9 ranges. Expand a file to inspect source; the > gutter marks introduced lines.

src/vs/platform/agentHost/node/codex/codexGuardianReview.ts 81 introduced LOC · 9 ranges

Open complete file

1 > /*--------------------------------------------------------------------------------------------- codexGuardianReview.ts
2 > * Copyright (c) Microsoft Corporation. All rights reserved.
3 > * Licensed under the MIT License. See License.txt in the project root for license information.
4 > *--------------------------------------------------------------------------------------------*/
5 >
6 > import type { GuardianApprovalReviewAction } from './protocol/generated/v2/GuardianApprovalReviewAction.js';
7 > import type { ItemGuardianApprovalReviewCompletedNotification } from './protocol/generated/v2/ItemGuardianApprovalReviewCompletedNotification.js';
8 > import type { RequestPermissionProfile } from './protocol/generated/v2/RequestPermissionProfile.js';
9 > import type { JsonValue } from './protocol/generated/serde_json/JsonValue.js';
10 > import { unwrapShellInvocation } from './codexShellCommand.js';
11 >
12 > /**
13 > * Auto-review (guardian) notifications are emitted by the app-server with
14 > * `ts-rs`-generated camelCase field names. The `thread/approveGuardianDeniedAction`
15 > * request, however, echoes back a `codex_protocol::protocol::GuardianAssessmentEvent`
16 > * that is (de)serialized with plain `serde` — which uses **snake_case** for enum
17 > * variants, enum values, and the tagged-union `type` discriminant. The two shapes
18 > * therefore diverge (`inProgress` vs `in_progress`, `networkAccess` vs
19 > * `network_access`, `unifiedExec` vs `unified_exec`, `toolName` vs `tool_name`, …),
20 > * so we cannot round-trip the notification payload verbatim.
21 > *
22 > * These helpers translate the camelCase completed-review notification into the
23 > * snake_case `GuardianAssessmentEvent` JSON that the app-server can deserialize,
24 > * and summarise a review action for display on the approval card.
25 > */
26 >
27 > /** camelCase {@link GuardianApprovalReviewStatus} value -> snake_case `GuardianAssessmentStatus`. */
28 function guardianStatusToEvent(status: string): string {
29 switch (status) {
34 }
35 }
37 > /** camelCase {@link GuardianCommandSource} value -> snake_case. */
38 function commandSourceToEvent(source: string): string {
39 return source === 'unifiedExec' ? 'unified_exec' : source;
40 }
42 > /** camelCase {@link NetworkApprovalProtocol} value -> snake_case. */
43 function networkProtocolToEvent(protocol: string): string {
44 switch (protocol) {
49 }
50 }
52 > /**
53 > * camelCase {@link RequestPermissionProfile} -> snake_case. The `network`
54 > * profile (`{ enabled }`) is identical in both casings, but the file-system
55 > * profile renames `fileSystem` -> `file_system` and `globScanMaxDepth` ->
56 > * `glob_scan_max_depth`. Its `read`/`write`/`entries` members (and the entry
57 > * `path`/`access` fields) are already snake_case in the notification, so they
58 > * round-trip verbatim.
59 > */
60 function requestPermissionProfileToEvent(profile: RequestPermissionProfile): JsonValue {
61 const fs = profile.fileSystem;
73 return { network: profile.network as JsonValue, file_system: fileSystem };
74 }
76 > /**
77 > * Translate the camelCase notification action into the snake_case
78 > * `GuardianAssessmentAction` (`#[serde(tag = "type", rename_all = "snake_case")]`)
79 > * that `thread/approveGuardianDeniedAction` deserializes.
80 > */
81 > export function guardianReviewActionToEventAction(action: GuardianApprovalReviewAction): JsonValue {
82 switch (action.type) {
83 case 'command':
95 }
96 }
98 > /**
99 > * Build the snake_case `GuardianAssessmentEvent` JSON expected by
100 > * `thread/approveGuardianDeniedAction` from a completed-review notification.
101 > * Optional fields are omitted when absent (the Rust struct defaults them).
102 > */
103 > export function toGuardianAssessmentEventJson(notification: ItemGuardianApprovalReviewCompletedNotification): JsonValue {
104 const event: Record<string, JsonValue> = {
105 id: notification.reviewId,
129 return event;
130 }
132 > /** A human-readable summary of a reviewed action for the approval card. */
133 > export interface IGuardianActionSummary {
134 > /** Short title (e.g. `"Network access"`). */
135 > readonly title: string;
136 > /** Detail line describing the specific action (e.g. the command or host). */
137 > readonly detail: string;
138 > /** Closest matching tool kind for iconography, when one applies. */
139 > readonly toolKind?: 'terminal' | 'search';
140 > }
141 >
142 > /** Summarise a review action for display on the denied-action approval card. */
143 > export function summarizeGuardianReviewAction(action: GuardianApprovalReviewAction): IGuardianActionSummary {
144 switch (action.type) {
145 case 'command':
161 }
162 }
164 > /** Escape the inline-code span so an embedded backtick can't break out of it. */
165 function inlineCode(text: string): string {
166 // Use a fence long enough to contain any run of backticks in the text, per
172 return `${fence}${padding}${text}${padding}${fence}`;
173 }
175 > /**
176 > * Compose the durable denial notice for an auto-review denial, rendered as a
177 > * Markdown response part (which survives turn completion and, unlike a transient
178 > * progress/system-notification message, is not dropped by the live streaming
179 > * path) so the user always learns *why* an action was blocked — including the
180 > * reviewer rationale — even when the turn ends before the best-effort "Approve
181 > * anyway" card can be acted on. The notice is emitted as a blockquote so it
182 > * stays visually distinct from the model's own prose even when adjacent
183 > * Markdown parts are concatenated into one rendered block.
184 > */
185 > export function formatGuardianDenialNotification(summary: IGuardianActionSummary, rationale: string | null): string {
186 const detail = summary.detail?.trim();
187 const header = '**Auto-review denied**';