Files
roblourensandCopilot 431af7bbe2 agentHost: native Mission Control environments (#339513)
* agentHost: checkpoint experimental Mission Control relay

Preserve the native-host registration and real WPS vertical slice before production hardening, including sealed authentication, request-form dispatch compatibility, heartbeat load shedding, tests, and the readiness checklist.

Development-only prototype; the documented security and lifecycle gaps remain release blockers.

(Written by Copilot)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* agentHost: harden Mission Control relay ingress

Fence relay authentication by owner and connection lifetime, protect host configuration, and authorize resources and native edit previews without changing local IPC behavior. Preserve existing clients while keeping deferred credential and release boundaries explicit.

(Written by Copilot)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* agentHost: checkpoint Mission Control lifecycle and discovery

Add generation-aware relay recovery, bounded keep-alive and token rotation, native user-local environment discovery, purpose-bound MCP sealing, and a bounded authoritative AHP mirror with signed retained backfill. Keep development gating and explicitly deferred URI and credential architecture boundaries.

(Written by Copilot)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* agentHost: complete Mission Control lifecycle and recovery parity

Bind registration withdrawal to its local account, refresh workspace grants safely, separate copied profile identities, and renew broker tickets before transport recovery. Preserve unchanged sealed credentials, retire permanently refused entries, and fence late refreshes. Surface passive connections as read-only and validate the native picker, MC catalog/history, and host restart flow without a test adapter.

(Written by Copilot)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Make native Agent Host session identities interoperable with AHP

Negotiate standard addressing for new allocations while preserving existing backend and frontend identities, explicit provider routing, and version-skew compatibility. Add regression coverage and contributor identity guardrails.

(Written by Copilot)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Fix remaining AHP identity consumers and CI regressions

Require connection-based committed session resolution, preserve exact owner deletion resources, route Copilot MCP replay explicitly, and keep cloud discovery/provisioning backend identity consistent. Add a public turn-tracker interface and repair CI fixture and class-field initialization wiring.

Validated 555 Chromium tests, 171 MCP/history/telemetry tests, and 29 native identity tests; both client and define-class-fields type checks, transpilation, lint and diff checks passed. (Written by Copilot)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Wire committed identity resolution in generic config chip tests

Update the provisional-generation fixture for the required connections contract. All 24 generic-config/submit-handler Chromium tests pass. (Written by Copilot)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Register eager Agent Host session identity before first send

Record each acknowledged allocation on its owning connection before subscriptions and first-send routing, and verify the host preserves the requested URI. Keep native allocation collision checks scoped away from non-native providers. Preserve historical recovery fixture addressing and use explicit Copilot provider IDs in MCP expectations.

Validated all 2096 affected unit tests (27 pending), all 3 local AgentHost and SDK-sandbox smoke scenarios, client and class-field type checks, transpilation and lint. (Written by Copilot)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* agentHost: mirror native session metadata to Mission Control

Publish selected genuine SDK events, synchronize native titles, and reconcile journal metadata with bounded independent SDK credit and acknowledgement-owned cursors.

(Written by Copilot)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Validate Agent Host identities before allocating disposable adapters

Reject conflicting backend registration before constructing adapters, preventing orphaned instances on refresh retry. Interpret older cloud-sandbox cached UI addresses only in the sandbox cache path, preserving generic/native advertised resources.

Reproduced five leaked adapters before the fix; 571 provider tests pass afterward. Live Code OSS with isolated cached state completed five session refreshes and ten forced GCs with zero leaked-disposable warnings or identity conflicts. Typecheck and lint pass. (Written by Copilot)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* agentHost: preserve backend session identities across clients

Keep advertised and persisted URI schemes intact in link, remote routing, session adapter and editor catalog paths. Apply the experimental native scheme only when constructing new local sessions, and retain provider attribution and automation identity. Package the relay crypto dependency for the remote server and use the uniform crypto randomInt API for connection generations.

(Written by Copilot)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* agentHost: retain host session schemes during remote chat routing

Preserve the scheme from existing remote metadata during subscription setup and use the explicitly configured remote backend scheme when opening a chat. This prevents Dev Container sessions from being readdressed through the experimental native alias. Cover legacy, AHP and custom backend schemes through the handler boundary.

(Written by Copilot)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Protect explicit session ownership and cold backing teardown

Serialize explicit creation by raw storage identity, preserve same-provider retries and legacy provenance, and prevent competing legacy/standard claims. Resolve persisted provider ownership before deletion and prepare all cold backings before destructive disposal, preserving metadata on unavailable-provider or preparation failures.

Added controlled contention and fresh-service cold-deletion regressions for all native providers, individual peer/default preparation failures and unresolved legacy identities. Full affected suites: 2290 passed, 27 pending; actual local AgentHost/SDK-sandbox smoke: 3 passed. Both typecheck modes, transpile and lint passed. (Written by Copilot)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* agentHost: reject non-directory relay path ancestors

Validate the resolved ancestor before granting a nonexistent path, since Windows can report ENOENT for a child of a regular file where POSIX reports ENOTDIR. Deny both cases consistently and cover filesystem writes as well as working-directory changes.

(Written by Copilot)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* agentHost: stabilize Mission Control naming and relay integration

Refresh the host-owned name on heartbeats, fence WPS root-setting forwarding, consume advertised execution-platform metadata, and omit unavailable relay extension capabilities. Validated with isolated live MC owner/viewer hosts and 547 focused tests.

(Written by Copilot)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* agentHost: enable opt-in Mission Control in built desktop products

Use product display names and ordinary management/lifecycle names, move the implementation under node/missionControl, and isolate native DI wiring in an entry-owned adapter. Preserve current settings and security boundaries. Document requirement coverage and only remaining gaps.

(Written by Copilot)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* agentHost: surface Mission Control relay disconnect diagnostics

Normalize the OSS environment name and retain only outstanding deployment qualification gaps. Socket close codes and network errors are reported once without logging untrusted close reasons. (Written by Copilot)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* agentHost: align merged fixtures with transport and identity contracts (Written by Copilot)

Expect no reply after transport teardown and advertise exact backend/provider identities instead of deriving restored sessions from allocation defaults.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* agentHost: harden Mission Control relay recovery and publication (Written by Copilot)

Isolate native diagnostic logs, backpressure the ordered mirror publisher, bound unanswered AHP handshakes, and recover transient identity-validation faults. Preserve legacy read-state upgrade regressions and move the current Mission Control documentation beside its implementation.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* docs: clarify and renumber Mission Control security requirements (Written by Copilot)

Name wire requirements as protocol specifications, number all35 requirements in reading order and update cross-references. Pin source/test links to the implemented revision and refresh local-validation and remaining-qualification evidence.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* docs: organize Mission Control requirements by security topic (Written by Copilot)

Replace misleading invariant-based parent headings with neutral topic groups, clarify requirement sources and upstream-versus-VSCode behavior, preserve35requirements and their links, and remove redundant status and qualification-history sections.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-10-05 16:06:27 -07:00
..
2026-09-17 22:18:25 +00:00
2026-09-22 02:58:34 +00:00