Skip to content

Adding policy config to forceFirstExecutionInSandbox setting - #322462

Draft
dileepyavan wants to merge 5 commits into
mainfrom
DileepY/forceFirstExecutionInSandbox
Draft

Adding policy config to forceFirstExecutionInSandbox setting#322462
dileepyavan wants to merge 5 commits into
mainfrom
DileepY/forceFirstExecutionInSandbox

Conversation

@dileepyavan

Copy link
Copy Markdown
Member

fixes #321647

Copilot AI review requested due to automatic review settings June 22, 2026 21:41
@vs-code-engineering

Copy link
Copy Markdown
Contributor

📬 CODENOTIFY

The following users are being notified based on files changed in this PR:

@anthonykim1

Matched files:

  • src/vs/workbench/contrib/terminalContrib/chatAgentTools/common/terminalChatAgentToolsConfiguration.ts

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR adds an enterprise policy definition for the existing chat.agent.sandbox.forceFirstExecutionInSandbox setting so administrators can centrally manage it as part of the terminal chat/agent sandbox configuration.

Changes:

  • Registers a new policy block for AgentSandboxForceFirstExecutionInSandbox.
  • Minor formatting/escaping adjustments in the configuration schema file (array bracket alignment; escaping markdown backticks in localized strings).
Show a summary per file
File Description
src/vs/workbench/contrib/terminalContrib/chatAgentTools/common/terminalChatAgentToolsConfiguration.ts Adds a policy definition for forceFirstExecutionInSandbox and includes small formatting/string escaping tweaks.

Copilot's findings

  • Files reviewed: 1/1 changed files
  • Comments generated: 2

Comment on lines +611 to +621
policy: {
name: 'ChatAgentSandboxForceFirstExecutionInSandbox',
category: PolicyCategory.IntegratedTerminal,
minimumVersion: '1.126',
localization: {
description: {
key: 'agentSandbox.forceFirstExecutionInSandbox',
value: localize('agentSandbox.forceFirstExecutionInSandbox', "Controls whether agent mode terminal commands first run with the sandbox's configured restrictions before honoring a request for execution outside the sandbox or unrestricted network access. The user is prompted to approve the requested additional access only if that sandboxed command fails. This applies only when {0} is enabled.", `\`#${AgentSandboxSettingId.AgentSandboxEnabled}#\``),
}
}
}
@dileepyavan
dileepyavan marked this pull request as draft June 22, 2026 21:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add a setting forceFirstExecutionInSandbox

2 participants