Automatic managed-settings refresh breaks IDE MCP reload and disables /allow-all
Dieses Issue hat noch niemand übernommen.
- Vorherrschende Sprache
- Shell
- Sterne
- 11.2k
- Forks
- 1.9k
- Ø Merge
- 14 Std. 16 Min.
- Gemergte PRs (30 T.)
- 6
Beschreibung
Describe the bug
In a long-running Copilot CLI session connected to Visual Studio Code, an automatic managed-settings refresh can fail while reloading the dynamically contributed IDE MCP server:
Failed to enforce managed Computer Use policy: failed to reload Computer Use
plugin contributions for session '<redacted>':
MCP reload failed: mcpServers.ide.type: Invalid literal value
After this failure, the session enters a fail-closed permission state even though the resolved enterprise policy does not disable permission bypass. /allow-all and /yolo can no longer be enabled, and every tool call requires approval. Restarting Copilot CLI restores normal behavior.
This has occurred in multiple long-running sessions.
Affected version
GitHub Copilot CLI 1.0.84-6
The installed binary has since updated to 1.0.84-8; the failure has not yet been reproduced there.
Steps to reproduce the behavior
- Start Copilot CLI on Windows from a VS Code-integrated environment.
- Enable
/allow-allor/yolo. - Keep the session active until the automatic managed-settings refresh runs.
- Observe the IDE MCP graph reload fail with
mcpServers.ide.type: Invalid literal value. - Run
/allow-allor/yoloagain. - Observe that permission escalation is rejected and subsequent tool calls prompt individually.
- Restart Copilot CLI.
- Observe that permissions and MCP tools work normally again.
The failure may be timing-dependent. In the captured occurrence, it happened exactly one hour after the CLI process started.
Expected behavior
The periodic managed-settings refresh should accept the IDE-provided MCP transport configuration and preserve the existing MCP graph. If applying refreshed settings fails, a policy that explicitly allows bypass permissions should not be replaced by the restrictive "policy undetermined" state for the lifetime of the process.
Additional context
- OS: Microsoft Windows 10.0.26200, x64
- Shell: PowerShell 7.6.6
- IDE: Visual Studio Code
- No user-defined
mcpServersexisted in the CLIconfig.jsonorsettings.json. - The IDE bridge was registered through a Windows named pipe.
- Sanitized log sequence:
[managedSettings] effective policy resolved:
source=mdm, bypassDisabled=false, serverFetchFailed=false
[managedSettings] applied: no bypass restriction in force
mcp graph load: reload {"force":true}
[managedSettings] applied: bypass-permissions mode DISABLED
(fail-closed: policy could not be determined)
[managedSettings] self-fetch errored:
MCP reload failed: mcpServers.ide.type: Invalid literal value
Managed Computer Use plugin activation remains unreconciled {"attempts":3}
The public MCP configuration types are local/stdio and http/sse. This looks like a transient IDE bridge transport value (possibly the named-pipe transport) is being passed through generic MCP configuration validation during the forced reload.
Beitragsleitfaden
Erste Schritte
- Lies das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreib ins Issue, dass du es übernimmst — das erspart doppelte Arbeit.
- Forke das Repository und arbeite in einem Branch.
- Öffne einen Pull Request, der die Issue-Nummer nennt.
Rechercherichtung
Beginne damit, die automatische Aktualisierung der verwalteten Einstellungen und das erzwungene Neuladen des MCP-Graphen in der in Windows integrierten VS Code-CLI anhand der gemeldeten Sequenz mcpServers.ide.type: Invalid literal value nachzuverfolgen. Vergleiche das Verhalten zwischen den Versionen 1.0.84-6 und 1.0.84-8 und reproduziere es mit aktiviertem /allow-all oder /yolo. Als abgeschlossen gilt die Untersuchung, wenn die MCP-Konfiguration der IDE erfolgreich neu geladen wird und eine erlaubte Bypass-Richtlinie nicht durch den Fail-Closed-Zustand ersetzt wird.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Bewertung
- Tech-Stack
- powershell, shell, vscode
- Bereich
- cli, security, tooling
- Issue-Typ
- Bug
- Schwierigkeit
- 4/5
- Geschätzter Aufwand
- 3-5 Tage
- Aktivitätsstatus
- Aktiv
- Klarheit
- Größtenteils klar
- Anfängerfreundlichkeit
- 52/100