Automatic managed-settings refresh breaks IDE MCP reload and disables /allow-all
Personne n'a encore pris cette issue.
- Langage dominant
- Shell
- Étoiles
- 11.2k
- Forks
- 1.9k
- Merge moyen
- 14 h 16 min
- PR mergées (30 j)
- 6
Description
Describe the bug
In a long-running Copilot CLI session connected to Visual Studio Code, an automatic managed-settings refresh can fail while reloading the dynamically contributed IDE MCP server:
Failed to enforce managed Computer Use policy: failed to reload Computer Use
plugin contributions for session '<redacted>':
MCP reload failed: mcpServers.ide.type: Invalid literal value
After this failure, the session enters a fail-closed permission state even though the resolved enterprise policy does not disable permission bypass. /allow-all and /yolo can no longer be enabled, and every tool call requires approval. Restarting Copilot CLI restores normal behavior.
This has occurred in multiple long-running sessions.
Affected version
GitHub Copilot CLI 1.0.84-6
The installed binary has since updated to 1.0.84-8; the failure has not yet been reproduced there.
Steps to reproduce the behavior
- Start Copilot CLI on Windows from a VS Code-integrated environment.
- Enable
/allow-allor/yolo. - Keep the session active until the automatic managed-settings refresh runs.
- Observe the IDE MCP graph reload fail with
mcpServers.ide.type: Invalid literal value. - Run
/allow-allor/yoloagain. - Observe that permission escalation is rejected and subsequent tool calls prompt individually.
- Restart Copilot CLI.
- Observe that permissions and MCP tools work normally again.
The failure may be timing-dependent. In the captured occurrence, it happened exactly one hour after the CLI process started.
Expected behavior
The periodic managed-settings refresh should accept the IDE-provided MCP transport configuration and preserve the existing MCP graph. If applying refreshed settings fails, a policy that explicitly allows bypass permissions should not be replaced by the restrictive "policy undetermined" state for the lifetime of the process.
Additional context
- OS: Microsoft Windows 10.0.26200, x64
- Shell: PowerShell 7.6.6
- IDE: Visual Studio Code
- No user-defined
mcpServersexisted in the CLIconfig.jsonorsettings.json. - The IDE bridge was registered through a Windows named pipe.
- Sanitized log sequence:
[managedSettings] effective policy resolved:
source=mdm, bypassDisabled=false, serverFetchFailed=false
[managedSettings] applied: no bypass restriction in force
mcp graph load: reload {"force":true}
[managedSettings] applied: bypass-permissions mode DISABLED
(fail-closed: policy could not be determined)
[managedSettings] self-fetch errored:
MCP reload failed: mcpServers.ide.type: Invalid literal value
Managed Computer Use plugin activation remains unreconciled {"attempts":3}
The public MCP configuration types are local/stdio and http/sse. This looks like a transient IDE bridge transport value (possibly the named-pipe transport) is being passed through generic MCP configuration validation during the forced reload.
Guide de contribution
Ouvrir le guide de contribution
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Piste de recherche
Commencez par retracer l’actualisation automatique des managed-settings et le rechargement forcé du graphe MCP dans la CLI intégrée à VS Code sous Windows, en utilisant la séquence signalée mcpServers.ide.type: Invalid literal value. Comparez le comportement entre les versions 1.0.84-6 et 1.0.84-8 et reproduisez-le avec /allow-all ou /yolo activé. Le travail est considéré comme terminé lorsque la configuration MCP de l’IDE se recharge correctement et qu’une policy de bypass autorisée n’est pas remplacée par l’état fail-closed.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Évaluation
- Stack technique
- powershell, shell, vscode
- Domaine
- cli, security, tooling
- Type d'issue
- Bug
- Difficulté
- 4/5
- Temps estimé
- 3-5 jours
- Activité
- Active
- Clarté
- Plutôt claire
- Accessibilité débutants
- 52/100