sandboxConfigSchema.ts ×1

Frontier kind: Code frontier

unlabeled · c_d7163e7342a2

1467 tests · 6825 LOC · 36 files · introduces 0 tests · 143 LOC · 1 file

Introduces — evidence that enters the hierarchy at this concept

Code
1 range143 lines · 1 files
Tests
0 tests

Contains — complete concept membership

All code (extent)
560 ranges6825 lines · 36 files · Browse complete extent
All tests (intent)
1467 testsBrowse complete intent

Neighbourhood graph

The orange circle is the focus. Violet and green circles are every ancestor and descendant, broader and narrower, at any distance; blue squares and pink diamonds are the introduced files and exact introduced tests of every visible concept, not only the focus's. Arrows point from broader to narrower concepts and bridge only concepts omitted from this view. Undirected links show source or test introduction. Concept and file size follows LOC; exact test nodes use test-count units.

Introduced files, introduced tests, and structurally relevant concept specialization

In the embedded map, ordinary wheel input scrolls the page; use the visible controls to zoom and drag to pan. Open the full-screen map for canvas navigation: wheel pans, Ctrl/Command plus wheel zooms, and arrow keys pan when this region is focused. On touch screens, open the full-screen map to pan or pinch. If JavaScript or WebGL is unavailable, use the native relationship evidence on this page.

Graph controls are ready.

Interactive rendering requires JavaScript and WebGL. Use the native relationship evidence on this page while the interactive map is unavailable.

Native relationship evidence

Every exact file and test below is linked only from the concept that introduces it.

Introduced tests

Every collected test enters the hierarchy at exactly one concept.

No tests are introduced at this concept. Its intent tests are introduced by other concepts.

Introduced code

Every collected source range enters the hierarchy at exactly one concept.

1 file ranked by introduced lines: 143 introduced LOC across 1 ranges. Expand a file to inspect source; the > gutter marks introduced lines.

src/vs/platform/agentHost/common/sandboxConfigSchema.ts 143 introduced LOC · 1 range

Open complete file

1 > /*--------------------------------------------------------------------------------------------- sandboxConfigSchema.ts
2 > * Copyright (c) Microsoft Corporation. All rights reserved.
3 > * Licensed under the MIT License. See License.txt in the project root for license information.
4 > *--------------------------------------------------------------------------------------------*/
5 >
6 > import { localize } from '../../../nls.js';
7 > import { AgentNetworkDomainSettingId } from '../../networkFilter/common/settings.js';
8 > import { AgentSandboxEnabledValue, AgentSandboxSettingId } from '../../sandbox/common/settings.js';
9 > import { createSchema, schemaProperty } from './agentHostSchema.js';
10 >
11 > /**
12 > * Top-level keys the agent host's root config bag exposes for sandboxing.
13 > * All sandbox-related values live nested under {@link AgentHostSandboxConfigKey.Sandbox}
14 > * — the persisted JSON has a single `"sandbox": { ... }` object rather than a
15 > * dozen flat keys.
16 > */
17 > export const enum AgentHostSandboxConfigKey {
18 > Sandbox = 'sandbox',
19 > }
20 >
21 > /**
22 > * Well-known sub-keys inside the agent host's `sandbox` object. These are
23 > * intentionally a flat, prefix-free namespace owned by the agent host —
24 > * distinct from the workbench's `chat.agent.sandbox.*` setting IDs. Hosts
25 > * (today: the workbench client) translate from their setting IDs to these
26 > * keys when forwarding values via a `RootConfigChanged` action.
27 > */
28 > export const enum AgentHostSandboxKey {
29 > Enabled = 'enabled',
30 > WindowsEnabled = 'enabled.windows',
31 > AllowNetwork = 'allowNetwork',
32 > AllowUnsandboxedCommands = 'allowUnsandboxedCommands',
33 > LinuxFileSystem = 'fileSystem.linux',
34 > MacFileSystem = 'fileSystem.mac',
35 > WindowsFileSystem = 'fileSystem.windows',
36 > AdvancedRuntime = 'advanced.runtime',
37 > AllowedNetworkDomains = 'allowedNetworkDomains',
38 > DeniedNetworkDomains = 'deniedNetworkDomains',
39 > }
40 >
41 > /** Shape of the persisted/forwarded `sandbox` object. */
42 > export type ISandboxConfigValue = Partial<{
43 > [AgentHostSandboxKey.Enabled]: AgentSandboxEnabledValue;
44 > [AgentHostSandboxKey.WindowsEnabled]: AgentSandboxEnabledValue;
45 > [AgentHostSandboxKey.AllowNetwork]: boolean;
46 > [AgentHostSandboxKey.AllowUnsandboxedCommands]: boolean;
47 > [AgentHostSandboxKey.LinuxFileSystem]: Record<string, unknown>;
48 > [AgentHostSandboxKey.MacFileSystem]: Record<string, unknown>;
49 > [AgentHostSandboxKey.WindowsFileSystem]: Record<string, unknown>;
50 > [AgentHostSandboxKey.AdvancedRuntime]: Record<string, unknown>;
51 > [AgentHostSandboxKey.AllowedNetworkDomains]: string[];
52 > [AgentHostSandboxKey.DeniedNetworkDomains]: string[];
53 > }>;
54 >
55 > /**
56 > * Schema for the subset of workbench sandbox settings that hosts (today: the
57 > * workbench client) may forward into the agent host's root config bag.
58 > *
59 > * The agent host's terminal sandbox engine reads these values through
60 > * {@link IAgentConfigurationService.getRootValue}. Only the modern,
61 > * normalized form of each setting is declared here — the workbench is
62 > * expected to:
63 > *
64 > * - map legacy boolean sandbox enabled values to the `'on' | 'off' | 'allowNetwork'`
65 > * agent-host enum, and
66 > * - migrate values from any deprecated setting IDs to their modern key
67 > *
68 > * before pushing a `RootConfigChanged` action. That keeps the agent-host
69 > * schema (and validation) free of backward-compat baggage.
70 > */
71 > export const sandboxConfigSchema = createSchema({
72 > [AgentHostSandboxConfigKey.Sandbox]: schemaProperty<ISandboxConfigValue>({
73 > type: 'object',
74 > title: localize('agentHost.config.sandbox.title', "Agent Sandbox"),
75 > properties: {
76 > [AgentHostSandboxKey.Enabled]: {
77 > type: 'string',
78 > title: localize('agentHost.config.sandbox.enabled.title', "Sandbox Enabled"),
79 > enum: [AgentSandboxEnabledValue.Off, AgentSandboxEnabledValue.On, AgentSandboxEnabledValue.AllowNetwork],
80 > },
81 > [AgentHostSandboxKey.WindowsEnabled]: {
82 > type: 'string',
83 > title: localize('agentHost.config.sandbox.windowsEnabled.title', "Sandbox Enabled (Windows)"),
84 > enum: [AgentSandboxEnabledValue.Off, AgentSandboxEnabledValue.On, AgentSandboxEnabledValue.AllowNetwork],
85 > },
86 > [AgentHostSandboxKey.AllowNetwork]: {
87 > type: 'boolean',
88 > title: localize('agentHost.config.sandbox.allowNetwork.title', "Allow Network"),
89 > },
90 > [AgentHostSandboxKey.AllowUnsandboxedCommands]: {
91 > type: 'boolean',
92 > title: localize('agentHost.config.sandbox.allowUnsandboxedCommands.title', "Allow Unsandboxed Commands"),
93 > },
94 > [AgentHostSandboxKey.LinuxFileSystem]: {
95 > type: 'object',
96 > title: localize('agentHost.config.sandbox.linuxFileSystem.title', "Linux Sandbox Filesystem"),
97 > },
98 > [AgentHostSandboxKey.MacFileSystem]: {
99 > type: 'object',
100 > title: localize('agentHost.config.sandbox.macFileSystem.title', "macOS Sandbox Filesystem"),
101 > },
102 > [AgentHostSandboxKey.WindowsFileSystem]: {
103 > type: 'object',
104 > title: localize('agentHost.config.sandbox.windowsFileSystem.title', "Windows Sandbox Filesystem"),
105 > },
106 > [AgentHostSandboxKey.AdvancedRuntime]: {
107 > type: 'object',
108 > title: localize('agentHost.config.sandbox.advancedRuntime.title', "Advanced Sandbox Runtime"),
109 > },
110 > [AgentHostSandboxKey.AllowedNetworkDomains]: {
111 > type: 'array',
112 > title: localize('agentHost.config.sandbox.allowedDomains.title', "Allowed Network Domains"),
113 > items: { type: 'string', title: localize('agentHost.config.sandbox.allowedDomains.item.title', "Domain") },
114 > },
115 > [AgentHostSandboxKey.DeniedNetworkDomains]: {
116 > type: 'array',
117 > title: localize('agentHost.config.sandbox.deniedDomains.title', "Denied Network Domains"),
118 > items: { type: 'string', title: localize('agentHost.config.sandbox.deniedDomains.item.title', "Domain") },
119 > },
120 > },
121 > }),
122 > });
123 >
124 > /**
125 > * Maps modern workbench sandbox setting IDs (the ones the engine asks about)
126 > * to the sub-keys inside the agent host's `sandbox` config object.
127 > *
128 > * Deprecated setting IDs are intentionally absent: hosts forwarding values
129 > * into the agent host are expected to migrate deprecated → modern IDs
130 > * before dispatching `RootConfigChanged`.
131 > */
132 > export const sandboxSettingIdToAgentHostKey: Readonly<Record<string, AgentHostSandboxKey>> = {
133 > [AgentSandboxSettingId.AgentSandboxEnabled]: AgentHostSandboxKey.Enabled,
134 > [AgentSandboxSettingId.AgentSandboxWindowsEnabled]: AgentHostSandboxKey.WindowsEnabled,
135 > [AgentSandboxSettingId.AgentSandboxAllowNetwork]: AgentHostSandboxKey.AllowNetwork,
136 > [AgentSandboxSettingId.AgentSandboxAllowUnsandboxedCommands]: AgentHostSandboxKey.AllowUnsandboxedCommands,
137 > [AgentSandboxSettingId.AgentSandboxLinuxFileSystem]: AgentHostSandboxKey.LinuxFileSystem,
138 > [AgentSandboxSettingId.AgentSandboxMacFileSystem]: AgentHostSandboxKey.MacFileSystem,
139 > [AgentSandboxSettingId.AgentSandboxWindowsFileSystem]: AgentHostSandboxKey.WindowsFileSystem,
140 > [AgentSandboxSettingId.AgentSandboxAdvancedRuntime]: AgentHostSandboxKey.AdvancedRuntime,
141 > [AgentNetworkDomainSettingId.AllowedNetworkDomains]: AgentHostSandboxKey.AllowedNetworkDomains,
142 > [AgentNetworkDomainSettingId.DeniedNetworkDomains]: AgentHostSandboxKey.DeniedNetworkDomains,
143 > };
144