Commit Graph
42 Commits
Author SHA1 Message Date
Connor PeetandCopilot dc51f4a3ae chat: require confirmation for .mcp.json and .npmrc edits (#332639)
* chat: require confirmation for .mcp.json edits

Updates edit approval patterns so edits to `.mcp.json` require user confirmation in both edit execution paths.

- Adds `.mcp.json` to the standard chat edit confirmation patterns.
- Adds `.mcp.json` to the agent host edit confirmation patterns.
- Extends focused tests for both edit execution paths.

(Commit message generated by Copilot)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* agentHost: test .mcp.json path casing

Adds `.mcp.json` to the existing non-canonical casing coverage for protected edit paths.

(Commit message generated by Copilot)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* chat: always confirm .npmrc edits

Treat .npmrc files as non-overridable protected edit targets in both chat approval paths, with root and nested-path coverage.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-08-26 02:28:24 +00:00
Martin Aeschlimann 680caf21e4 warn when reading linked files (#331799)
* warn when reading symlinked files

* fix windows tests
2026-08-20 15:12:45 +00:00
Paul 4224780376 Update edit permissions (#327199) 2026-07-23 21:00:49 +00:00
Connor Peet 977a239c99 tools: correctly resolve symlinks in editFileToolUtils (#317411)
* tools: correctly resolve symlinks in editFileToolUtils

(Commit message generated by Copilot)

* fix Windows: don't realpath filesystem root in non-existent path walk
2026-05-19 16:49:32 -07:00
Alex Dima b42dd65964 refactor: encapsulate working directory logic in WorkingDirectory class
Introduce a WorkingDirectory class that encapsulates the "use explicit
working directory if set, otherwise fall back to workspace folders" logic.
This replaces the pattern of passing a raw workingDirectory URI alongside
IWorkspaceService throughout tools, prompts, and confirmation helpers.

- Extension side: WorkingDirectory in platform/workspace/common/ uses
  @IWorkspaceService DI injection
- VS Code core side: WorkingDirectory in chat/common/ wraps
  IWorkspaceContextService
- Refactored inputGlobToPattern, assertFileOkForTool,
  isFileExternalAndNeedsConfirmation, isDirExternalAndNeedsConfirmation,
  createEditConfirmation, and resolveToolUri to use WorkingDirectory
- Updated prompt components (WorkspaceFoldersHint,
  MultirootWorkspaceStructure) and tool implementations
  (findFiles, findTextInFiles, searchSubagent, fetchPage)
2026-05-09 16:15:51 +02:00
Alex Dima 27ecfb15cf Thread session workingDirectory through tools, prompts, and confirmations
In the agents window, each chat session has its own working directory
that may differ from the current workspace folders (which change when
switching between sessions). This caused tools to search the wrong
folder, show spurious 'Allow reading external files?' prompts, and
render incorrect workspace_info in the system prompt.

Core plumbing:
- Add workingDirectory to IToolInvocationContext, IToolInvocationPreparationContext,
  ILanguageModelToolConfirmationRef, and IChatAgentRequest
- Enrich tool invocation context from model.workingDirectory in invokeTool()
- Include workingDirectory in toolInvocationToken built in extHostTypeConverters
- Pass workingDirectory through LanguageModelToolInvocationOptions and
  LanguageModelToolInvocationPrepareOptions (proposed API)
- Revive workingDirectory URI in extHostLanguageModelTools

Tool fixes (when workingDirectory is set, use it exclusively):
- chatExternalPathConfirmation: auto-approve paths within workingDirectory
- isFileExternalAndNeedsConfirmation / isDirExternalAndNeedsConfirmation /
  assertFileOkForTool: treat workingDirectory as workspace-internal
- createEditConfirmation: use workingDirectory for edit trust checks
- All edit tools (create_file, replace_string, multi_replace, apply_patch,
  insert_edit, edit_notebook, create_directory): pass workingDirectory
- resolveToolUri: resolve relative paths against workingDirectory
- inputGlobToPattern: scope unscoped globs to workingDirectory
- file_search / grep_search: scope searches to workingDirectory
- semantic_search: prefer workingDirectory for cwd
- run_in_terminal: prefer workingDirectory for terminal cwd
- fetchPageTool: check workingDirectory for file URI trust
- readFileTool / listDirTool / viewImageTool: pass workingDirectory

Prompt fixes:
- WorkspaceFoldersHint: show workingDirectory instead of workspace folders
- AgentMultirootWorkspaceStructure: generate file tree from workingDirectory
2026-05-08 16:15:11 +02:00
Jah-yee 25c2fe34a7 fix: resolve NoChangeError tool name interpolation and typo
Use backticks for proper template literal interpolation of ${ToolName.ReadFile}.
Fix duplicate 'and and' → 'and'.
Import ToolName from registry so message stays in sync if tool name changes.

Addresses Copilot AI review feedback: keeps tool name in sync with registry.
2026-05-01 22:55:34 +08:00
Megan Rogge 21b99b6c8a Resolve parent directory when realpath fails with ENOENT in edit confirmation (#313252) 2026-04-29 16:04:41 +00:00
Don Jayamanne 3c2c6b88e9 Do not prompt for permissions when editing files in workspace folder (#4010) 2026-02-26 02:27:42 +00:00
Johannes Rieken 526c569f25 Enhance edit file tools with disallowed URI error handling and add corresponding tests (#3972) 2026-02-25 11:17:00 +00:00
Paul 8e01c02da6 protect (#3666) 2026-02-11 18:58:54 +00:00
Paul 360a54fa99 Add edit protection for hooks (#3471)
* protect

* protect
2026-02-06 06:31:35 +00:00
Rob Lourens 98e4934dfb Adopt forceConfirmationReason for preToolUse hook (#3500)
* Adopt forceConfirmationReason for preToolUse hook

* Tweak confirmation reason
2026-02-06 04:07:09 +00:00
Connor Peet 03b29b7830 tools: skip diff display when content is identical after trim (#3088)
Improves file edit confirmation notifications by skipping diff display
when the only difference between old and new content is whitespace. This
prevents showing overly large diffs (e.g., >2500 lines) when the actual
changes are minimal or non-existent, making it clearer to users what
changes the agent is making.

- Adds early return in formatDiffAsUnified when content is identical
  after trimming whitespace
- Displays a brief 'contents are identical' message instead of a large
  diff

Fixes https://github.com/microsoft/vscode/issues/288781

(Commit message generated by Copilot)
2026-01-22 23:16:09 +00:00
Connor Peetandbhavyaus ba56721dfa tools: add support for model-specific tool registration (#2857)
* tools: add support for model-specific tool registration

This PR goes with https://github.com/microsoft/vscode/pull/287666

This allows the registration of tools that are scoped to specific
language models. These tools can be registered at runtime with
definitions derived from e.g. the server.

I think we should adopt this and go away from the current
`alternativeDefinitions` pattern which we have used previously.

Example of having tools specific for GPT 4.1 vs 4o:

```ts
ToolRegistry.registerModelSpecificTool(
	{
		name: 'gpt41_get_time',
		inputSchema: {},
		description: 'Get the current date and time (4.1)',
		displayName: 'Get Time (GPT 4.1)',
		toolReferenceName: 'get_time',
		source: undefined,
		tags: [],
		models: [{ id: 'gpt-4.1' }],
	},
	class implements ICopilotTool<unknown> {
		invoke() {
			return new vscode.LanguageModelToolResult([new vscode.LanguageModelTextPart('Current year is 2041 (GPT 4.1)')]);
		}
	}
);

ToolRegistry.registerModelSpecificTool(
	{
		name: 'gpt4o_get_time',
		inputSchema: {},
		description: 'Get the current date and time (4o)',
		displayName: 'Get Time (GPT 4o)',
		toolReferenceName: 'get_time',
		source: undefined,
		tags: [],
		models: [{ id: 'gpt-4o' }],
	},
	class implements ICopilotTool<unknown> {
		invoke() {
			return new vscode.LanguageModelToolResult([new vscode.LanguageModelTextPart('Current year is 2040 (GPT 4o)')]);
		}
	}
);
```

* demo

* fix

* overrides

* add overridesTool

* fix inverted logic

* test fixes and back compat

* make memory tool model specific

* fix tests and contribute memory to the vscode toolset

* verison

* fix unit tests

* rm config

* fix missing askquestions

---------

Co-authored-by: bhavyaus <bhavyau@microsoft.com>
2026-01-22 18:34:05 +00:00
Johannes RiekenandCopilot 367dc5fdbf feat: enhance edit confirmation by adding allowed edit URIs (#2975)
* feat: enhance edit confirmation by adding allowed edit URIs

re https://github.com/microsoft/vscode/issues/274770

* Update src/extension/agents/copilotcli/node/permissionHelpers.ts

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
2026-01-19 17:08:10 +00:00
Don Jayamanne 0b364a7194 Update canExistingFileBeEdited to support notebooks (#2657) 2025-12-23 03:34:39 +00:00
Connor Peet e45d9b5036 edits: extend diff processing time (#2593)
Closes https://github.com/microsoft/vscode/issues/281407

Don't think there's much better can do here sadly.
2025-12-15 22:48:34 +00:00
Matt Bierner 3c8134184b Enable no-unexternalized-strings in repo (#2448)
Enables the same `no-unexternalized-strings` with have in `vscode` in this repo. This make sure we have a more consistent style across repos and when generating edits
2025-12-05 18:45:12 +00:00
Martin Aeschlimann 6aa25cd215 allow reading personal skills, refining other isExternalInstructionsFile checks (#2392)
* allow reading personal skills, refining other isExternalInstructionsFile checks

* fix tests
2025-12-04 17:26:24 +00:00
Connor Peet fa50ac819a edits: fix replace_string not editing emptying file (#2212)
Closes https://github.com/microsoft/vscode/issues/277850
2025-11-26 14:09:28 +00:00
Connor Peet e4b5974b1a edits: fix conflicting edits in multi-replace-string (#2016)
* edits: fix conflicting edits in multi-replace-string

- Minimize identical content in text edits to avoid potential conflicts in context
- Explicitly error any edits that still fail rather than garbling the file

Closes https://github.com/microsoft/vscode/issues/277154

* rm test.only

* fix whitespaces not being preserved in ws flex match
2025-11-15 00:51:53 +00:00
Connor Peet 4572f4ee80 edits: don't prompt every edit for a folder within a default-system path (#1982)
Closes https://github.com/microsoft/vscode/issues/276193
2025-11-13 17:41:09 +00:00
Don Jayamanne 30c867c483 Move formatUriForFileWidget into common (#1973) 2025-11-13 06:00:21 +00:00
Don Jayamanne e6a67133a7 Render links in file edit confirmation (#1970) 2025-11-13 01:23:01 +00:00
Connor PeetandConnor Peet edb94a30a7 Cherry-pick MSRC 102702+103197 (#1926)
* Merge pull request #5 from devdiv-microsoft/release/msrc/103197

edits: avoid windows/ntfs path workarounds in edit guards

* edits: check files_added in patch for edit guards (#4)

Co-authored-by: Connor Peet <connor@peet.io>

---------

Co-authored-by: Connor Peet <connor@xbox.com>
2025-11-11 19:11:34 +00:00
Connor Peet ad9116d2af edits: show diffs for files being approved during edits (#1905)
* edits: show diffs for files being approved during edits

Requires a PR in core as well to adopt this nicely.

* cleanup
2025-11-11 01:36:17 +00:00
Connor Peet 7b81eec536 edits: fix race condition that leading to clobbering paralle edits (#1724)
This fixes a race condition that can happen in LM results that contain
multiple edit tool calls. The emission and application of edits is
async, and so it is possible that an edit can be emitted and the next
edit generated before the first edit's changes are propagated to the
extension host's model.

This resolves the issue by keeping, updating, and reusing snapshotted
documents on each turn's prompt context.

cc @DonJayamanne for notebook stuff. This is a little shakier but it
seems to work (and I know NB prefers the separate notebook edit tool
anyway.)
2025-10-31 09:07:07 +00:00
Connor Peet ed514427f6 edits: add edit tool logging and small success analyzer tool (#1334) 2025-10-15 02:12:51 +00:00
Connor Peet 2e80ddb78f edits: normalize case for edits to sensitive files (#1324) 2025-10-14 17:34:15 +00:00
Connor Peet 0de0814ea2 edits: add Library to default restricted paths on macos (#1311) 2025-10-14 01:01:31 +00:00
Bryan Chen b8ec099f50 Hide editFile tool message (#1232) 2025-10-06 17:16:52 +00:00
Connor Peet bfc23c61b2 edits: handle eperm in file edit checks (#1217)
Closes https://github.com/microsoft/vscode-internalbacklog/issues/5824
2025-10-01 19:41:57 +00:00
Connor Peet 6a589c6311 edits: fix file corruption issue with replace_string tool (#1134)
The similarity matching in the replace_string tool incorrect was using
line numbers rather than string offsets (since inception!) which caused
file corruption issues. I initially thought it was only in the multi
edit tool, but it happens in all replace_string variants.

Closes https://github.com/microsoft/vscode/issues/265842
2025-09-24 17:35:33 +00:00
Connor Peet 205fe3b3b8 edits: fix allow editing of untitled files (#1025)
Part of https://github.com/microsoft/vscode-copilot/issues/18637
2025-09-11 19:57:29 +00:00
Connor Peet ee68e16493 edits: consider symlinks when guarding edits to files (#913)
Closes https://github.com/microsoft/vscode-internalbacklog/issues/5824
2025-09-05 17:19:05 +00:00
Connor Peet 6caaa6d696 edits: support relative globs in chat.tools.edits.autoApprove (#892)
Closes https://github.com/microsoft/vscode/issues/265042
2025-09-03 23:08:49 +00:00
Connor Peet 244ea515c9 edits: adjust confirmations for system files and outside the workspace (#890)
- Don't block edits to files outside the workspace, but allow them with
  confirmations.
- Always confirm on certain files (dotfiles/folders in the home
  directory and appdatas on Windows)
2025-09-03 20:53:58 +00:00
Connor Peet 3de6af5556 edits: implement file edit guards using standard confirmations (#646)
After talking to Kai, we decided that the rare case of sensitive files edits should just use our standard confirmation UI instead of adding more variances to the base chat experience.
2025-08-18 19:35:40 +00:00
83803f9192 tools: add multi-replace-string tool (#593)
* add multi edit tool

* comment out reminder

* comment out reminder

* fix multi_replace_string_in_file issue in intents

* add multi_replace_string_in_file related instructions

* add more instructions

* remove next tool prediction parsing

* remove next_tool_prediction from toolSchemaNormalizer.ts

* add initial user reminder

* add hasMultiReplaceString

* add hasMultiReplaceString

* add references to MultiReplaceStringTool

* Delete test_implementation.js

* Delete test_dummy_parameter.js

* Delete test_required_dummy.js

* Delete verify_implementation.js

* Delete src/extension/tools/test/common/addNextToolPredictionParameter.spec.ts

* Fix formatting of multi-replace string reminder

* tidy up and exp

* eng: refactor multi and single edit tools

---------

Co-authored-by: Yevhen Mohylevskyy <yevhenmohylevskyy@Yevhens-MacBook-Pro.local>
Co-authored-by: Ubuntu <yevhen@ubuntu22-vm.1kpbk2tnedsetibfv2d2keui5d.xx.internal.cloudapp.net>
Co-authored-by: yemohyleyemohyle <127880594+yemohyleyemohyle@users.noreply.github.com>
2025-08-13 23:39:09 +00:00
Connor Peet 582b0bf837 tools: improve string_replace and add healing (ft. Gemini) (#251)
* test implementation of gemini-inspired model based healing

* rationalize types in string replace tools

* cleanup and add telemetry for string_replace healing

* prompting improvements

* add failsafe for string-replace healing

* update snapshot
2025-07-15 19:31:23 +00:00
kieferrmandcopilot-swe-agent[bot] 333d9a4053 Hello Copilot
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
2025-06-27 11:35:20 +02:00