Skip to content

[ci] Use repo NuGet config for template smoke build - #12335

Merged
jonathanpeppers merged 3 commits into
mainfrom
jonathanpeppers-fix-smoke-restore-access
Aug 12, 2026
Merged

jonathanpeppers merged 3 commits into
mainfrom
jonathanpeppers-fix-smoke-restore-access

Conversation

@jonathanpeppers

@jonathanpeppers jonathanpeppers commented Aug 10, 2026 •

Copy link
Copy Markdown
Member

Why

Depends on #12336.

The Windows template smoke project is generated under $(Build.StagingDirectory), outside the repository NuGet.config hierarchy. Its implicit build restore therefore falls back to the agent's machine NuGet configuration and may access unapproved package feeds.

#12336 disables NuGet auditing pipeline-wide. This dependent change keeps the smoke build's restore on the repository's approved sources.

Changes

  • Pass RestoreConfigFile=$(System.DefaultWorkingDirectory)\NuGet.config to the template build.
  • Quote the template creation and build staging paths using Windows path syntax.

Validation

  • Parsed build-windows-steps.yaml successfully.

  • Ran git diff --check.

  • Verified the Windows create and build commands with generated project paths containing spaces.

  • Verified restore used only the repository NuGet.config feeds and binlogtool reported the expected RestoreConfigFile.

  • Useful description of why the change is necessary.

  • Links to issues fixed (depends on [ci] Prevent isolated NuGet access #12336; no GitHub issue).

  • Unit tests (not applicable to pipeline-only YAML; targeted validation listed above).

Copilot AI lite review requested due to automatic review settings August 10, 2026 16:56
@jonathanpeppers jonathanpeppers changed the title jonathanpeppers fix smoke restore access [ci] Use repo NuGet config for template smoke build Aug 10, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the Windows CI template smoke-build step to ensure restores use the repository-approved NuGet sources even when the generated project lives outside the repo’s NuGet.config hierarchy, avoiding reliance on the agent’s machine-level NuGet configuration.

Changes:

  • Passes -p:RestoreConfigFile=...NuGet.config to the template dotnet build to force repository NuGet source usage.
  • Quotes the staging-directory project path for the build invocation and switches to Windows-style path separators.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

Comment thread build-tools/automation/yaml-templates/build-windows-steps.yaml
@jonathanpeppers jonathanpeppers mentioned this pull request Aug 10, 2026
3 tasks done
@jonathanpeppers jonathanpeppers added the ready-to-review This PR is ready to review/merge, I think any CI failures are just flaky (ignorable). label Aug 10, 2026
@jonathanpeppers

Copy link
Copy Markdown
Member Author

@dalexsoto review

@dalexsoto dalexsoto left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the current changes. NuGet config propagation, quoting, working directories, approved-feed isolation, and public/internal pipeline parity look correct. No blocking issues found.

Base automatically changed from jonathanpeppers-fix-pipeline-nuget-access to main August 11, 2026 19:09
@jonathanpeppers
jonathanpeppers force-pushed the jonathanpeppers-fix-smoke-restore-access branch from 9c5d68a to 7ba9e2a Compare August 11, 2026 19:10

@dalexsoto dalexsoto left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The current head only updates the base; the workflow change remains identical to the previously approved revision, and the NuGet config propagation and Windows path quoting are still correct. No blocking issues found.

@jonathanpeppers

Copy link
Copy Markdown
Member Author

Test failure is unrelated.

jonathanpeppers and others added 3 commits August 11, 2026 16:49
PR #12334 disables NuGet auditing for the pipeline, so keep this layer focused on selecting the approved restore configuration for the out-of-repo smoke project.

Co-authored-by: Copilot App <[email protected]>

Copilot-Session: 65dd1c1b-3b71-437c-87d8-1a0efdb512e7
Keep the create and build steps consistent so the smoke test remains valid when the staging directory contains spaces.

Co-authored-by: Copilot App <[email protected]>

Copilot-Session: 65dd1c1b-3b71-437c-87d8-1a0efdb512e7
@jonathanpeppers
jonathanpeppers force-pushed the jonathanpeppers-fix-smoke-restore-access branch from 7ba9e2a to 744005d Compare August 11, 2026 21:49
@jonathanpeppers

Copy link
Copy Markdown
Member Author

@dalexsoto review

@dalexsoto dalexsoto left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-reviewed the current context. The workflow diff remains byte-identical to the approved revision, and the repository NuGet configuration and Windows path quoting remain correct. No blocking issues found.

@jonathanpeppers
jonathanpeppers merged commit 13727e6 into main Aug 12, 2026
44 checks passed
@jonathanpeppers
jonathanpeppers deleted the jonathanpeppers-fix-smoke-restore-access branch August 12, 2026 14:57
jonathanpeppers added a commit that referenced this pull request Aug 16, 2026
## Summary

Backports the remaining non-Maven/Gradle CFSClean fixes from `main` to `release/10.0.1xx`, with release-specific conflict resolution that preserves files removed or consolidated on the release branch.

Maven/Gradle backports #12199 (`466da4a84`) and #12368 (`adffb38fd`) are intentionally excluded because they are being handled separately.

## Original changes

- #12198 / `8df1e87799f175f4c3e227c20e7c616e63d5570f` — Use dotnet-public for CI package resolution
- #12336 / `7ace3137a4fa04f5c3c67cc71b32f7b61c339243` — Prevent isolated NuGet access
- #12338 / `c09c89aa1f2e984c9eb37a2368d3b459568aab65` — Keep `dotnet new` restores on approved feeds
- #12335 / `13727e665929d7fd7fd9a03b5709ff179fcc6a3b` — Use repo NuGet config for template smoke build
- #12367 / `d57b8c42f131bd346a3c809da269ba18552272be` — Fix CodeBehind NuGet config placement

Co-authored-by: Copilot App <[email protected]>
jonathanpeppers added a commit that referenced this pull request Aug 24, 2026
## Summary

- backport `1c4d41c09eec` so direct Maven mirroring fails when any requested coordinate produces no payloads
- update `external/Java.Interop` from `33992194b9373e9322244612c94ed9941b9bc2fd` to dotnet/java-interop#1498's single release backport commit `7c110bfad3ee0a87f303609426167722ccb4ba77`
- include the release-applicable Java.Interop Maven test and java-source-utils routing that could not be carried by the main-branch subtree patch
- seed the release JavaParser 3.18.0 dependency graph into `dotnet-public-maven` for anonymous CI resolution

## Backport mapping

| Main change | Release equivalent |
| --- | --- |
| `ce636392a229` / #11711, `3c62389651c2` / #12055, Android portions of `466da4a84dc2` / #12199, and `adffb38fd731` / #12368 | `659cd98e7fb9` / #12397 |
| `8df1e87799f1` / #12198, `7ace3137a4fa` / #12336, `c09c89aa1f2e` / #12338, `13727e665929` / #12335, and `d57b8c42f131` / #12367 | `352831edcba6` / #12396 |
| approved .NET tool feed portion of `fa00357649bb` / #11701 | `dc9a8524138e` / #12420 |
| `1c4d41c09eec` / #12412 | `24252012aaf6` in this PR |
| Java.Interop hardening plus release-applicable routing from `466da4a84dc2` | dotnet/java-interop#1498, pinned here at `7c110bfad3ee0a87f303609426167722ccb4ba77` |

The later Dependabot-only Google Maven exposure and unrelated Gradle/dependency version churn are intentionally excluded. The final Java.Interop pin supersedes the earlier hardening-only candidate without amending or force-pushing commits.

## Validation

- Java.Interop.Tools.Maven tests: 106 passed, 0 failed
- CI-mode `java-source-utils` `jar` build resolved through `dotnet-public-maven` and succeeded after the mirror helper seeded the full transitive graph
- `mirror-dependencies.ps1` parsed successfully with the PowerShell parser
- Java.Interop final SHA is exactly one commit on top of the release pin
- `git diff --check origin/release/10.0.1xx..HEAD`

Co-authored-by: Copilot App <[email protected]>
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 12, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

ready-to-review This PR is ready to review/merge, I think any CI failures are just flaky (ignorable).

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants