Skip to content

chat: Enforce managed plugin availability - #338795

Draft
Paul (pwang347) wants to merge 3 commits into
microsoft:mainfrom
pwang347:fix/8906-managed-plugin-enforcement
Draft

Paul (pwang347) wants to merge 3 commits into
microsoft:mainfrom
pwang347:fix/8906-managed-plugin-enforcement

Conversation

@pwang347

@pwang347 Paul (pwang347) commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

Addresses microsoft/vscode-internalbacklog#8906.

Runtime counterpart: github/copilot-agent-runtime#23862.
Repository activation counterpart: #338945 (independent).

Summary

  • Reconcile enterprise enabledPlugins: true entries through a managed activation service, restoring required plugins without persisting policy into the user's profile.
  • Install managed plugins without confirmation only when enterprise policy also trusts the exact marketplace source.
  • Reconcile managed plugins and refresh the Agent Host active-client snapshot before every turn-start dispatch, preventing chat messages from racing installation or discovery.
  • Preserve configured marketplace names while hydrating installed plugins so exact plugin@marketplace policy identities survive restarts.
  • Forward the effective managed plugin map to the local Agent Host and stamp client plugin customizations with their exact plugin@marketplace identity.
  • Add a provider-independent, fail-closed turn-admission contribution that rejects turns until every required plugin has loaded.
  • Compose multiple client contributions restrictively (false wins), preserve full marketplace identity, and document the managed-plugin lifecycle.

Testing

  • npm run typecheck-client — passed.
  • Targeted ESLint over all changed TypeScript files — passed.
  • ./scripts/test.sh --run src/vs/workbench/contrib/chat/test/browser/plugins/agentPluginActivationService.test.ts --run src/vs/workbench/contrib/chat/test/browser/plugins/pluginInstallService.test.ts --run src/vs/workbench/contrib/chat/test/common/plugins/agentPluginEnablement.test.ts --run src/vs/workbench/contrib/chat/test/browser/agentSessions/resolveCustomizationRefs.test.ts --run src/vs/workbench/contrib/chat/test/browser/agentSessions/agentHostClientTools.test.ts --run src/vs/platform/agentHost/test/node/chatContributions.test.ts — passed.
  • node test/scenario/out/runScenario.js .build/vscode-playwright-mcp/managed-plugin-enforcement-only.cjs --dev — 2/2 steps passed on Code OSS Dev 1.141.0, macOS arm64.

Evidence

annotated.mp4

Managed plugin installed and locked

The video uses an isolated empty plugin directory. It shows the managed plugin install without confirmation and an attempted toggle that leaves the plugin enabled and locked.

Paul (pwang347) and others added 2 commits September 29, 2026 15:39
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@pwang347
Paul (pwang347) force-pushed the fix/8906-managed-plugin-enforcement branch from 7720eb2 to f8701d6 Compare September 29, 2026 22:50
@pwang347
Paul (pwang347) changed the base branch from fix/336858-workspace-plugin-activation to main September 29, 2026 22:50
Copilot AI balanced review requested due to automatic review settings September 30, 2026 17:00
@pwang347 Paul (pwang347) changed the title chat: Enforce managed plugin availability chat: Enforce managed and repository plugin activation Sep 30, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Untrusted repositories can affect installed plugins, legacy clients lose permission enforcement, and managed false entries are not enforced by Agent Host.

Review effort: Balanced
Findings: 2 High severity · 1 Medium severity

Open (3)
What changed in this PR

Enforces managed and trusted-repository plugin activation across the workbench and local Agent Host.

Changes:

  • Adds automatic installation and scoped plugin enablement reconciliation.
  • Forwards managed plugin policy and adds turn-admission enforcement.
  • Preserves marketplace identities and expands coverage/documentation.
File Description
src/​vs/​workbench/​contrib/​mcp/​test/​common/​pluginMcpDiscovery.test.ts Updates plugin service stub.
src/​vs/​workbench/​contrib/​chat/​test/​common/​plugins/​pluginMarketplaceService.test.ts Tests marketplace-name hydration.
src/​vs/​workbench/​contrib/​chat/​test/​common/​plugins/​agentPluginEnablement.test.ts Tests policy/workspace precedence.
src/​vs/​workbench/​contrib/​chat/​test/​browser/​plugins/​pluginInstallService.test.ts Tests trust-prompt bypass.
src/​vs/​workbench/​contrib/​chat/​test/​browser/​plugins/​agentPluginActivationService.test.ts Tests plugin reconciliation.
src/​vs/​workbench/​contrib/​chat/​test/​browser/​agentSessions/​resolveCustomizationRefs.test.ts Tests workspace enablement publication.
src/​vs/​workbench/​contrib/​chat/​test/​browser/​agentSessions/​agentHostClientTools.test.ts Tests reconciliation ordering.
src/​vs/​workbench/​contrib/​chat/​common/​plugins/​pluginMarketplaceService.ts Preserves marketplace identities and policy trust.
src/​vs/​workbench/​contrib/​chat/​common/​plugins/​pluginInstallService.ts Adds installation trust options.
src/​vs/​workbench/​contrib/​chat/​common/​plugins/​AGENTS_PLUGINS.md Documents managed activation.
src/​vs/​workbench/​contrib/​chat/​common/​plugins/​agentPluginServiceImpl.ts Applies policy and workspace overlays.
src/​vs/​workbench/​contrib/​chat/​common/​plugins/​agentPluginService.ts Extends plugin service API.
src/​vs/​workbench/​contrib/​chat/​common/​plugins/​agentPluginEnablement.ts Implements configured enablement precedence.
src/​vs/​workbench/​contrib/​chat/​common/​plugins/​agentPluginActivationService.ts Defines activation service contract.
src/​vs/​workbench/​contrib/​chat/​browser/​pluginInstallService.ts Implements trust-prompt bypass.
src/​vs/​workbench/​contrib/​chat/​browser/​chat.shared.contribution.ts Registers activation components.
src/​vs/​workbench/​contrib/​chat/​browser/​agentSessions/​agentHost/​agentHostLocalCustomizations.ts Publishes identity and workspace metadata.
src/​vs/​workbench/​contrib/​chat/​browser/​agentSessions/​agentHost/​agentHostActiveClientService.ts Awaits plugin reconciliation.
src/​vs/​workbench/​contrib/​chat/​browser/​agentPluginActivationService.ts Reconciles required plugin installations.
src/​vs/​platform/​agentHost/​test/​node/​protocolServerHandler.test.ts Updates managed-settings protocol tests.
src/​vs/​platform/​agentHost/​test/​node/​copilotSessionLauncher.test.ts Updates managed-settings stub.
src/​vs/​platform/​agentHost/​test/​node/​copilotAgent.test.ts Uses unified client contributions.
src/​vs/​platform/​agentHost/​test/​node/​chatContributions.test.ts Tests managed plugin admission.
src/​vs/​platform/​agentHost/​test/​node/​agentSideEffects.test.ts Registers managed-settings service.
src/​vs/​platform/​agentHost/​test/​node/​agentHostTurnTelemetry.test.ts Updates telemetry test wiring.
src/​vs/​platform/​agentHost/​test/​node/​agentHostTurnHangTelemetry.test.ts Updates telemetry test wiring.
src/​vs/​platform/​agentHost/​test/​node/​agentHostToolCallTelemetry.test.ts Updates telemetry test wiring.
src/​vs/​platform/​agentHost/​test/​node/​agentHostManagedSettingsService.test.ts Tests restrictive contribution merging.
src/​vs/​platform/​agentHost/​test/​electron-browser/​agentHostProtocolClient.test.ts Tests policy forwarding.
src/​vs/​platform/​agentHost/​test/​common/​agentHostManagedSettings.test.ts Tests managed plugin parsing.
src/​vs/​platform/​agentHost/​node/​protocolServerHandler.ts Receives unified managed settings.
src/​vs/​platform/​agentHost/​node/​chatContributions/​managedPluginAdmission/​managedPluginAdmissionContribution.ts Adds required-plugin admission gate.
src/​vs/​platform/​agentHost/​node/​chatContributions/​builtInChatContributions.ts Registers admission contribution.
src/​vs/​platform/​agentHost/​node/​agentHostManagedSettingsService.ts Aggregates permissions and plugin policy.
src/​vs/​platform/​agentHost/​common/​meta/​clientPluginIdentityMeta.ts Defines validated plugin identity metadata.
src/​vs/​platform/​agentHost/​common/​agentHostManagedSettings.ts Defines and resolves managed plugin settings.
src/​vs/​platform/​agentHost/​browser/​agentHostProtocolClient.ts Forwards local managed plugin policy.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +31 to +33
const required = Object.entries(this._managedSettingsService.enabledPlugins)
.filter(([, enabled]) => enabled)
.map(([pluginId]) => pluginId);
const policy = enabledPluginsPolicy.read(reader);
const result = new Map<string, boolean>();
if (discoveredPlugins && policy) {
const workspaceEnabledPlugins = this._workspacePluginSettingsService.enabledPlugins.read(reader);
Comment on lines +517 to +522
const params = (msg as { params?: { permissions?: unknown; enabledPlugins?: unknown } }).params;
if (isManagedSettingsPermissions(params?.permissions) && isManagedPluginEnablement(params.enabledPlugins)) {
this._managedSettingsService.setClientContribution(this._managedSettingsContributionId(client.clientId), {
permissions: params.permissions,
enabledPlugins: params.enabledPlugins,
});
@pwang347 Paul (pwang347) changed the title chat: Enforce managed and repository plugin activation chat: Enforce managed plugin availability Sep 30, 2026
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@pwang347
Paul (pwang347) force-pushed the fix/8906-managed-plugin-enforcement branch from 67983d5 to edb264c Compare September 30, 2026 17:24

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants