feat(app-server): enforce managed remote control disable (#27961)

## Why

Managed deployments need a reliable deny gate for remote control.
Persisted enablement and explicit startup requests currently remain able
to start the transport, while the removed `features.remote_control` key
is intentionally only a compatibility no-op.

This adds a dedicated requirement that administrators can use to force
remote control off without deleting the user's persisted preference.
Removing the requirement and restarting restores the prior choice.

## What Changed

- Added top-level `allow_remote_control` requirements parsing, sourced
layer precedence, debug output, and `configRequirements/read` exposure
as `allowRemoteControl`.
- Added a typed transport policy captured from the startup requirements
snapshot. Managed disable forces the initial state to disabled and
prevents enrollment, refresh, connection, and persisted-preference
mutation.
- Rejected every `remoteControl/*` RPC before parameter deserialization
with JSON-RPC `-32600` and `remote control is disabled by managed
requirements`.
- Preserved the existing disabled status notification and the previous
behavior when the requirement is `true` or omitted.
- Regenerated app-server protocol schemas and documented the new
requirement.

## Verification

- Confirmed all remote-control RPCs, including a malformed request,
return the managed-policy error while the initial status notification
remains `disabled`.
- Confirmed explicit ephemeral startup and persisted enablement make no
backend connection and leave the SQLite preference unchanged.
- Confirmed `allow_remote_control = true` does not enable or block
remote control and `configRequirements/read` returns
`allowRemoteControl: false` for the deny policy.

Related issue: N/A (managed-policy hardening).
This commit is contained in:
Anton Panasenko
2026-06-12 20:10:12 -07:00
committed by GitHub
Unverified
parent 5d7db08b61
commit b9dc3b7a8b
29 changed files with 691 additions and 38 deletions
@@ -364,6 +364,7 @@ fn map_requirements_toml_to_api(requirements: ConfigRequirementsToml) -> ConfigR
}),
allow_managed_hooks_only: requirements.allow_managed_hooks_only,
allow_appshots: requirements.allow_appshots,
allow_remote_control: requirements.allow_remote_control,
computer_use: requirements
.computer_use
.map(map_computer_use_requirements_to_api),
@@ -618,6 +619,16 @@ mod tests {
assert_eq!(mapped.hooks, None);
}
#[test]
fn requirements_api_includes_allow_remote_control() {
let mapped = map_requirements_toml_to_api(ConfigRequirementsToml {
allow_remote_control: Some(false),
..ConfigRequirementsToml::default()
});
assert_eq!(mapped.allow_remote_control, Some(false));
}
#[test]
fn requirements_api_includes_computer_use_requirements() {
let mapped = map_requirements_toml_to_api(ConfigRequirementsToml {
@@ -1,5 +1,6 @@
use crate::error_code::internal_error;
use crate::error_code::invalid_request;
use crate::transport::RemoteControlEnableError;
use crate::transport::RemoteControlHandle;
use crate::transport::RemoteControlUnavailable;
use codex_app_server_protocol::JSONRPCErrorError;
@@ -35,7 +36,7 @@ impl RemoteControlRequestProcessor {
) -> Result<RemoteControlEnableResponse, JSONRPCErrorError> {
let handle = self.handle()?;
let status = if ephemeral {
handle.enable_ephemeral().map_err(map_unavailable)?
handle.enable_ephemeral().map_err(map_enable_error)?
} else {
handle
.enable(app_server_client_name)
@@ -88,7 +89,8 @@ impl RemoteControlRequestProcessor {
params: RemoteControlPairingStatusParams,
) -> Result<RemoteControlPairingStatusResponse, JSONRPCErrorError> {
validate_pairing_status_params(&params)?;
self.handle()?
let handle = self.handle()?;
handle
.pairing_status(params)
.await
.map_err(map_pairing_start_error)
@@ -115,9 +117,21 @@ impl RemoteControlRequestProcessor {
}
fn handle(&self) -> Result<&RemoteControlHandle, JSONRPCErrorError> {
self.remote_control_handle
let handle = self
.remote_control_handle
.as_ref()
.ok_or_else(|| internal_error("remote control is unavailable for this app-server"))
.ok_or_else(|| internal_error("remote control is unavailable for this app-server"))?;
handle
.ensure_remote_control_allowed()
.map_err(|err| invalid_request(err.to_string()))?;
Ok(handle)
}
}
fn map_enable_error(err: RemoteControlEnableError) -> JSONRPCErrorError {
match err {
RemoteControlEnableError::Unavailable(err) => map_unavailable(err),
RemoteControlEnableError::DisabledByRequirements(err) => invalid_request(err.to_string()),
}
}
@@ -126,7 +140,10 @@ fn map_unavailable(err: RemoteControlUnavailable) -> JSONRPCErrorError {
}
fn map_update_error(err: io::Error) -> JSONRPCErrorError {
if err.kind() == io::ErrorKind::NotFound {
if matches!(
err.kind(),
io::ErrorKind::NotFound | io::ErrorKind::PermissionDenied
) {
invalid_request(err.to_string())
} else {
internal_error(err.to_string())