src/vs/platform/agentHost/node/codex/codexSessionConfigKeys.ts

197 LOC · 197 covered · 0 uncovered · 37 ranges · 25 concepts · 11 introducers · 13 tests

File neighbourhood

The centred file is linked to every concept that introduces one of its ranges, every test that runs code from the file, and the gray connector concepts standing between those tests and the file's own introducer concepts. Undirected links join concepts to every file where they introduce source and concepts to the tests they introduce; arrows show specialization between the displayed concepts and bridge only concepts omitted from this view. Concept colors match the source ranges below; connector concepts have no source color and are shown in gray.

Focused file, its introducer and connector concepts, their introduced files, and tests that run code from the file

In the embedded map, ordinary wheel input scrolls the page; use the visible controls to zoom and drag to pan. Open the full-screen map for canvas navigation: wheel pans, Ctrl/Command plus wheel zooms, and arrow keys pan when this region is focused. On touch screens, open the full-screen map to pan or pinch. If JavaScript or WebGL is unavailable, use the related-file, concept, and source links on this page.

Focused file, its introducer and connector concepts, their introduced files, and tests that run code from the filesrc/vs/platform/agentHost/common/codexSessionConfigKeys.ts · 114 LOCcommon/codexSessionConfi…src/vs/platform/agentHost/node/codex/codexAgent.ts · 4389 LOCcodex/codexAgent.tssrc/vs/platform/agentHost/node/codex/codexSessionMetadataStore.ts · 112 LOCcodex/codexSessionMetada…codexAgent.ts ×13 · 83 introduced LOCcodexAgent.ts ×13codexSessionConfigKeys.test|title=codexSessionConfigKeys resolveSessionConfig preserves legacy read-only permissions on restore|occurrence=1 · 0 introduced LOCcodexSessionConfigKeys.t…codexSessionConfigKeys.test|title=codexSessionConfigKeys resolveSessionConfig exposes a single permissions-preset chip|occurrence=1 · 0 introduced LOCcodexSessionConfigKeys.t…codexAgent.ts ×1 · 27 introduced LOCcodexAgent.ts ×1codexAgent.ts ×24 · 89 introduced LOCcodexAgent.ts ×24codexSessionConfigKeys.ts ×1 · 7 introduced LOCcodexSessionConfigKeys.t…codexSessionConfigKeys.ts ×1 · 2 introduced LOCcodexSessionConfigKeys.t…codexSessionConfigKeys.ts ×7 · 49 introduced LOCcodexSessionConfigKeys.t…codexSessionConfigKeys.ts ×1 · 11 introduced LOCcodexSessionConfigKeys.t…codexSessionConfigKeys.ts ×1 · 2 introduced LOCcodexSessionConfigKeys.t…codexSessionConfigKeys.ts ×2 · 4 introduced LOCcodexSessionConfigKeys.t…codexSessionConfigKeys.ts ×3 · 18 introduced LOCcodexSessionConfigKeys.t…codexSessionConfigKeys.ts ×3 · 19 introduced LOCcodexSessionConfigKeys.t…codexSessionConfigKeys.ts ×2 · 3 introduced LOCcodexSessionConfigKeys.t…codexSessionConfigKeys.ts ×2 · 2 introduced LOCcodexSessionConfigKeys.t…codexSessionConfigKeys.ts ×6 · 23 introduced LOCcodexSessionConfigKeys.t…codexAgent.ts ×1 · 2 introduced LOCcodexAgent.ts ×1codexAgent.ts ×1 · 2 introduced LOCcodexAgent.ts ×1codexAgent.ts ×3 · 7 introduced LOCcodexAgent.ts ×3codexAgent.ts ×1 · 2 introduced LOCcodexAgent.ts ×1codexAgent.ts ×1 · 2 introduced LOCcodexAgent.ts ×1codexAgent.ts ×1 · 2 introduced LOCcodexAgent.ts ×1codexAgent.ts ×1 · 10 introduced LOCcodexAgent.ts ×1codexAgent.ts ×8 · 19 introduced LOCcodexAgent.ts ×8codexAgent.ts ×158 · 1640 introduced LOCcodexAgent.ts ×158codexModelRefresh.test|title=CodexAgent model refresh keeps the last known-good models when a periodic refresh fails|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexModelRefresh.test|title=CodexAgent model refresh keeps the last known-good models when a periodic refresh fails|occurrence=1codexModelRefresh.test|t…codexPackagePaths.test|title=codex package paths codexBinaryTriple every suffix produced by codexPackageSuffix maps to a rust target triple|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexPackagePaths.test|title=codex package paths codexBinaryTriple every suffix produced by codexPackageSuffix maps to a rust target triple|occurrence=1codexPackagePaths.test|t…codexPackagePaths.test|title=codex package paths codexBinaryTriple returns undefined for unknown suffixes|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexPackagePaths.test|title=codex package paths codexBinaryTriple returns undefined for unknown suffixes|occurrence=1codexPackagePaths.test|t…codexPackagePaths.test|title=codex package paths codexPackageSuffix every supported (platform, arch) returns the npm optionalDependencies suffix|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexPackagePaths.test|title=codex package paths codexPackageSuffix every supported (platform, arch) returns the npm optionalDependencies suffix|occurrence=1codexPackagePaths.test|t…codexPackagePaths.test|title=codex package paths codexPackageSuffix never returns a -musl suffix on Linux (Codex is statically musl-linked)|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexPackagePaths.test|title=codex package paths codexPackageSuffix never returns a -musl suffix on Linux (Codex is statically musl-linked)|occurrence=1codexPackagePaths.test|t…codexPackagePaths.test|title=codex package paths codexPackageSuffix returns undefined for unsupported platforms and architectures|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexPackagePaths.test|title=codex package paths codexPackageSuffix returns undefined for unsupported platforms and architectures|occurrence=1codexPackagePaths.test|t…codex resolves|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexPackagePaths.test|title=codex package paths resolveCodexDevSdkRoot returns the directory containing node_modules when @openai/codex resolves|occurrence=1codex resolves|occurrenc…codexPackagePaths.test|title=codex package paths resolveCodexDevSdkRoot returns undefined when resolution throws (e.g. built product without the devDependency)|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexPackagePaths.test|title=codex package paths resolveCodexDevSdkRoot returns undefined when resolution throws (e.g. built product without the devDependency)|occurrence=1codexPackagePaths.test|t…codexSessionConfigKeys.test|title=codexSessionConfigKeys expands permissions presets and falls back to legacy axes|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexSessionConfigKeys.test|title=codexSessionConfigKeys expands permissions presets and falls back to legacy axes|occurrence=1codexSessionConfigKeys.t…codexSessionConfigKeys.test|title=codexSessionConfigKeys inverts presets and migrates legacy axes without escalating|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexSessionConfigKeys.test|title=codexSessionConfigKeys inverts presets and migrates legacy axes without escalating|occurrence=1codexSessionConfigKeys.t…codexSessionConfigKeys.test|title=codexSessionConfigKeys narrows valid values and rejects invalid values|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexSessionConfigKeys.test|title=codexSessionConfigKeys narrows valid values and rejects invalid values|occurrence=1codexSessionConfigKeys.t…codexSessionConfigKeys.test|title=codexSessionConfigKeys resolveSessionConfig exposes a single permissions-preset chip|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexSessionConfigKeys.test|title=codexSessionConfigKeys resolveSessionConfig exposes a single permissions-preset chip|occurrence=1codexSessionConfigKeys.t…codexSessionConfigKeys.test|title=codexSessionConfigKeys resolveSessionConfig preserves legacy read-only permissions on restore|occurrence=1 · introduced test · mocha:v1|namespace=vscode@05c208e9e28d8c1c723fa08f85e2b7a96092e8e5|file=vs/platform/agentHost/test/node/codex/codexSessionConfigKeys.test|title=codexSessionConfigKeys resolveSessionConfig preserves legacy read-only permissions on restore|occurrence=1codexSessionConfigKeys.t…Focused file · src/vs/platform/agentHost/node/codex/codexSessionConfigKeys.ts · 197 LOCcodex/codexSessionConfig…

Graph controls are ready.

Interactive rendering requires JavaScript and WebGL. Use the related-file, concept, and source links on this page while the interactive map is unavailable.

1 > /*--------------------------------------------------------------------------------------------- codexAgent.ts ×158
2 > * Copyright (c) Microsoft Corporation. All rights reserved.
3 > * Licensed under the MIT License. See License.txt in the project root for license information.
4 > *--------------------------------------------------------------------------------------------*/
5 >
6 > import type { ReasoningEffort } from './protocol/generated/ReasoningEffort.js';
7 > import type { ReasoningSummary } from './protocol/generated/ReasoningSummary.js';
8 > import type { Personality } from './protocol/generated/Personality.js';
9 > import type { WebSearchMode } from './protocol/generated/WebSearchMode.js';
10 > import type { ModeKind } from './protocol/generated/ModeKind.js';
11 > import type { SandboxMode } from './protocol/generated/v2/SandboxMode.js';
12 > import { CodexSessionConfigKey, CODEX_DEFAULT_PERMISSIONS_PRESET, narrowCodexPermissionsPreset, presetForResolvedPermissions, resolveCodexPermissionsPreset, type CodexApprovalPolicy, type ICodexResolvedPermissions } from '../../common/codexSessionConfigKeys.js';
13 >
14 > // Re-export the shared, protocol-free config-key surface so node callers can
15 > // keep importing everything from this module.
16 > export { CodexSessionConfigKey, resolveCodexPermissionsPreset, presetForResolvedPermissions, narrowCodexPermissionsPreset, CODEX_PERMISSIONS_PRESETS, CODEX_DEFAULT_PERMISSIONS_PRESET } from '../../common/codexSessionConfigKeys.js';
17 > export type { CodexApprovalPolicy, CodexPermissionsPreset, CodexSandboxMode, CodexApprovalsReviewer, ICodexResolvedPermissions } from '../../common/codexSessionConfigKeys.js';
18 >
19 > export function narrowApprovalPolicy(value: unknown): CodexApprovalPolicy | undefined {
20 > switch (value) { codexSessionConfigKeys.ts ×6
21 > case 'never':
22 > case 'on-request':
23 > case 'on-failure':
24 > case 'untrusted':
25 > return value; codexSessionConfigKeys.ts ×2
27 > return undefined; codexSessionConfigKeys.ts ×2
29 > }
31 > export function narrowSandboxMode(value: unknown): SandboxMode | undefined {
32 > switch (value) { codexSessionConfigKeys.ts ×6
33 > case 'read-only':
34 > case 'workspace-write':
35 > case 'danger-full-access':
36 > return value; codexSessionConfigKeys.ts ×2
38 > return undefined; codexSessionConfigKeys.ts ×2
40 > }
42 > /**
43 > * Resolve the Codex security axes (approval policy, sandbox, approvals
44 > * reviewer) for a session's stored config values.
45 > *
46 > * The user-facing {@link CodexSessionConfigKey.PermissionsPreset} is the source
47 > * of truth; when present it expands into all three axes. For backward
48 > * compatibility (older sessions / programmatic config) we fall back to the
49 > * individual {@link CodexSessionConfigKey.ApprovalPolicy} /
50 > * {@link CodexSessionConfigKey.SandboxMode} keys with a `user` reviewer.
51 > */
52 > export function resolveCodexPermissions(
53 > values: Record<string, unknown> | undefined, codexSessionConfigKeys.ts ×3
54 > defaults: { approvalPolicy: CodexApprovalPolicy; sandboxMode: SandboxMode },
55 > ): ICodexResolvedPermissions {
56 > const preset = narrowCodexPermissionsPreset(values?.[CodexSessionConfigKey.PermissionsPreset]);
57 > if (preset) {
58 > return resolveCodexPermissionsPreset(preset); codexSessionConfigKeys.ts ×1
59 > }
61 > approvalPolicy: narrowApprovalPolicy(values?.[CodexSessionConfigKey.ApprovalPolicy]) ?? defaults.approvalPolicy,
62 > sandboxMode: narrowSandboxMode(values?.[CodexSessionConfigKey.SandboxMode]) ?? defaults.sandboxMode,
63 > approvalsReviewer: 'user',
64 > };
65 > }
67 > /**
68 > * Decide how a restored session's three permission keys (`permissionsPreset`,
69 > * `approvalPolicy`, `sandboxMode`) should be represented, given its raw
70 > * persisted config values.
71 > *
72 > * This exists to prevent a silent privilege escalation on restore: a legacy
73 > * session that persisted only the individual axes (for example
74 > * `sandboxMode = 'read-only'`) and never chose a preset must not have a
75 > * materialized `permissionsPreset = 'default'` inserted on top of it, because
76 > * {@link resolveCodexPermissions} checks the preset first and would resume the
77 > * session as `workspace-write`.
78 > *
79 > * The returned object contains ONLY the permission keys that should be present
80 > * afterwards, so callers should drop all three permission keys before applying
81 > * it:
82 > * - an explicitly chosen preset is kept as-is;
83 > * - legacy axes that map exactly onto a preset are migrated to that preset
84 > * (single source of truth) and the raw axes dropped;
85 > * - legacy axes with a `workspace-write` or `danger-full-access` sandbox that
86 > * do NOT map exactly onto a preset are snapped to the preset whose sandbox
87 > * matches (`default` / `full-access`). This keeps the resolved axes in sync
88 > * with the preset the "Approvals" chip displays, so a legacy
89 > * `approvalPolicy = 'never'` + `workspace-write` session resolves to the
90 > * `default` preset's `on-request` policy (and actually prompts) instead of
91 > * silently running without approval while the chip claims "Default
92 > * Permissions". Snapping never grants more sandbox access than the legacy
93 > * value already had;
94 > * - legacy axes with a `read-only` sandbox (which no preset expands to, and
95 > * which is more locked-down than any preset) are preserved verbatim and no
96 > * preset is surfaced, so restore never silently escalates them to
97 > * `workspace-write`.
98 > */
99 > export function migrateCodexPermissionValues(
100 > config: Record<string, unknown> | undefined, codexSessionConfigKeys.ts ×3
101 > defaults: { approvalPolicy: CodexApprovalPolicy; sandboxMode: SandboxMode },
102 > ): Record<string, string> {
103 > const explicitPreset = narrowCodexPermissionsPreset(config?.[CodexSessionConfigKey.PermissionsPreset]);
104 > if (explicitPreset) {
105 > return { [CodexSessionConfigKey.PermissionsPreset]: explicitPreset }; codexSessionConfigKeys.ts ×1
106 > }
107 > const resolved = resolveCodexPermissions(config, defaults); codexSessionConfigKeys.ts ×3
108 > const equivalentPreset = presetForResolvedPermissions(resolved);
109 > if (equivalentPreset) {
110 > return { [CodexSessionConfigKey.PermissionsPreset]: equivalentPreset };
111 > }
112 > // `read-only` is more locked-down than any preset's sandbox and cannot be codexSessionConfigKeys.ts ×1
113 > // represented by one, so preserve the raw axes — surfacing a preset here
114 > // would silently escalate the session to `workspace-write` on restore.
115 > if (resolved.sandboxMode === 'read-only') {
116 > return {
117 > [CodexSessionConfigKey.ApprovalPolicy]: resolved.approvalPolicy,
118 > [CodexSessionConfigKey.SandboxMode]: resolved.sandboxMode,
119 > };
120 > }
121 > // Otherwise snap onto the preset whose sandbox matches so the displayed chip codexSessionConfigKeys.ts ×1
122 > // and the resolved axes stay consistent (`danger-full-access` → Full Access,
123 > // any other non-exact `workspace-write` combo → Default Permissions).
124 > return {
125 > [CodexSessionConfigKey.PermissionsPreset]: resolved.sandboxMode === 'danger-full-access'
126 > ? 'full-access'
127 > : CODEX_DEFAULT_PERMISSIONS_PRESET,
129 > }
131 > export function narrowAdditionalDirectories(value: unknown): readonly string[] | undefined {
132 > if (!Array.isArray(value)) { codexSessionConfigKeys.ts ×7
133 > return undefined;
134 > }
135 > return value.filter((entry): entry is string => typeof entry === 'string' && entry.length > 0);
136 > }
138 > export function narrowBoolean(value: unknown): boolean | undefined {
139 > return typeof value === 'boolean' ? value : undefined; codexSessionConfigKeys.ts ×7
140 > }
142 > export function narrowWebSearchMode(value: unknown): WebSearchMode | undefined {
143 > switch (value) { codexSessionConfigKeys.ts ×7
144 > case 'disabled':
145 > case 'cached':
146 > case 'live':
147 > return value;
148 > default:
149 > return undefined;
150 > }
151 > }
153 > export function narrowReasoningEffort(value: unknown): ReasoningEffort | undefined {
154 > switch (value) { codexSessionConfigKeys.ts ×7
155 > case 'none':
156 > case 'minimal':
157 > case 'low':
158 > case 'medium':
159 > case 'high':
160 > case 'xhigh':
161 > return value;
162 > default:
163 > return undefined;
164 > }
165 > }
167 > export function narrowPersonality(value: unknown): Personality | undefined {
168 > switch (value) { codexSessionConfigKeys.ts ×7
169 > case 'none':
170 > case 'friendly':
171 > case 'pragmatic':
172 > return value;
173 > default:
174 > return undefined;
175 > }
176 > }
178 > export function narrowReasoningSummary(value: unknown): ReasoningSummary | undefined {
179 > switch (value) { codexSessionConfigKeys.ts ×7
180 > case 'auto':
181 > case 'concise':
182 > case 'detailed':
183 > case 'none':
184 > return value;
185 > default:
186 > return undefined;
187 > }
188 > }
190 > /**
191 > * Map the platform-generic {@link SessionMode} (Agent Mode) to codex's native
192 > * collaboration {@link ModeKind}: VS Code "Plan" → codex `plan`, "Interactive"
193 > * → codex `default`.
194 > */
195 > export function collaborationModeKind(value: unknown): ModeKind {
196 > return value === 'plan' ? 'plan' : 'default'; codexSessionConfigKeys.ts ×7
197 > }