return undefined;
}
if (!this._sandboxConfigPath || forceRefresh || this._needsForceUpdateConfigFile) {
this._needsForceUpdateConfigFile = false;
}
return this._sandboxConfigPath;
}
Frontier kind: Code frontier
unlabeled · c_bcda0050cda7
32 tests · 12551 LOC · 56 files · introduces 0 tests · 33 LOC · 1 file
The orange circle is the focus. Violet and green circles are every ancestor and descendant, broader and narrower, at any distance; blue squares and pink diamonds are the introduced files and exact introduced tests of every visible concept, not only the focus's. Arrows point from broader to narrower concepts and bridge only concepts omitted from this view. Undirected links show source or test introduction. Concept and file size follows LOC; exact test nodes use test-count units.
Introduced files, introduced tests, and structurally relevant concept specialization
In the embedded map, ordinary wheel input scrolls the page; use the visible controls to zoom and drag to pan. Open the full-screen map for canvas navigation: wheel pans, Ctrl/Command plus wheel zooms, and arrow keys pan when this region is focused. On touch screens, open the full-screen map to pan or pinch. If JavaScript or WebGL is unavailable, use the native relationship evidence on this page.
Graph controls are ready.
Interactive rendering requires JavaScript and WebGL. Use the native relationship evidence on this page while the interactive map is unavailable.
Every exact file and test below is linked only from the concept that introduces it.
mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/copilotShellTools.test|title=CopilotShellTools primary shell tool merges configured filesystem allowRead paths into the sandbox config|occurrence=1mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/copilotShellTools.test|title=CopilotShellTools primary shell tool writes a sandbox config exposing the working directory as writable|occurrence=1mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/sandbox/test/common/terminalSandboxEngine.test|title=TerminalSandboxEngine requestAllowNetwork keeps the command sandboxed and refreshes its network config|occurrence=1mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/sandbox/test/common/terminalSandboxEngine.test|title=TerminalSandboxEngine runAsNode=false omits the ELECTRON_RUN_AS_NODE=1 prefix|occurrence=1mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/sandbox/test/common/terminalSandboxEngine.test|title=TerminalSandboxEngine wrapCommand adds ripgrep-universal platform-arch bin directory to PATH|occurrence=1mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/sandbox/test/common/terminalSandboxEngine.test|title=TerminalSandboxEngine Windows MXC config ignores unsupported network host lists|occurrence=1mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/sandbox/test/common/terminalSandboxEngine.test|title=TerminalSandboxEngine allowNetwork maps to MXC allow network config on Windows|occurrence=1mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/sandbox/test/common/terminalSandboxEngine.test|title=TerminalSandboxEngine preserves Windows filesystem symlink paths and resolves their targets when writing MXC config|occurrence=1mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/sandbox/test/common/terminalSandboxEngine.test|title=TerminalSandboxEngine wrapCommand applies Windows filesystem setting to MXC config|occurrence=1mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/sandbox/test/common/terminalSandboxEngine.test|title=TerminalSandboxEngine wrapCommand applies configured Windows MXC schema version|occurrence=1mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/sandbox/test/common/terminalSandboxEngine.test|title=TerminalSandboxEngine wrapCommand uses arm64 MXC executable on Windows arm64|occurrence=1mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/base/test/common/lifecycle.test|title=Lifecycle Action bar has broken accessibility #100273|occurrence=1mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/base/test/common/lifecycle.test|title=Lifecycle dispose disposable array|occurrence=1Every collected test enters the hierarchy at exactly one concept.
No tests are introduced at this concept. Its intent tests are introduced by other concepts.
Every collected source range enters the hierarchy at exactly one concept.
1 file ranked by introduced lines: 33 introduced LOC across 13 ranges. Expand a file to inspect source; the > gutter marks introduced lines.
return undefined;
}
if (!this._sandboxConfigPath || forceRefresh || this._needsForceUpdateConfigFile) {
this._needsForceUpdateConfigFile = false;
}
return this._sandboxConfigPath;
}
private async _createSandboxConfig(): Promise<string | undefined> {
await this._initTempDir();
}
if (!this._tempDir) {
return undefined;
}
const allowNetwork = this._commandAllowNetwork || await this.isSandboxAllowNetworkEnabled();
const linuxFileSystemSetting = this._os === OperatingSystem.Linux
? this._getSettingValue<ITerminalSandboxFileSystemSetting>(AgentSandboxSettingId.AgentSandboxLinuxFileSystem) ?? {}
: {};
? this._getSettingValue<ITerminalSandboxFileSystemSetting>(AgentSandboxSettingId.AgentSandboxMacFileSystem) ?? {}
: {};
const windowsFileSystemSetting = this._os === OperatingSystem.Windows
terminalSandboxEngine.ts
? this._getSettingValue<ITerminalSandboxFileSystemSetting>(AgentSandboxSettingId.AgentSandboxWindowsFileSystem) ?? {}
: {};
? this._getSettingValue<string>(AgentSandboxSettingId.AgentSandboxWindowsSchemaVersion)
: undefined;
const runtimeSetting = this._getSettingValue<Record<string, unknown>>(AgentSandboxSettingId.AgentSandboxAdvancedRuntime) ?? {};
terminalSandboxEngine.ts
const commandRuntimeSetting = getTerminalSandboxRuntimeConfigurationForCommands(this._os, this._commandAllowListCommandDetails);
const commandRuntimeAllowReadPaths = this._getCommandRuntimeFileSystemPaths(commandRuntimeSetting, 'allowRead');
const commandRuntimeAllowWritePaths = this._getCommandRuntimeFileSystemPaths(commandRuntimeSetting, 'allowWrite');
const configFileUri = URI.joinPath(this._tempDir, `vscode-sandbox-settings-${this._sandboxSettingsId}.json`);
const configFilePath = this._getUriPath(configFileUri);
let allowWritePaths: string[] = [];
let allowReadPaths: string[] = [];
let denyReadPaths: string[] = [];
let denyWritePaths: string[] | undefined;
if (this._os === OperatingSystem.Windows) {
const filesystemPolicy = await this._getWindowsMxcFilesystemPolicy();
const env = await this._getWindowsMxcEnvironment();
denyReadPaths = await this._resolveFileSystemPaths(windowsFileSystemSetting.denyRead ?? []);
this._windowsMxcEnvironment = env;
allowWritePaths = (await this._resolveFileSystemPaths(await this._updateAllowWritePathsWithWorkspaceFolders(macFileSystemSetting.allowWrite, commandRuntimeAllowWritePaths))).filter(path => path !== configFilePath);
allowReadPaths = await this._resolveFileSystemPaths(await this._updateAllowReadPathsWithAllowWrite(macFileSystemSetting.allowRead, allowWritePaths, commandRuntimeAllowReadPaths));
denyWritePaths = await this._resolveFileSystemPaths(linuxFileSystemSetting.denyWrite);
}
const sandboxSettings = this._os === OperatingSystem.Windows ? await this._windowsMxcRuntime.createConfig({
terminalSandboxEngine.ts
command: this._commandLine ?? '',
shell: this._commandShell,
denyReadPaths,
env: this._windowsMxcEnvironment ?? [],
network: allowNetwork ? { allowedDomains: [], deniedDomains: [], enabled: false } : this.getResolvedNetworkDomains(),
filesystem: {
},
};
const sandboxRuntimeSettings = sandboxSettings as Record<string, unknown>;
this._mergeAdditionalSandboxConfigProperties(sandboxRuntimeSettings, runtimeSetting);
}
}
await this._fileService.createFile(configFileUri, VSBuffer.fromString(JSON.stringify(sandboxSettings, null, '\t')), { overwrite: true });
return this._sandboxConfigPath;
}
private async _getFileSystemAccessPaths(configFilePath: string | undefined): Promise<ITerminalSandboxFileSystemAccessPaths> {