sandboxConfigForSdk.ts ×2

Frontier kind: Code frontier

unlabeled · c_c2ebbc9e83bf

19 tests · 6955 LOC · 37 files · introduces 0 tests · 3 LOC · 1 file

Introduces — evidence that enters the hierarchy at this concept

Code
2 ranges3 lines · 1 files
Tests
0 tests

Contains — complete concept membership

All code (extent)
572 ranges6955 lines · 37 files · Browse complete extent
All tests (intent)
19 testsBrowse complete intent

Neighbourhood graph

The orange circle is the focus. Violet and green circles are every ancestor and descendant, broader and narrower, at any distance; blue squares and pink diamonds are the introduced files and exact introduced tests of every visible concept, not only the focus's. Arrows point from broader to narrower concepts and bridge only concepts omitted from this view. Undirected links show source or test introduction. Concept and file size follows LOC; exact test nodes use test-count units.

Introduced files, introduced tests, and structurally relevant concept specialization

In the embedded map, ordinary wheel input scrolls the page; use the visible controls to zoom and drag to pan. Open the full-screen map for canvas navigation: wheel pans, Ctrl/Command plus wheel zooms, and arrow keys pan when this region is focused. On touch screens, open the full-screen map to pan or pinch. If JavaScript or WebGL is unavailable, use the native relationship evidence on this page.

Introduced files, introduced tests, and structurally relevant concept specializationcopilotAgentSession.test|title=CopilotAgentSession permission handling per-request sandbox: applies the configured policy under default approvals|occurrence=1, copilotAgentSession.test|title=CopilotAgentSession permission handling per-request permissions: Autopilot with Ask When Needed keeps SDK approval mode off|occurrence=1 · 0 introduced LOCcopilotAgentSession.test…copilotAgentSession.test|title=CopilotAgentSession permission handling per-request sandbox: disabled under global auto-approve|occurrence=1 · 0 introduced LOCcopilotAgentSession.test…copilotAgentSession.test|title=CopilotAgentSession permission handling per-request sandbox: disabled under session bypass approvals|occurrence=1 · 0 introduced LOCcopilotAgentSession.test…copilotAgentSession.ts ×1 · 8 introduced LOCcopilotAgentSession.ts ×…sandboxConfigForSdk.ts ×1 · 2 introduced LOCsandboxConfigForSdk.ts ×… allowRead for the same path|occurrence=1 · 0 introduced LOC allowRead for the same …sandboxConfigForSdk.test|title=buildSandboxConfigForSdk filesystem policy denyRead wins over every other setting for the same path|occurrence=1 · 0 introduced LOCsandboxConfigForSdk.test…sandboxConfigForSdk.test|title=buildSandboxConfigForSdk filesystem policy keeps distinct paths in their own lists when settings overlap on some paths|occurrence=1 · 0 introduced LOCsandboxConfigForSdk.test…sandboxConfigForSdk.test|title=buildSandboxConfigForSdk filesystem policy allowWrite wins over allowRead for the same path|occurrence=1 · 0 introduced LOCsandboxConfigForSdk.test…sandboxConfigForSdk.test|title=buildSandboxConfigForSdk filesystem policy selects the OS-specific slice from the per-OS filesystem keys|occurrence=1 · 0 introduced LOCsandboxConfigForSdk.test…sandboxConfigForSdk.ts ×1 · 2 introduced LOCsandboxConfigForSdk.ts ×…sandboxConfigForSdk.ts ×2 · 2 introduced LOCsandboxConfigForSdk.ts ×…sandboxConfigForSdk.ts ×2 · 2 introduced LOCsandboxConfigForSdk.ts ×…sandboxConfigForSdk.ts ×1 · 2 introduced LOCsandboxConfigForSdk.ts ×…sandboxConfigForSdk.ts ×2 · 2 introduced LOCsandboxConfigForSdk.ts ×…sandboxConfigForSdk.test|title=buildSandboxConfigForSdk enablement enables sandbox for `on` on non-Windows platforms|occurrence=1, sandboxConfigForSdk.test|title=buildSandboxConfigForSdk network hosts ignores host lists when sandbox is `allowNetwork` (allow all)|occurrence=1, +2 · 0 introduced LOCsandboxConfigForSdk.test…sandboxConfigForSdk.ts ×1 · 1 introduced LOCsandboxConfigForSdk.ts ×…sandboxConfigForSdk.ts ×1 · 1 introduced LOCsandboxConfigForSdk.ts ×…sandboxConfigForSdk.ts ×3 · 6 introduced LOCsandboxConfigForSdk.ts ×…sandboxConfigForSdk.ts ×1 · 2 introduced LOCsandboxConfigForSdk.ts ×…sandboxConfigForSdk.ts ×1 · 3 introduced LOCsandboxConfigForSdk.ts ×…sandboxConfigForSdk.ts ×7 · 37 introduced LOCsandboxConfigForSdk.ts ×…sandboxConfigForSdk.ts ×1 · 85 introduced LOCsandboxConfigForSdk.ts ×…sandboxConfigSchema.ts ×1 · 143 introduced LOCsandboxConfigSchema.ts ×…agentHostSchema.ts ×21 · 546 introduced LOCagentHostSchema.ts ×21settings.ts ×2 · 36 introduced LOCsettings.ts ×2configuration.ts ×12 · 203 introduced LOCconfiguration.ts ×12sessionProtocol.ts ×5 · 364 introduced LOCsessionProtocol.ts ×5settings.ts ×1 · 21 introduced LOCsettings.ts ×1sessionConfigKeys.ts ×1 · 52 introduced LOCsessionConfigKeys.ts ×1commands.ts ×1 · 1661 introduced LOCcommands.ts ×1equals.ts ×14 · 108 introduced LOCequals.ts ×14state.ts ×1 · 73 introduced LOCstate.ts ×1uri.test|title=URI URI#file, win-speciale|occurrence=1, charCode.test|title=CharCode has good values|occurrence=1, +2 · 0 introduced LOCuri.test|title=URI URI#f…utils.ts ×3 · 9 introduced LOCutils.ts ×3telemetry.ts ×3 · 115 introduced LOCtelemetry.ts ×3nls.ts ×1 · 1 introduced LOCnls.ts ×1nls.ts ×6 · 13 introduced LOCnls.ts ×6instantiation.ts ×5 · 111 introduced LOCinstantiation.ts ×5lifecycle.ts ×2 · 4 introduced LOClifecycle.ts ×2lifecycle.ts ×1 · 2 introduced LOClifecycle.ts ×1lifecycle.ts ×4 · 8 introduced LOClifecycle.ts ×4lifecycle.ts ×6 · 16 introduced LOClifecycle.ts ×6lifecycle.ts ×1 · 2 introduced LOClifecycle.ts ×1lifecycle.ts ×1 · 2 introduced LOClifecycle.ts ×1lifecycle.ts ×1 · 3 introduced LOClifecycle.ts ×1map.ts ×97 · 3334 introduced LOCmap.ts ×97src/vs/base/common/arrays.ts · 949 LOCcommon/arrays.tssrc/vs/base/common/arraysFind.ts · 226 LOCcommon/arraysFind.tssrc/vs/base/common/assert.ts · 91 LOCcommon/assert.tssrc/vs/base/common/charCode.ts · 450 LOCcommon/charCode.tssrc/vs/base/common/collections.ts · 176 LOCcommon/collections.tssrc/vs/base/common/equals.ts · 206 LOCcommon/equals.tssrc/vs/base/common/errors.ts · 357 LOCcommon/errors.tssrc/vs/base/common/functional.ts · 32 LOCcommon/functional.tssrc/vs/base/common/iterator.ts · 194 LOCcommon/iterator.tssrc/vs/base/common/lifecycle.ts · 974 LOCcommon/lifecycle.tssrc/vs/base/common/map.ts · 1016 LOCcommon/map.tssrc/vs/base/common/marshallingIds.ts · 33 LOCcommon/marshallingIds.tssrc/vs/base/common/path.ts · 1589 LOCcommon/path.tssrc/vs/base/common/platform.ts · 281 LOCcommon/platform.tssrc/vs/base/common/process.ts · 76 LOCcommon/process.tssrc/vs/base/common/types.ts · 410 LOCcommon/types.tssrc/vs/base/common/uri.ts · 754 LOCcommon/uri.tssrc/vs/base/test/common/utils.ts · 107 LOCcommon/utils.tssrc/vs/nls.ts · 244 LOCvs/nls.tssrc/vs/platform/agentHost/common/agentHostSchema.ts · 732 LOCcommon/agentHostSchema.t…src/vs/platform/agentHost/common/sandboxConfigSchema.ts · 144 LOCcommon/sandboxConfigSche…src/vs/platform/agentHost/common/sessionConfigKeys.ts · 52 LOCcommon/sessionConfigKeys…src/vs/platform/agentHost/common/state/protocol/channels-changeset/commands.ts · 105 LOCchannels-changeset/comma…src/vs/platform/agentHost/common/state/protocol/channels-chat/commands.ts · 147 LOCchannels-chat/commands.t…src/vs/platform/agentHost/common/state/protocol/channels-resource-watch/state.ts · 73 LOCchannels-resource-watch/…src/vs/platform/agentHost/common/state/protocol/channels-session/commands.ts · 323 LOCchannels-session/command…src/vs/platform/agentHost/common/state/protocol/commands.ts · 15 LOCprotocol/commands.tssrc/vs/platform/agentHost/common/state/protocol/common/commands.ts · 1071 LOCcommon/commands.tssrc/vs/platform/agentHost/common/state/protocol/common/errors.ts · 215 LOCcommon/errors.tssrc/vs/platform/agentHost/common/state/protocol/errors.ts · 9 LOCprotocol/errors.tssrc/vs/platform/agentHost/common/state/sessionProtocol.ts · 148 LOCstate/sessionProtocol.tssrc/vs/platform/agentHost/node/copilot/copilotAgentSession.ts · 4663 LOCcopilot/copilotAgentSess…src/vs/platform/agentHost/node/copilot/sandboxConfigForSdk.ts · 156 LOCcopilot/sandboxConfigFor…src/vs/platform/configuration/common/configuration.ts · 358 LOCcommon/configuration.tssrc/vs/platform/instantiation/common/instantiation.ts · 130 LOCcommon/instantiation.tssrc/vs/platform/networkFilter/common/settings.ts · 21 LOCcommon/settings.tssrc/vs/platform/sandbox/common/settings.ts · 46 LOCcommon/settings.tssrc/vs/platform/telemetry/common/telemetry.ts · 119 LOCcommon/telemetry.tscharCode.test|title=CharCode has good values|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/base/test/common/charCode.test|title=CharCode has good values|occurrence=1charCode.test|title=Char…path.test|title=Paths (Node Implementation) path|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/base/test/common/path.test|title=Paths (Node Implementation) path|occurrence=1path.test|title=Paths (N…uri.test|title=URI File paths containing apostrophes break URI parsing and cannot be opened #276075|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/base/test/common/uri.test|title=URI File paths containing apostrophes break URI parsing and cannot be opened #276075|occurrence=1uri.test|title=URI File …uri.test|title=URI URI#file, win-speciale|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/base/test/common/uri.test|title=URI URI#file, win-speciale|occurrence=1uri.test|title=URI URI#f…copilotAgentSession.test|title=CopilotAgentSession permission handling auto-approves sandboxed-by-default shell command without prompting|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/copilotAgentSession.test|title=CopilotAgentSession permission handling auto-approves sandboxed-by-default shell command without prompting|occurrence=1copilotAgentSession.test…copilotAgentSession.test|title=CopilotAgentSession permission handling per-request permissions: Autopilot with Ask When Needed keeps SDK approval mode off|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/copilotAgentSession.test|title=CopilotAgentSession permission handling per-request permissions: Autopilot with Ask When Needed keeps SDK approval mode off|occurrence=1copilotAgentSession.test…copilotAgentSession.test|title=CopilotAgentSession permission handling per-request sandbox: applies the configured policy under default approvals|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/copilotAgentSession.test|title=CopilotAgentSession permission handling per-request sandbox: applies the configured policy under default approvals|occurrence=1copilotAgentSession.test…copilotAgentSession.test|title=CopilotAgentSession permission handling per-request sandbox: disabled under global auto-approve|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/copilotAgentSession.test|title=CopilotAgentSession permission handling per-request sandbox: disabled under global auto-approve|occurrence=1copilotAgentSession.test…copilotAgentSession.test|title=CopilotAgentSession permission handling per-request sandbox: disabled under session bypass approvals|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/copilotAgentSession.test|title=CopilotAgentSession permission handling per-request sandbox: disabled under session bypass approvals|occurrence=1copilotAgentSession.test…sandboxConfigForSdk.test|title=buildSandboxConfigForSdk enablement enables sandbox and outbound network for `allowNetwork` on non-Windows platforms|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/sandboxConfigForSdk.test|title=buildSandboxConfigForSdk enablement enables sandbox and outbound network for `allowNetwork` on non-Windows platforms|occurrence=1sandboxConfigForSdk.test…sandboxConfigForSdk.test|title=buildSandboxConfigForSdk enablement enables sandbox for `on` on non-Windows platforms|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/sandboxConfigForSdk.test|title=buildSandboxConfigForSdk enablement enables sandbox for `on` on non-Windows platforms|occurrence=1sandboxConfigForSdk.test…sandboxConfigForSdk.test|title=buildSandboxConfigForSdk enablement returns undefined for `off`|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/sandboxConfigForSdk.test|title=buildSandboxConfigForSdk enablement returns undefined for `off`|occurrence=1sandboxConfigForSdk.test…sandboxConfigForSdk.test|title=buildSandboxConfigForSdk enablement returns undefined when the bag is empty|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/sandboxConfigForSdk.test|title=buildSandboxConfigForSdk enablement returns undefined when the bag is empty|occurrence=1sandboxConfigForSdk.test…sandboxConfigForSdk.test|title=buildSandboxConfigForSdk filesystem policy allowWrite wins over allowRead for the same path|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/sandboxConfigForSdk.test|title=buildSandboxConfigForSdk filesystem policy allowWrite wins over allowRead for the same path|occurrence=1sandboxConfigForSdk.test…sandboxConfigForSdk.test|title=buildSandboxConfigForSdk filesystem policy denyRead wins over every other setting for the same path|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/sandboxConfigForSdk.test|title=buildSandboxConfigForSdk filesystem policy denyRead wins over every other setting for the same path|occurrence=1sandboxConfigForSdk.test… allowRead for the same path|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/sandboxConfigForSdk.test|title=buildSandboxConfigForSdk filesystem policy denyWrite wins over allowWrite / allowRead for the same path|occurrence=1 allowRead for the same …sandboxConfigForSdk.test|title=buildSandboxConfigForSdk filesystem policy keeps distinct paths in their own lists when settings overlap on some paths|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/sandboxConfigForSdk.test|title=buildSandboxConfigForSdk filesystem policy keeps distinct paths in their own lists when settings overlap on some paths|occurrence=1sandboxConfigForSdk.test…sandboxConfigForSdk.test|title=buildSandboxConfigForSdk filesystem policy maps each setting to the corresponding SDK list|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/sandboxConfigForSdk.test|title=buildSandboxConfigForSdk filesystem policy maps each setting to the corresponding SDK list|occurrence=1sandboxConfigForSdk.test…sandboxConfigForSdk.test|title=buildSandboxConfigForSdk filesystem policy omits filesystem lists that are empty|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/sandboxConfigForSdk.test|title=buildSandboxConfigForSdk filesystem policy omits filesystem lists that are empty|occurrence=1sandboxConfigForSdk.test…sandboxConfigForSdk.test|title=buildSandboxConfigForSdk filesystem policy selects the OS-specific slice from the per-OS filesystem keys|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/sandboxConfigForSdk.test|title=buildSandboxConfigForSdk filesystem policy selects the OS-specific slice from the per-OS filesystem keys|occurrence=1sandboxConfigForSdk.test…sandboxConfigForSdk.test|title=buildSandboxConfigForSdk network hosts drops host lists and keeps outbound closed when sandbox is `on` (host lists disabled on all platforms)|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/sandboxConfigForSdk.test|title=buildSandboxConfigForSdk network hosts drops host lists and keeps outbound closed when sandbox is `on` (host lists disabled on all platforms)|occurrence=1sandboxConfigForSdk.test…sandboxConfigForSdk.test|title=buildSandboxConfigForSdk network hosts ignores empty host lists|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/sandboxConfigForSdk.test|title=buildSandboxConfigForSdk network hosts ignores empty host lists|occurrence=1sandboxConfigForSdk.test…sandboxConfigForSdk.test|title=buildSandboxConfigForSdk network hosts ignores host lists when sandbox is `allowNetwork` (allow all)|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/sandboxConfigForSdk.test|title=buildSandboxConfigForSdk network hosts ignores host lists when sandbox is `allowNetwork` (allow all)|occurrence=1sandboxConfigForSdk.test…Focused concept · sandboxConfigForSdk.ts ×2 · 3 introduced LOCsandboxConfigForSdk.ts ×…

Graph controls are ready.

Interactive rendering requires JavaScript and WebGL. Use the native relationship evidence on this page while the interactive map is unavailable.

Native relationship evidence

Every exact file and test below is linked only from the concept that introduces it.

Introduced tests

Every collected test enters the hierarchy at exactly one concept.

No tests are introduced at this concept. Its intent tests are introduced by other concepts.

Introduced code

Every collected source range enters the hierarchy at exactly one concept.

1 file ranked by introduced lines: 3 introduced LOC across 2 ranges. Expand a file to inspect source; the > gutter marks introduced lines.

src/vs/platform/agentHost/node/copilot/sandboxConfigForSdk.ts 3 introduced LOC · 2 ranges

Open complete file

96 return undefined;
97 }
99 > const enabledRaw = platform === 'win32' && sandbox[AgentHostSandboxKey.WindowsEnabled] !== undefined
100 ? sandbox[AgentHostSandboxKey.WindowsEnabled]
101 > : sandbox[AgentHostSandboxKey.Enabled]; sandboxConfigForSdk.ts
102 if (enabledRaw !== AgentSandboxEnabledValue.On && enabledRaw !== AgentSandboxEnabledValue.AllowNetwork) {
103 return undefined;