Skip to content

[tests] Keep XASdk restores on approved feeds - #12338

Merged
jonathanpeppers merged 3 commits into
mainfrom
jonathanpeppers-fix-xasdk-network-access
Aug 11, 2026
Merged

jonathanpeppers merged 3 commits into
mainfrom
jonathanpeppers-fix-xasdk-network-access

Conversation

@jonathanpeppers

@jonathanpeppers jonathanpeppers commented Aug 10, 2026 •

Copy link
Copy Markdown
Member

Changes

  • declare the standard skipRestore symbol in every Android project template
  • map skipRestore to the user-facing --no-restore option through each template's dotnetcli.host.json
  • prevent XASdkTests.DotNetNew from restoring generated projects implicitly
  • copy the repository NuGet.config into generated projects before builds restore
  • route AndroidMavenLibrary items with blank repository metadata through dotnet-public-maven in test scope

Why templates declare skipRestore

--no-restore is presented as a standard dotnet new option, but project templates must opt into accepting it by declaring a skipRestore boolean symbol and mapping that symbol to --no-restore in dotnetcli.host.json. This follows the symbol/mapping convention used by the .NET SDK and .NET MAUI templates.

The Android templates intentionally do not add a restore post-action. They therefore preserve their existing default behavior and avoid restoring before test call sites configure approved package versions and feeds. The new option lets XASdkTests explicitly document and enforce that expectation before copying the repository NuGet.config into generated projects.

Validation

  • packed and installed Microsoft.Android.Templates

  • verified all five project templates create without producing obj/project.assets.json or reporting a restore by default

  • passed XASdkTests.DotNetNew for android, androidlib, android-bindinglib, and androidwear

  • verified the wear binlog contains no api.nuget.org or repo1.maven.org references

  • Useful description of why the change is necessary

  • Links to issues fixed

  • Unit tests

Copilot AI lite review requested due to automatic review settings August 10, 2026 17:23

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR adjusts the XASdk template tests so that restores/builds for generated dotnet new projects are constrained to the repository-approved NuGet/Maven feeds, avoiding unintended network access to public endpoints during test runs.

Changes:

  • Adds --no-restore support to DotNetCLI.New() and uses it for the initial template project generation.
  • Copies the repo NuGet.config into the generated project directory before restore/build.
  • Adds a test-scope MSBuild targets file that rewrites blank AndroidMavenLibrary.Repository metadata to use the dotnet-public-maven feed (used by the androidwear template).

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 2 comments.

File Description
src/Xamarin.Android.Build.Tasks/Tests/Xamarin.ProjectTools/Common/DotNetCLI.cs Adds optional --no-restore support for dotnet new in test infrastructure.
src/Xamarin.Android.Build.Tasks/Tests/Xamarin.Android.Build.Tests/XASdkTests.cs Updates DotNetNew test flow to avoid implicit restores and to enforce repo feed configuration; routes wear builds through a test-scope targets hook.
src/Xamarin.Android.Build.Tasks/Tests/Xamarin.Android.Build.Tests/dotnet-public-maven.targets Introduces a test-only MSBuild hook to set the Maven repository URL when item metadata is blank.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

Prevent template creation from restoring implicitly, copy the repository NuGet.config into generated projects, and route blank AndroidMavenLibrary repositories through dotnet-public-maven in test scope.

Co-authored-by: Copilot App <[email protected]>
@jonathanpeppers
jonathanpeppers force-pushed the jonathanpeppers-fix-xasdk-network-access branch from 2dcfc15 to da6867a Compare August 10, 2026 17:34
@jonathanpeppers jonathanpeppers added ready-to-review This PR is ready to review/merge, I think any CI failures are just flaky (ignorable). and removed ready-to-review This PR is ready to review/merge, I think any CI failures are just flaky (ignorable). labels Aug 10, 2026
Declare the standard skipRestore symbol and restore post-action in every Android project template, and map it to the dotnet CLI --no-restore option.

Co-authored-by: Copilot App <[email protected]>

Copilot-Session: eaf73cba-70d1-47cb-9854-fa4c537c5700
@jonathanpeppers jonathanpeppers added the ready-to-review This PR is ready to review/merge, I think any CI failures are just flaky (ignorable). label Aug 11, 2026
@jonathanpeppers

Copy link
Copy Markdown
Member Author

@dalexsoto review

@dalexsoto dalexsoto left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Blocking on the new default template restore. It also affects DotNetNewAndroidTest, which invokes the template before its approved nightly package version and feed configuration are applied; its output is outside the checkout, so the repository NuGet.config is not guaranteed to govern that restore. Please preserve the previous no-restore behavior, or suppress restore and explicitly install an approved config at every affected call site.

Keep the skipRestore CLI option without adding restore post-actions, so existing template call sites do not restore before configuring approved feeds.

Co-authored-by: Copilot App <[email protected]>

Copilot-Session: eaf73cba-70d1-47cb-9854-fa4c537c5700
@jonathanpeppers

Copy link
Copy Markdown
Member Author

Addressed review 4908596729 in a60f9b8: removed the newly added restore post-actions from all five project templates while retaining the skipRestore/--no-restore mapping. Verified every template still creates without restoring by default and the focused XASdkTests.DotNetNew matrix passes.

@dalexsoto dalexsoto left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-reviewed the current changes. The follow-up removes restore post-actions from all five templates, preserving the previous default no-restore behavior and fixing the DotNetNewAndroidTest timing path. XASdk still installs the repository NuGet configuration before building and routes blank Maven repositories through the approved feed. No blocking issues found.

@jonathanpeppers

Copy link
Copy Markdown
Member Author

Merging, failures are unrelated, being fixed:

       (Restore target) -> 
         /Users/cloudtest/vss/_work/1/a/TestRelease/08-11_18.11.32/temp/DotNetBuildandroid-arm64FalseFalseTrueCoreCLR/Test Me.csproj : error NU1605: Warning As Error: Detected package downgrade: Microsoft.JSInterop from 9.0.0 to 8.0.29. Reference the package directly from the project to select a different version. 
       /Users/cloudtest/vss/_work/1/a/TestRelease/08-11_18.11.32/temp/DotNetBuildandroid-arm64FalseFalseTrueCoreCLR/Test Me.csproj : error NU1605:  Test Me -> Microsoft.AspNetCore.Components.WebView 8.0.30 -> Microsoft.AspNetCore.Components.Web 9.0.0 -> Microsoft.JSInterop (>= 9.0.0) 
       /Users/cloudtest/vss/_work/1/a/TestRelease/08-11_18.11.32/temp/DotNetBuildandroid-arm64FalseFalseTrueCoreCLR/Test Me.csproj : error NU1605:  Test Me -> Microsoft.JSInterop (>= 8.0.0)

    1 Warning(s)
    1 Error(s)

@jonathanpeppers
jonathanpeppers merged commit c09c89a into main Aug 11, 2026
40 of 44 checks passed
@jonathanpeppers
jonathanpeppers deleted the jonathanpeppers-fix-xasdk-network-access branch August 11, 2026 20:40
jonathanpeppers added a commit that referenced this pull request Aug 16, 2026
## Summary

Backports the remaining non-Maven/Gradle CFSClean fixes from `main` to `release/10.0.1xx`, with release-specific conflict resolution that preserves files removed or consolidated on the release branch.

Maven/Gradle backports #12199 (`466da4a84`) and #12368 (`adffb38fd`) are intentionally excluded because they are being handled separately.

## Original changes

- #12198 / `8df1e87799f175f4c3e227c20e7c616e63d5570f` — Use dotnet-public for CI package resolution
- #12336 / `7ace3137a4fa04f5c3c67cc71b32f7b61c339243` — Prevent isolated NuGet access
- #12338 / `c09c89aa1f2e984c9eb37a2368d3b459568aab65` — Keep `dotnet new` restores on approved feeds
- #12335 / `13727e665929d7fd7fd9a03b5709ff179fcc6a3b` — Use repo NuGet config for template smoke build
- #12367 / `d57b8c42f131bd346a3c809da269ba18552272be` — Fix CodeBehind NuGet config placement

Co-authored-by: Copilot App <[email protected]>
jonathanpeppers added a commit that referenced this pull request Aug 24, 2026
## Summary

- backport `1c4d41c09eec` so direct Maven mirroring fails when any requested coordinate produces no payloads
- update `external/Java.Interop` from `33992194b9373e9322244612c94ed9941b9bc2fd` to dotnet/java-interop#1498's single release backport commit `7c110bfad3ee0a87f303609426167722ccb4ba77`
- include the release-applicable Java.Interop Maven test and java-source-utils routing that could not be carried by the main-branch subtree patch
- seed the release JavaParser 3.18.0 dependency graph into `dotnet-public-maven` for anonymous CI resolution

## Backport mapping

| Main change | Release equivalent |
| --- | --- |
| `ce636392a229` / #11711, `3c62389651c2` / #12055, Android portions of `466da4a84dc2` / #12199, and `adffb38fd731` / #12368 | `659cd98e7fb9` / #12397 |
| `8df1e87799f1` / #12198, `7ace3137a4fa` / #12336, `c09c89aa1f2e` / #12338, `13727e665929` / #12335, and `d57b8c42f131` / #12367 | `352831edcba6` / #12396 |
| approved .NET tool feed portion of `fa00357649bb` / #11701 | `dc9a8524138e` / #12420 |
| `1c4d41c09eec` / #12412 | `24252012aaf6` in this PR |
| Java.Interop hardening plus release-applicable routing from `466da4a84dc2` | dotnet/java-interop#1498, pinned here at `7c110bfad3ee0a87f303609426167722ccb4ba77` |

The later Dependabot-only Google Maven exposure and unrelated Gradle/dependency version churn are intentionally excluded. The final Java.Interop pin supersedes the earlier hardening-only candidate without amending or force-pushing commits.

## Validation

- Java.Interop.Tools.Maven tests: 106 passed, 0 failed
- CI-mode `java-source-utils` `jar` build resolved through `dotnet-public-maven` and succeeded after the mirror helper seeded the full transitive graph
- `mirror-dependencies.ps1` parsed successfully with the PowerShell parser
- Java.Interop final SHA is exactly one commit on top of the release pin
- `git diff --check origin/release/10.0.1xx..HEAD`

Co-authored-by: Copilot App <[email protected]>
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 11, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

ready-to-review This PR is ready to review/merge, I think any CI failures are just flaky (ignorable).

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants