Repository navigation
[automated] Merge branch 'release/9.0.1xx' => 'release/9.0.3xx' - #55674
Merged
mthalman merged 86 commits intoAug 11, 2026
Merged
Conversation
backport of https://dev.azure.com/dnceng/internal/_git/dotnet-sdk/pullrequest/60602 for 8.0 with 8.0 code changes
similar to https://dev.azure.com/dnceng/internal/_git/dotnet-sdk/commit/24d060950e77e6c35cb491286c282434b77c2637?refName=refs%2Fheads%2Fnagilson-nagilson%2Fpipe-restrict-int8.0.3xx but slightly different due to msi package method changes in 100 vs 300 ---- #### AI description (iteration 1) #### PR Classification Security enhancement to restrict and validate workload installer IPC pipe access and file path operations. #### PR Summary This PR strengthens security in the .NET workload installer by restricting named pipe access to specific users and validating all file paths to prevent traversal attacks. The changes ensure that elevated installer operations cannot be exploited to access arbitrary system locations. - `WindowsUtils.cs`: Added methods to retrieve process user SIDs, create restricted pipe security (granting access only to the parent process user instead of all authenticated users), and validate file paths against traversal attacks - `NetSdkMsiInstallerServer.cs`: Modified pipe security configuration to use parent process user SID instead of the broad "authenticated users" group - `MsiInstallerBase.cs` and `MsiPackageCache.cs`: Added path validation to ensure log files and package paths remain within expected directories (cache root or user temp) - `WindowsInstallerTests.cs`: Added comprehensive unit tests covering pipe security, log file path validation, package path validation, and path component validation - `NativeMethods.cs`: Added P/Invoke declaration for `OpenProcessToken` to support retrieving process security identifiers <!-- GitOpsUserAgent=GitOps.Apps.Server.pullrequestcopilot -->
…3 repositories This pull request updates the following dependencies [marker]: <> (Begin:5ae73aca-14b4-4570-17b0-08dbd53e3897) ## From https://dev.azure.com/dnceng/internal/_git/dotnet-aspnetcore - **Subscription**: [5ae73aca-14b4-4570-17b0-08dbd53e3897](https://maestro.dot.net/subscriptions?search=5ae73aca-14b4-4570-17b0-08dbd53e3897) - **Build**: [20260518.3](https://dev.azure.com/dnceng/internal/_build/results?buildId=2977960) ([314868](https://maestro.dot.net/channel/3880/azdo:dnceng:internal:dotnet-aspnetcore/build/314868)) - **Date Produced**: May 18, 2026 9:39:51 PM UTC - **Commit**: [206e82da31a67bbe713cf7aac8d6f04de099a9f8](https://dev.azure.com/dnceng/internal/_git/dotnet-aspnetcore?_a=history&version=GC206e82da31a67bbe713cf7aac8d6f04de099a9f8) - **Branch**: [refs/heads/internal/release/8.0](https://dev.azure.com/dnceng/internal/_git/dotnet-aspnetcore?version=GBrefs/heads/internal/release/8.0) [DependencyUpdate]: <> (Begin) - **Dependency Updates**: - From [8.0.27-servicing.26230.8 to 8.0.28-servicing.26268.3][1] - dotnet-dev-certs - dotnet-user-jwts - dotnet-user-secrets - Microsoft.AspNetCore.Analyzers - Microsoft.AspNetCore.App.Ref.Internal - Microsoft.AspNetCore.Components.SdkAnalyzers - Microsoft.AspNetCore.DeveloperCertificates.XPlat - Microsoft.AspNetCore.Mvc.Analyzers - Microsoft.AspNetCore.Mvc.Api.Analyzers - VS.Redist.Common.AspNetCore.SharedFramework.x64.8.0 - From [8.0.27 to 8.0.28][1] - Microsoft.AspNetCore.App.Ref - Microsoft.AspNetCore.App.Runtime.win-x64 - Microsoft.AspNetCore.Authorization - Microsoft.AspNetCore.Components.Web - Microsoft.AspNetCore.TestHost - Microsoft.Extensions.FileProviders.Embedded - Microsoft.Extensions.ObjectPool - Microsoft.JSInterop [1]: https://dev.azure.com/dnceng/internal/_git/dotnet-aspnetcore/branches?baseVersion=GCbe2530c3035e4bfa7670c6b18f5a64ef89e0e80d&targetVersion=GC206e82da31a67bbe713cf7aac8d6f04de099a9f8&_a=files [DependencyUpdate]: <> (End) [marker]: <> (End:5ae73aca-14b4-4570-17b0-08dbd53e3897) [marker]: <> (Begin:Coherency Updates) ## Coherency Updates The following updates ensure that dependencies with a *CoherentParentDependency* attribute were produced in a build used as input to the parent dependency's build. See [Dependency Description Format](https://github.com/dotnet/arcade/blob/master/Documentation/DependencyDescriptionFormat.md#dependency-description-overview) [DependencyUpdate]: <> (Begin) - **Coherency Updates**: - **Microsoft.NET.Sdk.WindowsDesktop**: from 8.0.27-servicing.26230.2 to 8.0.28-servicing.26264.9 (parent: Microsoft.WindowsDesktop.App.Ref) [DependencyUpdate]: <> (End) [marker]: <> (End:Coherency Updates) [marker]: <> (Begin:dd95552e-72fb-4363-9b59-08dbd5a5c3e7) ## From https://dev.azure.com/dnceng/internal/_git/dotnet-runtime - **Subscription**: [dd95552e-72fb-4363-9b59-08dbd5a5c3e7](https://maestro.dot.net/subscriptions?search=dd95552e-72fb-4363-9b59-08dbd5a5...
…dnceng/internal/dotnet-windowsdesktop This pull request updates the following dependencies [marker]: <> (Begin:Coherency Updates) ## Coherency Updates The following updates ensure that dependencies with a *CoherentParentDependency* attribute were produced in a build used as input to the parent dependency's build. See [Dependency Description Format](https://github.com/dotnet/arcade/blob/master/Documentation/DependencyDescriptionFormat.md#dependency-description-overview) [DependencyUpdate]: <> (Begin) - **Coherency Updates**: - **Microsoft.NET.Sdk.WindowsDesktop**: from 8.0.28-servicing.26264.9 to 8.0.28-servicing.26265.4 (parent: Microsoft.WindowsDesktop.App.Ref) [DependencyUpdate]: <> (End) [marker]: <> (End:Coherency Updates) [marker]: <> (Begin:43ca46dd-3142-499e-f076-08dbd5a5cbe7) ## From https://dev.azure.com/dnceng/internal/_git/dotnet-windowsdesktop - **Subscription**: [43ca46dd-3142-499e-f076-08dbd5a5cbe7](https://maestro.dot.net/subscriptions?search=43ca46dd-3142-499e-f076-08dbd5a5cbe7) - **Build**: [20260518.2](https://dev.azure.com/dnceng/internal/_build/results?buildId=2978265) ([314896](https://maestro.dot.net/channel/3880/azdo:dnceng:internal:dotnet-windowsdesktop/build/314896)) - **Date Produced**: May 19, 2026 12:00:47 AM UTC - **Commit**: [ec791e700315d8dcaecb11a6a1850092afad1ca7](https://dev.azure.com/dnceng/internal/_git/dotnet-windowsdesktop?_a=history&version=GCec791e700315d8dcaecb11a6a1850092afad1ca7) - **Branch**: [refs/heads/internal/release/8.0](https://dev.azure.com/dnceng/internal/_git/dotnet-windowsdesktop?version=GBrefs/heads/internal/release/8.0) [DependencyUpdate]: <> (Begin) - **Dependency Updates**: - From [8.0.28 to 8.0.28][1] - Microsoft.WindowsDesktop.App.Ref - Microsoft.WindowsDesktop.App.Runtime.win-x64 - From [8.0.28-servicing.26264.2 to 8.0.28-servicing.26268.2][1] - VS.Redist.Common.WindowsDesktop.SharedFramework.x64.8.0 - VS.Redist.Common.WindowsDesktop.TargetingPack.x64.8.0 [1]: https://dev.azure.com/dnceng/internal/_git/dotnet-windowsdesktop/branches?baseVersion=GCa2e8b8fd21f2fc18e5c0758c0584245e343ebeb7&targetVersion=GCec791e700315d8dcaecb11a6a1850092afad1ca7&_a=files [DependencyUpdate]: <> (End) [marker]: <> (End:43ca46dd-3142-499e-f076-08dbd5a5cbe7)
…dnceng/internal/dotnet-aspnetcore This pull request updates the following dependencies [marker]: <> (Begin:5ae73aca-14b4-4570-17b0-08dbd53e3897) ## From https://dev.azure.com/dnceng/internal/_git/dotnet-aspnetcore - **Subscription**: [5ae73aca-14b4-4570-17b0-08dbd53e3897](https://maestro.dot.net/subscriptions?search=5ae73aca-14b4-4570-17b0-08dbd53e3897) - **Build**: [20260519.13](https://dev.azure.com/dnceng/internal/_build/results?buildId=2979206) ([315073](https://maestro.dot.net/channel/3880/azdo:dnceng:internal:dotnet-aspnetcore/build/315073)) - **Date Produced**: May 19, 2026 11:13:23 PM UTC - **Commit**: [bb9eccba9080e07bce32c0bc27c3564c753a7cfe](https://dev.azure.com/dnceng/internal/_git/dotnet-aspnetcore?_a=history&version=GCbb9eccba9080e07bce32c0bc27c3564c753a7cfe) - **Branch**: [refs/heads/internal/release/8.0](https://dev.azure.com/dnceng/internal/_git/dotnet-aspnetcore?version=GBrefs/heads/internal/release/8.0) [DependencyUpdate]: <> (Begin) - **Dependency Updates**: - From [8.0.28-servicing.26268.3 to 8.0.28-servicing.26269.13][1] - dotnet-dev-certs - dotnet-user-jwts - dotnet-user-secrets - Microsoft.AspNetCore.Analyzers - Microsoft.AspNetCore.App.Ref.Internal - Microsoft.AspNetCore.Components.SdkAnalyzers - Microsoft.AspNetCore.DeveloperCertificates.XPlat - Microsoft.AspNetCore.Mvc.Analyzers - Microsoft.AspNetCore.Mvc.Api.Analyzers - VS.Redist.Common.AspNetCore.SharedFramework.x64.8.0 - From [8.0.28 to 8.0.28][1] - Microsoft.AspNetCore.App.Ref - Microsoft.AspNetCore.App.Runtime.win-x64 - Microsoft.AspNetCore.Authorization - Microsoft.AspNetCore.Components.Web - Microsoft.AspNetCore.TestHost - Microsoft.Extensions.FileProviders.Embedded - Microsoft.Extensions.ObjectPool - Microsoft.JSInterop [1]: https://dev.azure.com/dnceng/internal/_git/dotnet-aspnetcore/branches?baseVersion=GC206e82da31a67bbe713cf7aac8d6f04de099a9f8&targetVersion=GCbb9eccba9080e07bce32c0bc27c3564c753a7cfe&_a=files [DependencyUpdate]: <> (End) [marker]: <> (End:5ae73aca-14b4-4570-17b0-08dbd53e3897)
…dnceng/internal/dotnet-windowsdesktop This pull request updates the following dependencies [marker]: <> (Begin:Coherency Updates) ## Coherency Updates The following updates ensure that dependencies with a *CoherentParentDependency* attribute were produced in a build used as input to the parent dependency's build. See [Dependency Description Format](https://github.com/dotnet/arcade/blob/master/Documentation/DependencyDescriptionFormat.md#dependency-description-overview) [DependencyUpdate]: <> (Begin) - **Coherency Updates**: - **Microsoft.NET.Sdk.WindowsDesktop**: from 8.0.28-servicing.26265.4 to 8.0.28-servicing.26269.2 (parent: Microsoft.WindowsDesktop.App.Ref) [DependencyUpdate]: <> (End) [marker]: <> (End:Coherency Updates) [marker]: <> (Begin:43ca46dd-3142-499e-f076-08dbd5a5cbe7) ## From https://dev.azure.com/dnceng/internal/_git/dotnet-windowsdesktop - **Subscription**: [43ca46dd-3142-499e-f076-08dbd5a5cbe7](https://maestro.dot.net/subscriptions?search=43ca46dd-3142-499e-f076-08dbd5a5cbe7) - **Build**: [20260519.1](https://dev.azure.com/dnceng/internal/_build/results?buildId=2979365) ([315092](https://maestro.dot.net/channel/3880/azdo:dnceng:internal:dotnet-windowsdesktop/build/315092)) - **Date Produced**: May 20, 2026 1:17:40 AM UTC - **Commit**: [432d0577ee8d6a36654d23a83182a0c7da27a69f](https://dev.azure.com/dnceng/internal/_git/dotnet-windowsdesktop?_a=history&version=GC432d0577ee8d6a36654d23a83182a0c7da27a69f) - **Branch**: [refs/heads/internal/release/8.0](https://dev.azure.com/dnceng/internal/_git/dotnet-windowsdesktop?version=GBrefs/heads/internal/release/8.0) [DependencyUpdate]: <> (Begin) - **Dependency Updates**: - From [8.0.28 to 8.0.28][1] - Microsoft.WindowsDesktop.App.Ref - Microsoft.WindowsDesktop.App.Runtime.win-x64 - From [8.0.28-servicing.26268.2 to 8.0.28-servicing.26269.1][1] - VS.Redist.Common.WindowsDesktop.SharedFramework.x64.8.0 - VS.Redist.Common.WindowsDesktop.TargetingPack.x64.8.0 [1]: https://dev.azure.com/dnceng/internal/_git/dotnet-windowsdesktop/branches?baseVersion=GCec791e700315d8dcaecb11a6a1850092afad1ca7&targetVersion=GC432d0577ee8d6a36654d23a83182a0c7da27a69f&_a=files [DependencyUpdate]: <> (End) [marker]: <> (End:43ca46dd-3142-499e-f076-08dbd5a5cbe7)
Replace Ubuntu 22.04 VM pool images, Helix queues, and agentOs labels with Azure Linux 3 equivalents across CI/PR pipelines. Changes: - 1es-ubuntu-2204-open -> build.azurelinux.3.amd64.open - 1es-ubuntu-2204 -> build.azurelinux.3.amd64 - build.ubuntu.2204.amd64.open -> build.azurelinux.3.amd64.open - build.ubuntu.2204.amd64 -> build.azurelinux.3.amd64 - ubuntu.2204.amd64.open -> azurelinux.3.amd64.open - Ubuntu.2204.Amd64 -> AzureLinux.3.Amd64 - agentOs: Ubuntu_22_04 -> AzureLinux_3 - vmImage: ubuntu-22.04 -> demands-based pool with azurelinux image Container images and eng/common (from arcade) are unchanged. Co-authored-by: Copilot <[email protected]>
These tests fail on Azure Linux 3 because older .NET Core runtimes (netcoreapp3.0/3.1) require libicu for globalization support, which is not installed by default on Azure Linux. Since these TFMs are long out of support, remove them rather than adding workarounds. Changes: - Remove netcoreapp3.1 from PublishTestUtils.SupportedTfms (affects ~14 tests) - Remove netcoreapp3.0 InlineData from ILLink_runs_and_creates_linked_app - Remove netcoreapp3.1 InlineData from ILLink_old_defaults_keep_nonframework - Remove netcoreapp3.1 InlineData from ILLink_displays_informational_warning_up_to_net5_by_default - Retarget ILLink_and_crossgen_process_razor_assembly from netcoreapp3.0 to net6.0 - Update CreateTestProjectForILLinkTesting helper package reference TFM from netcoreapp3.0 to net5.0 Co-authored-by: Copilot <[email protected]>
- Set DOTNET_SYSTEM_GLOBALIZATION_INVARIANT=true in both RunTestsOnHelix.sh and RunTestsOnHelix.cmd so old .NET Core runtimes (1.x/2.x) can run on distros without ICU installed (e.g., Azure Linux 3) - Fix ILLink_and_crossgen_process_razor_assembly test: check TestWeb.dll instead of TestWeb.Views.dll since net6.0+ compiles Razor views into the main assembly Co-authored-by: Copilot <[email protected]>
The globalization invariant mode was causing ~70+ test failures on Azure Linux 3 by preventing culture-aware operations: - CultureNotFoundException for en-US, ja, de, fr cultures - Missing satellite assemblies (.resources.dll/.resources.wasm) - Failed culture code warnings in build tasks - Cascading test directory collisions from Arcade retries Azure Linux 3 Helix images have ICU installed, so invariant mode is not needed. Windows never needed it either. Co-authored-by: Copilot <[email protected]>
Create ICU version symlinks in RunTestsOnHelix.sh so old .NET runtimes (< .NET 6) can discover ICU on Azure Linux 3 where the ICU version (74) is higher than what those runtimes probe for via dlopen. Also update EnvironmentInfo.SupportsTargetFramework to skip netcoreapp1.x tests on Azure Linux since those runtimes are not installed there. Co-authored-by: Copilot <[email protected]>
…ymlinks Azure Linux 3 ships ICU 72 which uses versioned symbol names (e.g. u_charsToUChars_72). Old .NET runtimes (< .NET 5) try to load symbols with older version suffixes that don't exist in ICU 72, causing 'undefined symbol' crashes. This ABI incompatibility cannot be fixed via symlinks. Changes: - Remove broken ICU symlink logic from RunTestsOnHelix.sh - Expand EnvironmentInfo.SupportsTargetFramework to skip < net5.0 on Azure Linux (was < netcoreapp2.0) - Add RequiresSpecificFrameworkFact/Theory(netcoreapp2.2) to tests that invoke legacy DotNetCliTool packages - Add runtime SupportsTargetFramework check to CoreMSBuildOnlyFact tests that generate/run netcoreapp2.2 tool deps files Co-authored-by: Copilot <[email protected]>
- Add zlib symlink workaround in RunTestsOnHelix.sh for NativeAOT linking (Azure Linux 3 has libz.so.1 but missing libz.so from zlib-devel) - Skip DepsJson version conflict tests on Azure Linux (netcoreapp2.0/2.2) - Skip WebApp self-contained 2x publish test on Azure Linux (netcoreapp2.2) - Skip AppHost netcoreapp3.1 test variant on Azure Linux (ICU 72 ABI) Co-authored-by: Copilot <[email protected]>
- TransitiveProjectRefs: 4 tests build+run netcoreapp2.1 apps (ICU crash) - Store compose: 3 tests target netcoreapp2.0 (missing native crypto lib) - ReferenceExeTests: netcoreapp3.1 referenced project (ICU crash) - RunFromOutputFolder: netcoreapp2.0/2.1 variants (ICU crash) - SingleFileApp: netcoreapp3.0/3.1 variants (ICU crash) All failures are due to Azure Linux 3 having ICU 72 which is ABI-incompatible with .NET runtimes < 5.0 (versioned symbol names). Co-authored-by: Copilot <[email protected]>
netcoreapp2.1/2.2 variants crash with ICU 72 ABI incompatibility. Co-authored-by: Copilot <[email protected]>
…build 20260601.2 On relative base path root Microsoft.SourceBuild.Intermediate.source-build-assets From Version 8.0.0-alpha.1.26262.3 -> To Version 8.0.0-alpha.1.26301.2
…b-4f87-b6df-eb6d681a7c48
…b-4f87-b6df-eb6d681a7c48
…-merge-8.0.1xx-2026-06-09-1516
…se/9.0.1xx-febac99c-888a-4057-b279-e9d47bbfd801 # Conflicts: # NuGet.config Co-authored-by: mthalman <[email protected]>
…#55587) Co-authored-by: dotnet-maestro[bot] <dotnet-maestro[bot]@users.noreply.github.com>
Copilot-Session: d769c502-f3c6-4f02-9e0d-db729faebcb4
Co-authored-by: dotnet-maestro[bot] <dotnet-maestro[bot]@users.noreply.github.com>
…#55624) [release/9.0.1xx] Update dependencies from dotnet/source-build-assets
Co-authored-by: dotnet-maestro[bot] <dotnet-maestro[bot]@users.noreply.github.com>
Reset patterns: - global.json - NuGet.config - eng/Version.Details.xml - eng/Versions.props - eng/common/*
Member
|
@copilot resolve the merge conflicts in this pull request |
mthalman
approved these changes
Aug 7, 2026
…9.0.3xx Co-authored-by: mthalman <[email protected]>
Contributor
Resolved in f448a9b. Only one file conflicted: |
mthalman
approved these changes
Aug 7, 2026
mthalman
enabled auto-merge
August 7, 2026 15:14
dsplaisted
approved these changes
Aug 11, 2026
This was referenced Sep 1, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
I detected changes in the release/9.0.1xx branch which have not been merged yet to release/9.0.3xx. I'm a robot and am configured to help you automatically keep release/9.0.3xx up to date, so I've opened this PR.
This PR merges commits made on release/9.0.1xx by the following committers:
Instructions for merging from UI
This PR will not be auto-merged. When pull request checks pass, complete this PR by creating a merge commit, not a squash or rebase commit.
If this repo does not allow creating merge commits from the GitHub UI, use command line instructions.
Instructions for merging via command line
Run these commands to merge this pull request from the command line.
or if you are using SSH
After PR checks are complete push the branch
Instructions for resolving conflicts
Instructions for updating this pull request
Contributors to this repo have permission update this pull request by pushing to the branch 'merge/release/9.0.1xx-to-release/9.0.3xx'. This can be done to resolve conflicts or make other changes to this pull request before it is merged.
The provided examples assume that the remote is named 'origin'. If you have a different remote name, please replace 'origin' with the name of your remote.
or if you are using SSH
Contact .NET Core Engineering (dotnet/dnceng) if you have questions or issues.
Also, if this PR was generated incorrectly, help us fix it. See https://github.com/dotnet/arcade/blob/main/.github/workflows/scripts/inter-branch-merge.ps1.