1
>
/*---------------------------------------------------------------------------------------------
sandboxConfigSchema.ts
2
>
* Copyright (c) Microsoft Corporation. All rights reserved.
3
>
* Licensed under the MIT License. See License.txt in the project root for license information.
4
>
*--------------------------------------------------------------------------------------------*/
5
>
6
>
import { localize } from '../../../nls.js';
7
>
import { AgentNetworkDomainSettingId } from '../../networkFilter/common/settings.js';
8
>
import { AgentSandboxEnabledValue, AgentSandboxSettingId } from '../../sandbox/common/settings.js';
9
>
import { createSchema, schemaProperty } from './agentHostSchema.js';
10
>
11
>
/**
12
>
* Top-level keys the agent host's root config bag exposes for sandboxing.
13
>
* All sandbox-related values live nested under {@link AgentHostSandboxConfigKey.Sandbox}
14
>
* — the persisted JSON has a single `"sandbox": { ... }` object rather than a
15
>
* dozen flat keys.
16
>
*/
17
>
export const enum AgentHostSandboxConfigKey {
18
>
Sandbox = 'sandbox',
19
>
}
20
>
21
>
/**
22
>
* Well-known sub-keys inside the agent host's `sandbox` object. These are
23
>
* intentionally a flat, prefix-free namespace owned by the agent host —
24
>
* distinct from the workbench's `chat.agent.sandbox.*` setting IDs. Hosts
25
>
* (today: the workbench client) translate from their setting IDs to these
26
>
* keys when forwarding values via a `RootConfigChanged` action.
27
>
*/
28
>
export const enum AgentHostSandboxKey {
29
>
Enabled = 'enabled',
30
>
WindowsEnabled = 'enabled.windows',
31
>
AllowNetwork = 'allowNetwork',
32
>
AllowUnsandboxedCommands = 'allowUnsandboxedCommands',
33
>
LinuxFileSystem = 'fileSystem.linux',
34
>
MacFileSystem = 'fileSystem.mac',
35
>
WindowsFileSystem = 'fileSystem.windows',
36
>
AdvancedRuntime = 'advanced.runtime',
37
>
AllowedNetworkDomains = 'allowedNetworkDomains',
38
>
DeniedNetworkDomains = 'deniedNetworkDomains',
39
>
}
40
>
41
>
/** Shape of the persisted/forwarded `sandbox` object. */
42
>
export type ISandboxConfigValue = Partial<{
43
>
[AgentHostSandboxKey.Enabled]: AgentSandboxEnabledValue;
44
>
[AgentHostSandboxKey.WindowsEnabled]: AgentSandboxEnabledValue;
45
>
[AgentHostSandboxKey.AllowNetwork]: boolean;
46
>
[AgentHostSandboxKey.AllowUnsandboxedCommands]: boolean;
47
>
[AgentHostSandboxKey.LinuxFileSystem]: Record<string, unknown>;
48
>
[AgentHostSandboxKey.MacFileSystem]: Record<string, unknown>;
49
>
[AgentHostSandboxKey.WindowsFileSystem]: Record<string, unknown>;
50
>
[AgentHostSandboxKey.AdvancedRuntime]: Record<string, unknown>;
51
>
[AgentHostSandboxKey.AllowedNetworkDomains]: string[];
52
>
[AgentHostSandboxKey.DeniedNetworkDomains]: string[];
53
>
}>;
54
>
55
>
/**
56
>
* Schema for the subset of workbench sandbox settings that hosts (today: the
57
>
* workbench client) may forward into the agent host's root config bag.
58
>
*
59
>
* The agent host's terminal sandbox engine reads these values through
60
>
* {@link IAgentConfigurationService.getRootValue}. Only the modern,
61
>
* normalized form of each setting is declared here — the workbench is
62
>
* expected to:
63
>
*
64
>
* - map legacy boolean sandbox enabled values to the `'on' | 'off' | 'allowNetwork'`
65
>
* agent-host enum, and
66
>
* - migrate values from any deprecated setting IDs to their modern key
67
>
*
68
>
* before pushing a `RootConfigChanged` action. That keeps the agent-host
69
>
* schema (and validation) free of backward-compat baggage.
70
>
*/
71
>
export const sandboxConfigSchema = createSchema({
72
>
[AgentHostSandboxConfigKey.Sandbox]: schemaProperty<ISandboxConfigValue>({
73
>
type: 'object',
74
>
title: localize('agentHost.config.sandbox.title', "Agent Sandbox"),
75
>
properties: {
76
>
[AgentHostSandboxKey.Enabled]: {
77
>
type: 'string',
78
>
title: localize('agentHost.config.sandbox.enabled.title', "Sandbox Enabled"),
79
>
enum: [AgentSandboxEnabledValue.Off, AgentSandboxEnabledValue.On, AgentSandboxEnabledValue.AllowNetwork],
80
>
},
81
>
[AgentHostSandboxKey.WindowsEnabled]: {
82
>
type: 'string',
83
>
title: localize('agentHost.config.sandbox.windowsEnabled.title', "Sandbox Enabled (Windows)"),
84
>
enum: [AgentSandboxEnabledValue.Off, AgentSandboxEnabledValue.On, AgentSandboxEnabledValue.AllowNetwork],
85
>
},
86
>
[AgentHostSandboxKey.AllowNetwork]: {
87
>
type: 'boolean',
88
>
title: localize('agentHost.config.sandbox.allowNetwork.title', "Allow Network"),
89
>
},
90
>
[AgentHostSandboxKey.AllowUnsandboxedCommands]: {
91
>
type: 'boolean',
92
>
title: localize('agentHost.config.sandbox.allowUnsandboxedCommands.title', "Allow Unsandboxed Commands"),
93
>
},
94
>
[AgentHostSandboxKey.LinuxFileSystem]: {
95
>
type: 'object',
96
>
title: localize('agentHost.config.sandbox.linuxFileSystem.title', "Linux Sandbox Filesystem"),
97
>
},
98
>
[AgentHostSandboxKey.MacFileSystem]: {
99
>
type: 'object',
100
>
title: localize('agentHost.config.sandbox.macFileSystem.title', "macOS Sandbox Filesystem"),
101
>
},
102
>
[AgentHostSandboxKey.WindowsFileSystem]: {
103
>
type: 'object',
104
>
title: localize('agentHost.config.sandbox.windowsFileSystem.title', "Windows Sandbox Filesystem"),
105
>
},
106
>
[AgentHostSandboxKey.AdvancedRuntime]: {
107
>
type: 'object',
108
>
title: localize('agentHost.config.sandbox.advancedRuntime.title', "Advanced Sandbox Runtime"),
109
>
},
110
>
[AgentHostSandboxKey.AllowedNetworkDomains]: {
111
>
type: 'array',
112
>
title: localize('agentHost.config.sandbox.allowedDomains.title', "Allowed Network Domains"),
113
>
items: { type: 'string', title: localize('agentHost.config.sandbox.allowedDomains.item.title', "Domain") },
114
>
},
115
>
[AgentHostSandboxKey.DeniedNetworkDomains]: {
116
>
type: 'array',
117
>
title: localize('agentHost.config.sandbox.deniedDomains.title', "Denied Network Domains"),
118
>
items: { type: 'string', title: localize('agentHost.config.sandbox.deniedDomains.item.title', "Domain") },
119
>
},
120
>
},
121
>
}),
122
>
});
123
>
124
>
/**
125
>
* Maps modern workbench sandbox setting IDs (the ones the engine asks about)
126
>
* to the sub-keys inside the agent host's `sandbox` config object.
127
>
*
128
>
* Deprecated setting IDs are intentionally absent: hosts forwarding values
129
>
* into the agent host are expected to migrate deprecated → modern IDs
130
>
* before dispatching `RootConfigChanged`.
131
>
*/
132
>
export const sandboxSettingIdToAgentHostKey: Readonly<Record<string, AgentHostSandboxKey>> = {
133
>
[AgentSandboxSettingId.AgentSandboxEnabled]: AgentHostSandboxKey.Enabled,
134
>
[AgentSandboxSettingId.AgentSandboxWindowsEnabled]: AgentHostSandboxKey.WindowsEnabled,
135
>
[AgentSandboxSettingId.AgentSandboxAllowNetwork]: AgentHostSandboxKey.AllowNetwork,
136
>
[AgentSandboxSettingId.AgentSandboxAllowUnsandboxedCommands]: AgentHostSandboxKey.AllowUnsandboxedCommands,
137
>
[AgentSandboxSettingId.AgentSandboxLinuxFileSystem]: AgentHostSandboxKey.LinuxFileSystem,
138
>
[AgentSandboxSettingId.AgentSandboxMacFileSystem]: AgentHostSandboxKey.MacFileSystem,
139
>
[AgentSandboxSettingId.AgentSandboxWindowsFileSystem]: AgentHostSandboxKey.WindowsFileSystem,
140
>
[AgentSandboxSettingId.AgentSandboxAdvancedRuntime]: AgentHostSandboxKey.AdvancedRuntime,
141
>
[AgentNetworkDomainSettingId.AllowedNetworkDomains]: AgentHostSandboxKey.AllowedNetworkDomains,
142
>
[AgentNetworkDomainSettingId.DeniedNetworkDomains]: AgentHostSandboxKey.DeniedNetworkDomains,
143
>
};
144