Automatic managed-settings refresh breaks IDE MCP reload and disables /allow-all
Mantenedores costumam responder em até 1 dia
Ninguém assumiu esta issue ainda.
Avaliação
- Dificuldade
- 4/5
- Tempo estimado
- 3-5 dias
- Facilidade para iniciantes
- 52/100
Direção de pesquisa
Comece rastreando a atualização automática de managed-settings e o recarregamento forçado do grafo MCP na CLI integrada ao VS Code para Windows, usando a sequência relatada mcpServers.ide.type: Invalid literal value. Compare o comportamento entre as versões 1.0.84-6 e 1.0.84-8 e reproduza-o com /allow-all ou /yolo habilitado. Considera-se concluído quando a configuração MCP da IDE for recarregada com sucesso e uma política de bypass permitida não for substituída pelo estado fail-closed.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
Describe the bug
In a long-running Copilot CLI session connected to Visual Studio Code, an automatic managed-settings refresh can fail while reloading the dynamically contributed IDE MCP server:
Failed to enforce managed Computer Use policy: failed to reload Computer Use
plugin contributions for session '<redacted>':
MCP reload failed: mcpServers.ide.type: Invalid literal value
After this failure, the session enters a fail-closed permission state even though the resolved enterprise policy does not disable permission bypass. /allow-all and /yolo can no longer be enabled, and every tool call requires approval. Restarting Copilot CLI restores normal behavior.
This has occurred in multiple long-running sessions.
Affected version
GitHub Copilot CLI 1.0.84-6
The installed binary has since updated to 1.0.84-8; the failure has not yet been reproduced there.
Steps to reproduce the behavior
- Start Copilot CLI on Windows from a VS Code-integrated environment.
- Enable
/allow-allor/yolo. - Keep the session active until the automatic managed-settings refresh runs.
- Observe the IDE MCP graph reload fail with
mcpServers.ide.type: Invalid literal value. - Run
/allow-allor/yoloagain. - Observe that permission escalation is rejected and subsequent tool calls prompt individually.
- Restart Copilot CLI.
- Observe that permissions and MCP tools work normally again.
The failure may be timing-dependent. In the captured occurrence, it happened exactly one hour after the CLI process started.
Expected behavior
The periodic managed-settings refresh should accept the IDE-provided MCP transport configuration and preserve the existing MCP graph. If applying refreshed settings fails, a policy that explicitly allows bypass permissions should not be replaced by the restrictive "policy undetermined" state for the lifetime of the process.
Additional context
- OS: Microsoft Windows 10.0.26200, x64
- Shell: PowerShell 7.6.6
- IDE: Visual Studio Code
- No user-defined
mcpServersexisted in the CLIconfig.jsonorsettings.json. - The IDE bridge was registered through a Windows named pipe.
- Sanitized log sequence:
[managedSettings] effective policy resolved:
source=mdm, bypassDisabled=false, serverFetchFailed=false
[managedSettings] applied: no bypass restriction in force
mcp graph load: reload {"force":true}
[managedSettings] applied: bypass-permissions mode DISABLED
(fail-closed: policy could not be determined)
[managedSettings] self-fetch errored:
MCP reload failed: mcpServers.ide.type: Invalid literal value
Managed Computer Use plugin activation remains unreconciled {"attempts":3}
The public MCP configuration types are local/stdio and http/sse. This looks like a transient IDE bridge transport value (possibly the named-pipe transport) is being passed through generic MCP configuration validation during the forced reload.
- Linguagem predominante
- Shell
- Estrelas
- 11.2k
- Forks
- 1.9k
- Merge médio
- 17h 6min
- PRs com merge (30d)
- 5
Preparar o ambiente
- Sem Dockerfile nem arquivo Docker Compose
- Sem modelo de pull request
- Ler o guia de contribuição
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de github/copilot-cli
-
area:sessions
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
github/copilot-cli#4996 ·
Mantenedores costumam responder em até 1 dia
-
triage
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 88/100
github/copilot-cli#4963 · 1 comentário ·
Mantenedores costumam responder em até 1 dia
-
triage
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 75/100
github/copilot-cli#4932 ·
Mantenedores costumam responder em até 1 dia
-
triage
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
github/copilot-cli#4909 ·
Mantenedores costumam responder em até 1 dia
-
triage
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 76/100
github/copilot-cli#4906 ·
Mantenedores costumam responder em até 1 dia
Todas as issues de github/copilot-cli
Issues semelhantes
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 88/100
opdev/vuln-scan-cert#38 ·
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 74/100
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 84/100
chainguard-dev/actions#1063 ·
Mantenedores costumam responder em até 1 dia
-
test_update_rollback_recovery: the no-change slice anchors on a comment, widening it to ~1800 linesAberta
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 90/100
WingedGuardian/GENesis-AGI#2719 ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 68/100
fedora-copr/copr#4532 · 2 comentários ·
Mantenedores costumam responder em até 3 dias