chat: Enforce managed plugin availability - #338795
Draft
Paul (pwang347) wants to merge 3 commits into
Draft
Paul (pwang347) wants to merge 3 commits into
Paul (pwang347) wants to merge 3 commits into
Conversation
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Paul (pwang347)
force-pushed
the
fix/8906-managed-plugin-enforcement
branch
from
September 29, 2026 22:50
7720eb2 to
f8701d6
Compare
Paul (pwang347)
changed the base branch from
fix/336858-workspace-plugin-activation
to
main
September 29, 2026 22:50
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Untrusted repositories can affect installed plugins, legacy clients lose permission enforcement, and managed false entries are not enforced by Agent Host.
Review effort: Balanced
Findings: 2
Open (3)
What changed in this PR
Enforces managed and trusted-repository plugin activation across the workbench and local Agent Host.
Changes:
- Adds automatic installation and scoped plugin enablement reconciliation.
- Forwards managed plugin policy and adds turn-admission enforcement.
- Preserves marketplace identities and expands coverage/documentation.
| File | Description |
|---|---|
src/vs/workbench/contrib/mcp/test/common/pluginMcpDiscovery.test.ts |
Updates plugin service stub. |
src/vs/workbench/contrib/chat/test/common/plugins/pluginMarketplaceService.test.ts |
Tests marketplace-name hydration. |
src/vs/workbench/contrib/chat/test/common/plugins/agentPluginEnablement.test.ts |
Tests policy/workspace precedence. |
src/vs/workbench/contrib/chat/test/browser/plugins/pluginInstallService.test.ts |
Tests trust-prompt bypass. |
src/vs/workbench/contrib/chat/test/browser/plugins/agentPluginActivationService.test.ts |
Tests plugin reconciliation. |
src/vs/workbench/contrib/chat/test/browser/agentSessions/resolveCustomizationRefs.test.ts |
Tests workspace enablement publication. |
src/vs/workbench/contrib/chat/test/browser/agentSessions/agentHostClientTools.test.ts |
Tests reconciliation ordering. |
src/vs/workbench/contrib/chat/common/plugins/pluginMarketplaceService.ts |
Preserves marketplace identities and policy trust. |
src/vs/workbench/contrib/chat/common/plugins/pluginInstallService.ts |
Adds installation trust options. |
src/vs/workbench/contrib/chat/common/plugins/AGENTS_PLUGINS.md |
Documents managed activation. |
src/vs/workbench/contrib/chat/common/plugins/agentPluginServiceImpl.ts |
Applies policy and workspace overlays. |
src/vs/workbench/contrib/chat/common/plugins/agentPluginService.ts |
Extends plugin service API. |
src/vs/workbench/contrib/chat/common/plugins/agentPluginEnablement.ts |
Implements configured enablement precedence. |
src/vs/workbench/contrib/chat/common/plugins/agentPluginActivationService.ts |
Defines activation service contract. |
src/vs/workbench/contrib/chat/browser/pluginInstallService.ts |
Implements trust-prompt bypass. |
src/vs/workbench/contrib/chat/browser/chat.shared.contribution.ts |
Registers activation components. |
src/vs/workbench/contrib/chat/browser/agentSessions/agentHost/agentHostLocalCustomizations.ts |
Publishes identity and workspace metadata. |
src/vs/workbench/contrib/chat/browser/agentSessions/agentHost/agentHostActiveClientService.ts |
Awaits plugin reconciliation. |
src/vs/workbench/contrib/chat/browser/agentPluginActivationService.ts |
Reconciles required plugin installations. |
src/vs/platform/agentHost/test/node/protocolServerHandler.test.ts |
Updates managed-settings protocol tests. |
src/vs/platform/agentHost/test/node/copilotSessionLauncher.test.ts |
Updates managed-settings stub. |
src/vs/platform/agentHost/test/node/copilotAgent.test.ts |
Uses unified client contributions. |
src/vs/platform/agentHost/test/node/chatContributions.test.ts |
Tests managed plugin admission. |
src/vs/platform/agentHost/test/node/agentSideEffects.test.ts |
Registers managed-settings service. |
src/vs/platform/agentHost/test/node/agentHostTurnTelemetry.test.ts |
Updates telemetry test wiring. |
src/vs/platform/agentHost/test/node/agentHostTurnHangTelemetry.test.ts |
Updates telemetry test wiring. |
src/vs/platform/agentHost/test/node/agentHostToolCallTelemetry.test.ts |
Updates telemetry test wiring. |
src/vs/platform/agentHost/test/node/agentHostManagedSettingsService.test.ts |
Tests restrictive contribution merging. |
src/vs/platform/agentHost/test/electron-browser/agentHostProtocolClient.test.ts |
Tests policy forwarding. |
src/vs/platform/agentHost/test/common/agentHostManagedSettings.test.ts |
Tests managed plugin parsing. |
src/vs/platform/agentHost/node/protocolServerHandler.ts |
Receives unified managed settings. |
src/vs/platform/agentHost/node/chatContributions/managedPluginAdmission/managedPluginAdmissionContribution.ts |
Adds required-plugin admission gate. |
src/vs/platform/agentHost/node/chatContributions/builtInChatContributions.ts |
Registers admission contribution. |
src/vs/platform/agentHost/node/agentHostManagedSettingsService.ts |
Aggregates permissions and plugin policy. |
src/vs/platform/agentHost/common/meta/clientPluginIdentityMeta.ts |
Defines validated plugin identity metadata. |
src/vs/platform/agentHost/common/agentHostManagedSettings.ts |
Defines and resolves managed plugin settings. |
src/vs/platform/agentHost/browser/agentHostProtocolClient.ts |
Forwards local managed plugin policy. |
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+31
to
+33
| const required = Object.entries(this._managedSettingsService.enabledPlugins) | ||
| .filter(([, enabled]) => enabled) | ||
| .map(([pluginId]) => pluginId); |
| const policy = enabledPluginsPolicy.read(reader); | ||
| const result = new Map<string, boolean>(); | ||
| if (discoveredPlugins && policy) { | ||
| const workspaceEnabledPlugins = this._workspacePluginSettingsService.enabledPlugins.read(reader); |
Comment on lines
+517
to
+522
| const params = (msg as { params?: { permissions?: unknown; enabledPlugins?: unknown } }).params; | ||
| if (isManagedSettingsPermissions(params?.permissions) && isManagedPluginEnablement(params.enabledPlugins)) { | ||
| this._managedSettingsService.setClientContribution(this._managedSettingsContributionId(client.clientId), { | ||
| permissions: params.permissions, | ||
| enabledPlugins: params.enabledPlugins, | ||
| }); |
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Paul (pwang347)
force-pushed
the
fix/8906-managed-plugin-enforcement
branch
from
September 30, 2026 17:24
67983d5 to
edb264c
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Addresses microsoft/vscode-internalbacklog#8906.
Runtime counterpart: github/copilot-agent-runtime#23862.
Repository activation counterpart: #338945 (independent).
Summary
enabledPlugins: trueentries through a managed activation service, restoring required plugins without persisting policy into the user's profile.plugin@marketplacepolicy identities survive restarts.plugin@marketplaceidentity.falsewins), preserve full marketplace identity, and document the managed-plugin lifecycle.Testing
npm run typecheck-client— passed../scripts/test.sh --run src/vs/workbench/contrib/chat/test/browser/plugins/agentPluginActivationService.test.ts --run src/vs/workbench/contrib/chat/test/browser/plugins/pluginInstallService.test.ts --run src/vs/workbench/contrib/chat/test/common/plugins/agentPluginEnablement.test.ts --run src/vs/workbench/contrib/chat/test/browser/agentSessions/resolveCustomizationRefs.test.ts --run src/vs/workbench/contrib/chat/test/browser/agentSessions/agentHostClientTools.test.ts --run src/vs/platform/agentHost/test/node/chatContributions.test.ts— passed.node test/scenario/out/runScenario.js .build/vscode-playwright-mcp/managed-plugin-enforcement-only.cjs --dev— 2/2 steps passed on Code OSS Dev 1.141.0, macOS arm64.Evidence
annotated.mp4
The video uses an isolated empty plugin directory. It shows the managed plugin install without confirmation and an attempted toggle that leaves the plugin enabled and locked.