diff --git a/.config/dotnet-tools.json b/.config/dotnet-tools.json index 111aec2c8a2a6d..74ab0de0094926 100644 --- a/.config/dotnet-tools.json +++ b/.config/dotnet-tools.json @@ -27,7 +27,7 @@ ] }, "microsoft.dotnet.helix.jobmonitor": { - "version": "11.0.0-beta.26407.8", + "version": "11.0.0-beta.26411.119", "commands": [ "dotnet-helix-job-monitor" ] diff --git a/eng/AcquireEmscriptenSdk.targets b/eng/AcquireEmscriptenSdk.targets index 9cb00edc50d907..e0563d98ac3122 100644 --- a/eng/AcquireEmscriptenSdk.targets +++ b/eng/AcquireEmscriptenSdk.targets @@ -10,6 +10,15 @@ bump provisions a fresh entry and every clone and git worktree on the machine shares one copy. --> + + + $(MicrosoftNETRuntimeEmscriptenInternalPackageVersion) + + true $(EmscriptenSdkCacheDir.Replace('\', '/')) diff --git a/eng/Version.Details.props b/eng/Version.Details.props index 92c05063d16c53..14299a3d6b53b4 100644 --- a/eng/Version.Details.props +++ b/eng/Version.Details.props @@ -5,92 +5,92 @@ This file should be imported by eng/Versions.props --> - - 11.0.0-beta.26407.8 - 11.0.0-beta.26381.1 - 5.10.0-1.26379.102 - 5.10.0-1.26379.102 - 5.10.0-1.26379.102 - 5.10.0-1.26379.102 - 11.0.100-rc.1.26379.102 - 11.0.100-rc.1.26379.102 - 11.0.0-beta.26379.102 - 11.0.0-beta.26379.102 - 11.0.0-beta.26379.102 - 11.0.0-beta.26379.102 - 11.0.0-beta.26379.102 - 11.0.0-beta.26379.102 - 11.0.0-beta.26379.102 - 11.0.0-beta.26379.102 - 0.11.5-preview.26379.102 - 11.0.0-beta.26379.102 - 11.0.0-beta.26379.102 - 11.0.0-beta.26379.102 - 11.0.0-beta.26379.102 - 11.0.0-beta.26379.102 - 11.0.0-beta.26379.102 - 11.0.0-beta.26379.102 + 5.11.0-1.26411.119 + 5.11.0-1.26411.119 + 5.11.0-1.26411.119 + 5.11.0-1.26411.119 + 11.0.100-rc.1.26411.119 + 11.0.100-rc.1.26411.119 + 11.0.0-beta.26411.119 + 11.0.0-beta.26411.119 + 11.0.0-beta.26411.119 + 11.0.0-beta.26411.119 + 11.0.0-beta.26411.119 + 11.0.0-beta.26411.119 + 11.0.0-beta.26411.119 + 11.0.0-beta.26411.119 + 0.11.5-preview.26411.119 + 11.0.0-beta.26411.119 + 11.0.0-beta.26411.119 + 11.0.0-beta.26411.119 + 11.0.0-beta.26411.119 + 11.0.0-beta.26411.119 + 11.0.0-beta.26411.119 + 11.0.0-beta.26411.119 + 11.0.0-beta.26411.119 + 11.0.0-beta.26411.119 3.2.2-beta.26257.113 - 2.9.3-beta.26379.102 - 11.0.0-beta.26379.102 - 5.10.0-1.26379.102 - 11.0.0-rc.1.26379.102 - 11.0.100-rc.1.26379.102 - 11.0.0-rc.1.26379.102 - 11.0.0-rc.1.26379.102 - 7.10.0-rc.38002 - 7.10.0-rc.38002 - 7.10.0-rc.38002 - 7.10.0-rc.38002 - 11.0.0-rc.1.26379.102 - 3.0.0-rc.1.26379.102 - 11.0.0-rc.1.26379.102 - 11.0.0-rc.1.26379.102 - 11.0.0-rc.1.26379.102 + 2.9.3-beta.26411.119 + 11.0.0-beta.26411.119 + 5.11.0-1.26411.119 + 11.0.0-rc.1.26411.119 + 11.0.0-rc.1.26411.119 + 11.0.100-rc.1.26411.119 + 11.0.0-rc.1.26411.119 + 11.0.0-rc.1.26411.119 + 7.11.0-rc.65534 + 7.11.0-rc.65534 + 7.11.0-rc.65534 + 7.11.0-rc.65534 + 11.0.0-rc.1.26411.119 + 3.0.0-rc.1.26411.119 + 11.0.0-rc.1.26411.119 + 11.0.0-rc.1.26411.119 + 11.0.0-rc.1.26411.119 11.0.0-alpha.0.26180.1 11.0.0-alpha.1.26364.1 - 23.1.0-alpha.1.26370.1 - 23.1.0-alpha.1.26370.1 - 23.1.0-alpha.1.26370.1 - 23.1.0-alpha.1.26370.1 - 23.1.0-alpha.1.26370.1 - 23.1.0-alpha.1.26370.1 - 23.1.0-alpha.1.26370.1 - 23.1.0-alpha.1.26370.1 - 23.1.0-alpha.1.26370.1 - 23.1.0-alpha.1.26370.1 - 23.1.0-alpha.1.26370.1 - 23.1.0-alpha.1.26370.1 - 23.1.0-alpha.1.26370.1 - 23.1.0-alpha.1.26370.1 - 23.1.0-alpha.1.26370.1 - 23.1.0-alpha.1.26370.1 - 23.1.0-alpha.1.26370.1 - 23.1.0-alpha.1.26370.1 - 23.1.0-alpha.1.26370.1 - 23.1.0-alpha.1.26370.1 - 23.1.0-alpha.1.26370.1 - 23.1.0-alpha.1.26370.1 - 23.1.0-alpha.1.26370.1 - 23.1.0-alpha.1.26370.1 - 23.1.0-alpha.1.26370.1 - 23.1.0-alpha.1.26370.1 - 23.1.0-alpha.1.26370.1 - 23.1.0-alpha.1.26370.1 - 23.1.0-alpha.1.26370.1 + 23.1.0-alpha.1.26405.2 + 23.1.0-alpha.1.26405.2 + 23.1.0-alpha.1.26405.2 + 23.1.0-alpha.1.26405.2 + 23.1.0-alpha.1.26405.2 + 23.1.0-alpha.1.26405.2 + 23.1.0-alpha.1.26405.2 + 23.1.0-alpha.1.26405.2 + 23.1.0-alpha.1.26405.2 + 23.1.0-alpha.1.26405.2 + 23.1.0-alpha.1.26405.2 + 23.1.0-alpha.1.26405.2 + 23.1.0-alpha.1.26405.2 + 23.1.0-alpha.1.26405.2 + 23.1.0-alpha.1.26405.2 + 23.1.0-alpha.1.26405.2 + 23.1.0-alpha.1.26405.2 + 23.1.0-alpha.1.26405.2 + 23.1.0-alpha.1.26405.2 + 23.1.0-alpha.1.26405.2 + 23.1.0-alpha.1.26405.2 + 23.1.0-alpha.1.26405.2 + 23.1.0-alpha.1.26405.2 + 23.1.0-alpha.1.26405.2 + 23.1.0-alpha.1.26405.2 + 23.1.0-alpha.1.26405.2 + 23.1.0-alpha.1.26405.2 + 23.1.0-alpha.1.26405.2 + 23.1.0-alpha.1.26405.2 - 11.0.0-alpha.1.26372.1 - 11.0.0-alpha.1.26372.1 - 11.0.0-alpha.1.26372.1 - 11.0.0-alpha.1.26372.1 - 11.0.0-alpha.1.26372.1 - 11.0.0-alpha.1.26372.1 - 11.0.0-alpha.1.26372.1 - 11.0.0-alpha.1.26372.1 + 11.0.0-alpha.1.26407.6 + 11.0.0-alpha.1.26407.6 + 11.0.0-alpha.1.26407.6 + 11.0.0-alpha.1.26407.6 + 11.0.0-alpha.1.26407.6 + 11.0.0-alpha.1.26407.6 + 11.0.0-alpha.1.26407.6 + 11.0.0-alpha.1.26407.6 1.0.0-prerelease.26403.1 1.0.0-prerelease.26403.1 @@ -122,9 +122,6 @@ This file should be imported by eng/Versions.props - - $(MicrosoftDotNetHelixJobMonitorPackageVersion) - $(MicrosoftDotNetHelixSdkPackageVersion) $(MicrosoftCodeAnalysisPackageVersion) $(MicrosoftCodeAnalysisAnalyzersPackageVersion) @@ -144,6 +141,8 @@ This file should be imported by eng/Versions.props $(MicrosoftDotNetCodeAnalysisPackageVersion) $(MicrosoftDotNetGenAPIPackageVersion) $(MicrosoftDotNetGenFacadesPackageVersion) + $(MicrosoftDotNetHelixJobMonitorPackageVersion) + $(MicrosoftDotNetHelixSdkPackageVersion) $(MicrosoftDotNetPackageTestingPackageVersion) $(MicrosoftDotNetRemoteExecutorPackageVersion) $(MicrosoftDotNetSharedFrameworkSdkPackageVersion) @@ -152,6 +151,7 @@ This file should be imported by eng/Versions.props $(MicrosoftDotNetXUnitConsoleRunnerPackageVersion) $(MicrosoftDotNetXUnitExtensionsPackageVersion) $(MicrosoftNetCompilersToolsetPackageVersion) + $(MicrosoftNETRuntimeEmscriptenInternalPackageVersion) $(MicrosoftNETSdkILPackageVersion) $(MicrosoftNETWorkloadEmscriptenCurrentManifest110100TransportPackageVersion) $(MicrosoftNETCoreAppRefPackageVersion) diff --git a/eng/Version.Details.xml b/eng/Version.Details.xml index 8bff8f943709cc..07b61070f84fbd 100644 --- a/eng/Version.Details.xml +++ b/eng/Version.Details.xml @@ -1,127 +1,131 @@ - + https://github.com/dotnet/icu 6cfb6605cf78bc12164284ec6cc7afbafb52d64e - + https://github.com/dotnet/llvm-project - f4d1fd43c863e8b17c0f8d50536e23c4e84c3242 + 8ae183bac6b9a8fc311b885cc6e261f77bbb7a57 - + https://github.com/dotnet/llvm-project - f4d1fd43c863e8b17c0f8d50536e23c4e84c3242 + 8ae183bac6b9a8fc311b885cc6e261f77bbb7a57 - + https://github.com/dotnet/llvm-project - f4d1fd43c863e8b17c0f8d50536e23c4e84c3242 + 8ae183bac6b9a8fc311b885cc6e261f77bbb7a57 - + https://github.com/dotnet/llvm-project - f4d1fd43c863e8b17c0f8d50536e23c4e84c3242 + 8ae183bac6b9a8fc311b885cc6e261f77bbb7a57 - + https://github.com/dotnet/llvm-project - f4d1fd43c863e8b17c0f8d50536e23c4e84c3242 + 8ae183bac6b9a8fc311b885cc6e261f77bbb7a57 - + https://github.com/dotnet/llvm-project - f4d1fd43c863e8b17c0f8d50536e23c4e84c3242 + 8ae183bac6b9a8fc311b885cc6e261f77bbb7a57 - + https://github.com/dotnet/llvm-project - f4d1fd43c863e8b17c0f8d50536e23c4e84c3242 + 8ae183bac6b9a8fc311b885cc6e261f77bbb7a57 - + https://github.com/dotnet/llvm-project - f4d1fd43c863e8b17c0f8d50536e23c4e84c3242 + 8ae183bac6b9a8fc311b885cc6e261f77bbb7a57 - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a + + + https://github.com/dotnet/dotnet + 7cdb217445905f3342bbb0266a4497b9a014389a - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a - - https://github.com/dotnet/arcade - 93eebf1a31a5eaafd44326f1a81ca107913e098c + + https://github.com/dotnet/dotnet + 7cdb217445905f3342bbb0266a4497b9a014389a - - https://github.com/dotnet/arcade - 212960245c74330fbfb71776563638061e35446c + + https://github.com/dotnet/dotnet + 7cdb217445905f3342bbb0266a4497b9a014389a - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a https://github.com/dotnet/dotnet 0eae08ed2f094f44e0151e4815e7cdd1a334fcdf - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a https://github.com/dotnet/runtime-assets @@ -175,117 +179,117 @@ https://github.com/dotnet/runtime-assets 7d4d3d2b53b18ad0ca1826581c9710b565b44fe5 - + https://github.com/dotnet/llvm-project - f4d1fd43c863e8b17c0f8d50536e23c4e84c3242 + 8ae183bac6b9a8fc311b885cc6e261f77bbb7a57 - + https://github.com/dotnet/llvm-project - f4d1fd43c863e8b17c0f8d50536e23c4e84c3242 + 8ae183bac6b9a8fc311b885cc6e261f77bbb7a57 - + https://github.com/dotnet/llvm-project - f4d1fd43c863e8b17c0f8d50536e23c4e84c3242 + 8ae183bac6b9a8fc311b885cc6e261f77bbb7a57 - + https://github.com/dotnet/llvm-project - f4d1fd43c863e8b17c0f8d50536e23c4e84c3242 + 8ae183bac6b9a8fc311b885cc6e261f77bbb7a57 - + https://github.com/dotnet/llvm-project - f4d1fd43c863e8b17c0f8d50536e23c4e84c3242 + 8ae183bac6b9a8fc311b885cc6e261f77bbb7a57 - + https://github.com/dotnet/llvm-project - f4d1fd43c863e8b17c0f8d50536e23c4e84c3242 + 8ae183bac6b9a8fc311b885cc6e261f77bbb7a57 - + https://github.com/dotnet/llvm-project - f4d1fd43c863e8b17c0f8d50536e23c4e84c3242 + 8ae183bac6b9a8fc311b885cc6e261f77bbb7a57 - + https://github.com/dotnet/llvm-project - f4d1fd43c863e8b17c0f8d50536e23c4e84c3242 + 8ae183bac6b9a8fc311b885cc6e261f77bbb7a57 - + https://github.com/dotnet/llvm-project - f4d1fd43c863e8b17c0f8d50536e23c4e84c3242 + 8ae183bac6b9a8fc311b885cc6e261f77bbb7a57 - + https://github.com/dotnet/llvm-project - f4d1fd43c863e8b17c0f8d50536e23c4e84c3242 + 8ae183bac6b9a8fc311b885cc6e261f77bbb7a57 - + https://github.com/dotnet/llvm-project - f4d1fd43c863e8b17c0f8d50536e23c4e84c3242 + 8ae183bac6b9a8fc311b885cc6e261f77bbb7a57 - + https://github.com/dotnet/llvm-project - f4d1fd43c863e8b17c0f8d50536e23c4e84c3242 + 8ae183bac6b9a8fc311b885cc6e261f77bbb7a57 - + https://github.com/dotnet/llvm-project - f4d1fd43c863e8b17c0f8d50536e23c4e84c3242 + 8ae183bac6b9a8fc311b885cc6e261f77bbb7a57 - + https://github.com/dotnet/llvm-project - f4d1fd43c863e8b17c0f8d50536e23c4e84c3242 + 8ae183bac6b9a8fc311b885cc6e261f77bbb7a57 - + https://github.com/dotnet/llvm-project - f4d1fd43c863e8b17c0f8d50536e23c4e84c3242 + 8ae183bac6b9a8fc311b885cc6e261f77bbb7a57 - + https://github.com/dotnet/llvm-project - f4d1fd43c863e8b17c0f8d50536e23c4e84c3242 + 8ae183bac6b9a8fc311b885cc6e261f77bbb7a57 - + https://github.com/dotnet/llvm-project - f4d1fd43c863e8b17c0f8d50536e23c4e84c3242 + 8ae183bac6b9a8fc311b885cc6e261f77bbb7a57 - + https://github.com/dotnet/llvm-project - f4d1fd43c863e8b17c0f8d50536e23c4e84c3242 + 8ae183bac6b9a8fc311b885cc6e261f77bbb7a57 - + https://github.com/dotnet/llvm-project - f4d1fd43c863e8b17c0f8d50536e23c4e84c3242 + 8ae183bac6b9a8fc311b885cc6e261f77bbb7a57 - + https://github.com/dotnet/llvm-project - f4d1fd43c863e8b17c0f8d50536e23c4e84c3242 + 8ae183bac6b9a8fc311b885cc6e261f77bbb7a57 - + https://github.com/dotnet/llvm-project - f4d1fd43c863e8b17c0f8d50536e23c4e84c3242 + 8ae183bac6b9a8fc311b885cc6e261f77bbb7a57 - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a https://github.com/dotnet/xharness @@ -299,9 +303,9 @@ https://github.com/dotnet/xharness acc639bea6c5720abf118b8808e18f9cabe90568 - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a https://dev.azure.com/dnceng/internal/_git/dotnet-optimization @@ -327,33 +331,33 @@ https://github.com/dotnet/runtime-assets 7d4d3d2b53b18ad0ca1826581c9710b565b44fe5 - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a https://dev.azure.com/dnceng/internal/_git/dotnet-optimization @@ -365,53 +369,53 @@ - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a - + https://github.com/dotnet/node - 547dab528bc5dfd593064589564b64501ad7ab78 + db20b769545bd6a97f81fbe23cd1fcd5f6b88c5a - + https://github.com/dotnet/node - 547dab528bc5dfd593064589564b64501ad7ab78 + db20b769545bd6a97f81fbe23cd1fcd5f6b88c5a - + https://github.com/dotnet/node - 547dab528bc5dfd593064589564b64501ad7ab78 + db20b769545bd6a97f81fbe23cd1fcd5f6b88c5a - + https://github.com/dotnet/node - 547dab528bc5dfd593064589564b64501ad7ab78 + db20b769545bd6a97f81fbe23cd1fcd5f6b88c5a - + https://github.com/dotnet/node - 547dab528bc5dfd593064589564b64501ad7ab78 + db20b769545bd6a97f81fbe23cd1fcd5f6b88c5a - + https://github.com/dotnet/node - 547dab528bc5dfd593064589564b64501ad7ab78 + db20b769545bd6a97f81fbe23cd1fcd5f6b88c5a - + https://github.com/dotnet/node - 547dab528bc5dfd593064589564b64501ad7ab78 + db20b769545bd6a97f81fbe23cd1fcd5f6b88c5a - + https://github.com/dotnet/node - 547dab528bc5dfd593064589564b64501ad7ab78 + db20b769545bd6a97f81fbe23cd1fcd5f6b88c5a https://github.com/dotnet/runtime-assets @@ -421,9 +425,9 @@ https://github.com/dotnet/runtime-assets 7d4d3d2b53b18ad0ca1826581c9710b565b44fe5 - + https://github.com/dotnet/dotnet - 813f634ceb016018f5acc9bd3c2b16e17dff4686 + 7cdb217445905f3342bbb0266a4497b9a014389a diff --git a/eng/Versions.props b/eng/Versions.props index ca9cfcae7c87ea..21e88638fc35db 100644 --- a/eng/Versions.props +++ b/eng/Versions.props @@ -128,7 +128,7 @@ 2.0.0 17.10.0-beta1.24272.1 3.1.28 - 0.2.736901 + 0.2.740901 2.1.0 2.0.3 1.0.4-preview6.19326.1 @@ -136,6 +136,7 @@ 17.11.48 17.11.48 17.11.48 + 18.7.1 17.11.48 7.0.412701 6.0 @@ -167,8 +168,6 @@ $(MicrosoftDotNetApiCompatTaskPackageVersion) - - $(MicrosoftNETCoreAppRefPackageVersion) $(runtimewinx64MicrosoftNETCoreRuntimeWasmNodeTransportPackageVersion) 6.0.2 diff --git a/eng/common/Get-GitHubAppToken.ps1 b/eng/common/Get-GitHubAppToken.ps1 new file mode 100644 index 00000000000000..6b5899d7a29925 --- /dev/null +++ b/eng/common/Get-GitHubAppToken.ps1 @@ -0,0 +1,154 @@ +# Mints a short-lived GitHub App installation access token by signing a JWT +# with a private key stored in Azure Key Vault (RSA, RS256). The signed JWT is +# exchanged with the GitHub API for a token scoped to a single installation. +# +# Requirements: +# - A GitHub App whose private key has been uploaded into Key Vault as an RSA +# key (the PEM converted to a Key Vault *key*, NOT stored as a secret). +# - The caller (the federated Azure service connection used to run this script) +# must have the `Key Vault Crypto User` role (or at minimum the `Sign` +# action) on that key. +# - The App must be installed on the target organization/account +# (`InstallationOwner`) with the permissions/repositories it needs. +# +# Installation tokens (ghs_*) are exempt from the enterprise classic-PAT +# lifetime policy, which is why this replaces the long-lived PAT. + +[CmdletBinding()] +param( + # Name of the Key Vault that holds the GitHub App's RSA signing key. + [Parameter(Mandatory = $true)] + [string] $KeyVaultName, + + # Name of the RSA key inside the Key Vault (the App's private key). + [Parameter(Mandatory = $true)] + [string] $KeyName, + + # The GitHub App's Client ID (the value to put in the `iss` JWT claim). + [Parameter(Mandatory = $true)] + [string] $AppClientId, + + # Login of the organization or user account whose installation we should + # mint the token for (e.g. `dotnet`, `microsoft`). + [Parameter(Mandatory = $true)] + [string] $InstallationOwner, + + # Optional Azure DevOps pipeline variable name to set with the installation + # token (marked as a secret). When not specified, the token is written to + # stdout instead. + [Parameter(Mandatory = $false)] + [string] $OutputVariableName +) + +$ErrorActionPreference = 'Stop' +$PSNativeCommandUseErrorActionPreference = $true + +. $PSScriptRoot\pipeline-logging-functions.ps1 + +function ConvertTo-Base64Url([byte[]] $bytes) { + return [Convert]::ToBase64String($bytes).TrimEnd('=').Replace('+', '-').Replace('/', '_') +} + +# Build JWT header and payload. Use [ordered] hashtables so JSON +# serialization is deterministic. +$jwtHeader = [ordered]@{ + alg = 'RS256' + typ = 'JWT' +} +$now = [System.DateTimeOffset]::UtcNow +$jwtPayload = [ordered]@{ + iat = $now.AddMinutes(-1).ToUnixTimeSeconds() + exp = $now.AddMinutes(5).ToUnixTimeSeconds() + iss = $AppClientId +} + +$headerEncoded = ConvertTo-Base64Url ([System.Text.Encoding]::UTF8.GetBytes(($jwtHeader | ConvertTo-Json -Compress))) +$payloadEncoded = ConvertTo-Base64Url ([System.Text.Encoding]::UTF8.GetBytes(($jwtPayload | ConvertTo-Json -Compress))) +$signingInput = "$headerEncoded.$payloadEncoded" + +# Key Vault `sign` expects the *digest* (base64), not the raw bytes. +$sha256 = [System.Security.Cryptography.SHA256]::Create() +$digestBytes = $sha256.ComputeHash([System.Text.Encoding]::UTF8.GetBytes($signingInput)) +$digestBase64 = [Convert]::ToBase64String($digestBytes) + +Write-Host "Signing JWT with key '$KeyName' in vault '$KeyVaultName'..." +$previousNativeCommandErrorPreference = $PSNativeCommandUseErrorActionPreference +try { + # Azure CLI can emit non-fatal Python warnings to stderr even when signing succeeds. + # Use the exit code to determine success for this invocation. + $PSNativeCommandUseErrorActionPreference = $false + $signatureBase64 = az keyvault key sign ` + --vault-name $KeyVaultName ` + --name $KeyName ` + --algorithm RS256 ` + --digest $digestBase64 ` + --query signature ` + --output tsv ` + --only-show-errors + $signExitCode = $LASTEXITCODE +} +catch { + Write-PipelineTelemetryError -Category 'Build' -Message "Failed to sign the JWT via Key Vault (key '$KeyName', vault '$KeyVaultName'): $_. Verify the service connection identity has the 'Key Vault Crypto User' role (Sign action) on the key." + exit 1 +} +finally { + $PSNativeCommandUseErrorActionPreference = $previousNativeCommandErrorPreference +} +if ($signExitCode -ne 0 -or [string]::IsNullOrWhiteSpace($signatureBase64)) { + Write-PipelineTelemetryError -Category 'Build' -Message "'az keyvault key sign' exited with code $signExitCode for key '$KeyName' in vault '$KeyVaultName'. Verify the service connection identity has the 'Key Vault Crypto User' role (Sign action) on the key." + exit 1 +} +$signatureUrl = $signatureBase64.Trim().TrimEnd('=').Replace('+', '-').Replace('/', '_') +$jwt = "$signingInput.$signatureUrl" + +$headers = @{ + Authorization = "Bearer $jwt" + 'X-GitHub-Api-Version' = '2022-11-28' + Accept = 'application/vnd.github+json' + 'User-Agent' = 'dotnet-arcade-onelocbuild' +} + +Write-Host "Looking up installation for '$InstallationOwner'..." +try { + $installations = @() + $page = 1 + do { + $pageInstallations = @(Invoke-RestMethod ` + -Uri "https://api.github.com/app/installations?per_page=100&page=$page" ` + -Headers $headers ` + -Method Get) + $installations += $pageInstallations + $page++ + } while ($pageInstallations.Count -eq 100) +} +catch { + Write-PipelineTelemetryError -Category 'Build' -Message "Failed to list GitHub App installations: $_. The signed JWT may be invalid or the App's Client ID ('$AppClientId') may be incorrect." + exit 1 +} +$installation = $installations | Where-Object { $_.account.login -ieq $InstallationOwner } | Select-Object -First 1 +if (-not $installation) { + $found = ($installations | ForEach-Object { $_.account.login }) -join ', ' + Write-PipelineTelemetryError -Category 'Build' -Message "No installation found for '$InstallationOwner'. App is installed on: $found" + exit 1 +} + +try { + $tokenResponse = Invoke-RestMethod ` + -Uri "https://api.github.com/app/installations/$($installation.id)/access_tokens" ` + -Headers $headers ` + -Method Post ` + -ContentType 'application/json' +} +catch { + Write-PipelineTelemetryError -Category 'Build' -Message "Failed to mint an installation access token for '$InstallationOwner' (installation $($installation.id)): $_" + exit 1 +} + +Write-Host "Got installation token for '$InstallationOwner' (expires $($tokenResponse.expires_at))." +if ($OutputVariableName) { + Write-Host "Setting pipeline variable '$OutputVariableName'." + Write-Host "##vso[task.setvariable variable=$OutputVariableName;issecret=true]$($tokenResponse.token)" +} +else { + Write-Host $tokenResponse.token -ForegroundColor Green +} diff --git a/eng/common/SetupNugetSources.ps1 b/eng/common/SetupNugetSources.ps1 index b3bddff355e7f3..b7a3769364dde4 100644 --- a/eng/common/SetupNugetSources.ps1 +++ b/eng/common/SetupNugetSources.ps1 @@ -11,7 +11,7 @@ # condition: eq(variables['Agent.OS'], 'Windows_NT') # inputs: # filePath: $(System.DefaultWorkingDirectory)/eng/common/SetupNugetSources.ps1 -# arguments: -ConfigFile $(System.DefaultWorkingDirectory)/NuGet.config -Password $Env:Token +# arguments: -ConfigFile $(System.DefaultWorkingDirectory)/NuGet.config # env: # Token: $(InternalFeedToken) # @@ -29,12 +29,14 @@ [CmdletBinding()] param ( [Parameter(Mandatory = $true)][string]$ConfigFile, - $Password + # Keep the legacy name as an alias while callers migrate secrets to the Token environment variable. + [Alias("Password")]$Credential ) $ErrorActionPreference = "Stop" Set-StrictMode -Version 2.0 [Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12 +$feedCredential = if ($env:Token) { $env:Token } else { $Credential } # This script only consumes helper functions from tools.ps1 to configure NuGet feeds. # Skip importing configure-toolset.ps1 so that repo-specific toolset setup (e.g. acquiring @@ -44,14 +46,14 @@ $disableConfigureToolsetImport = $true . $PSScriptRoot\tools.ps1 # Adds or enables the package source with the given name -function AddOrEnablePackageSource($sources, $disabledPackageSources, $SourceName, $SourceEndPoint, $creds, $Username, $pwd) { - if ($disabledPackageSources -eq $null -or -not (EnableInternalPackageSource -DisabledPackageSources $disabledPackageSources -Creds $creds -PackageSourceName $SourceName)) { - AddPackageSource -Sources $sources -SourceName $SourceName -SourceEndPoint $SourceEndPoint -Creds $creds -Username $userName -pwd $Password +function AddOrEnablePackageSource($sources, $disabledPackageSources, $SourceName, $SourceEndPoint, $creds, $Username, $credential) { + if ($disabledPackageSources -eq $null -or -not (EnableInternalPackageSource -DisabledPackageSources $disabledPackageSources -Creds $creds -PackageSourceName $SourceName -Credential $credential)) { + AddPackageSource -Sources $sources -SourceName $SourceName -SourceEndPoint $SourceEndPoint -Creds $creds -Username $Username -credential $credential } } # Add source entry to PackageSources -function AddPackageSource($sources, $SourceName, $SourceEndPoint, $creds, $Username, $pwd) { +function AddPackageSource($sources, $SourceName, $SourceEndPoint, $creds, $Username, $credential) { $packageSource = $sources.SelectSingleNode("add[@key='$SourceName']") if ($packageSource -eq $null) @@ -67,13 +69,13 @@ function AddPackageSource($sources, $SourceName, $SourceEndPoint, $creds, $Usern Write-Host "Package source $SourceName already present and enabled." } - AddCredential -Creds $creds -Source $SourceName -Username $Username -pwd $pwd + AddCredential -Creds $creds -Source $SourceName -Username $Username -credential $credential } # Add a credential node for the specified source -function AddCredential($creds, $source, $username, $pwd) { +function AddCredential($creds, $source, $username, $credential) { # If no cred supplied, don't do anything. - if (!$pwd) { + if (!$credential) { return; } @@ -108,19 +110,19 @@ function AddCredential($creds, $source, $username, $pwd) { $sourceElement.AppendChild($passwordElement) | Out-Null } - $passwordElement.SetAttribute("value", $pwd) + $passwordElement.SetAttribute("value", $credential) } # Enable all darc-int package sources. -function EnableMaestroInternalPackageSources($DisabledPackageSources, $Creds) { +function EnableMaestroInternalPackageSources($DisabledPackageSources, $Creds, $Credential) { $maestroInternalSources = $DisabledPackageSources.SelectNodes("add[contains(@key,'darc-int')]") ForEach ($DisabledPackageSource in $maestroInternalSources) { - EnableInternalPackageSource -DisabledPackageSources $DisabledPackageSources -Creds $Creds -PackageSourceName $DisabledPackageSource.key + EnableInternalPackageSource -DisabledPackageSources $DisabledPackageSources -Creds $Creds -PackageSourceName $DisabledPackageSource.key -Credential $Credential } } # Enables an internal package source by name, if found. Returns true if the package source was found and enabled, false otherwise. -function EnableInternalPackageSource($DisabledPackageSources, $Creds, $PackageSourceName) { +function EnableInternalPackageSource($DisabledPackageSources, $Creds, $PackageSourceName, $Credential) { $DisabledPackageSource = $DisabledPackageSources.SelectSingleNode("add[@key='$PackageSourceName']") if ($DisabledPackageSource) { Write-Host "Enabling internal source '$($DisabledPackageSource.key)'." @@ -128,7 +130,7 @@ function EnableInternalPackageSource($DisabledPackageSources, $Creds, $PackageSo # Due to https://github.com/NuGet/Home/issues/10291, we must actually remove the disabled entries $DisabledPackageSources.RemoveChild($DisabledPackageSource) - AddCredential -Creds $creds -Source $DisabledPackageSource.Key -Username $userName -pwd $Password + AddCredential -Creds $creds -Source $DisabledPackageSource.Key -Username $userName -credential $credential return $true } return $false @@ -153,7 +155,7 @@ if ($sources -eq $null) { $creds = $null $feedSuffix = "v3/index.json" -if ($Password) { +if ($feedCredential) { $feedSuffix = "v2" # Looks for a node. Create it if none is found. $creds = $doc.DocumentElement.SelectSingleNode("packageSourceCredentials") @@ -169,7 +171,7 @@ $userName = "dn-bot" $disabledSources = $doc.DocumentElement.SelectSingleNode("disabledPackageSources") if ($disabledSources -ne $null) { Write-Host "Checking for any darc-int disabled package sources in the disabledPackageSources node" - EnableMaestroInternalPackageSources -DisabledPackageSources $disabledSources -Creds $creds + EnableMaestroInternalPackageSources -DisabledPackageSources $disabledSources -Creds $creds -Credential $feedCredential } $dotnetVersions = @('5','6','7','8','9','10') @@ -177,8 +179,8 @@ foreach ($dotnetVersion in $dotnetVersions) { $feedPrefix = "dotnet" + $dotnetVersion; $dotnetSource = $sources.SelectSingleNode("add[@key='$feedPrefix']") if ($dotnetSource -ne $null) { - AddOrEnablePackageSource -Sources $sources -DisabledPackageSources $disabledSources -SourceName "$feedPrefix-internal" -SourceEndPoint "https://pkgs.dev.azure.com/dnceng/internal/_packaging/$feedPrefix-internal/nuget/$feedSuffix" -Creds $creds -Username $userName -pwd $Password - AddOrEnablePackageSource -Sources $sources -DisabledPackageSources $disabledSources -SourceName "$feedPrefix-internal-transport" -SourceEndPoint "https://pkgs.dev.azure.com/dnceng/internal/_packaging/$feedPrefix-internal-transport/nuget/$feedSuffix" -Creds $creds -Username $userName -pwd $Password + AddOrEnablePackageSource -Sources $sources -DisabledPackageSources $disabledSources -SourceName "$feedPrefix-internal" -SourceEndPoint "https://pkgs.dev.azure.com/dnceng/internal/_packaging/$feedPrefix-internal/nuget/$feedSuffix" -Creds $creds -Username $userName -credential $feedCredential + AddOrEnablePackageSource -Sources $sources -DisabledPackageSources $disabledSources -SourceName "$feedPrefix-internal-transport" -SourceEndPoint "https://pkgs.dev.azure.com/dnceng/internal/_packaging/$feedPrefix-internal-transport/nuget/$feedSuffix" -Creds $creds -Username $userName -credential $feedCredential } } diff --git a/eng/common/SetupNugetSources.sh b/eng/common/SetupNugetSources.sh index 67e7e0942ca14e..c3ae8ac054fe11 100755 --- a/eng/common/SetupNugetSources.sh +++ b/eng/common/SetupNugetSources.sh @@ -24,7 +24,9 @@ # This logic is also abstracted into enable-internal-sources.yml. ConfigFile=$1 -CredToken=$2 +# Prefer the environment variable so credentials do not appear in process arguments. +# Retain the positional argument as a compatibility fallback for existing callers. +CredToken=${Token:-$2} NL='\n' TB=' ' diff --git a/eng/common/build.ps1 b/eng/common/build.ps1 index dd84699f500c09..fee2f839919a52 100644 --- a/eng/common/build.ps1 +++ b/eng/common/build.ps1 @@ -8,6 +8,7 @@ Param( [bool] $warnAsError = $true, [string] $warnNotAsError = '', [bool] $nodeReuse = $true, + [bool][Alias('mt')]$msbuildMultiThreaded = $false, [switch] $buildCheck = $false, [switch][Alias('r')]$restore, [switch] $deployDeps, @@ -79,6 +80,7 @@ function Print-Usage() { Write-Host " -excludePrereleaseVS Set to exclude build engines in prerelease versions of Visual Studio" Write-Host " -nativeToolsOnMachine Sets the native tools on machine environment variable (indicating that the script should use native tools on machine)" Write-Host " -nodeReuse Sets nodereuse msbuild parameter ('true' or 'false')" + Write-Host " -msbuildMultiThreaded Sets MSBuild's multi-threaded mode, i.e. the -mt switch ('1' or '0') (short: -mt)" Write-Host " -buildCheck Sets /check msbuild parameter" Write-Host " -fromVMR Set when building from within the VMR" Write-Host " -disablePipelineSetResult Set to disable masking the actual exit code in the pipeline when the build fails" @@ -175,9 +177,8 @@ try { if (-not $excludeCIBinarylog) { $binaryLog = $true } - # Disable node reuse on CI unless explicitly opted in via MSBUILD_NODEREUSE_ENABLED. - # Internal testing only; this env var will be replaced with a switch (https://github.com/dotnet/arcade/issues/17013) and must not be depended on. - if ($env:MSBUILD_NODEREUSE_ENABLED -ne "1") { + # Node reuse isn't used on CI unless it was explicitly requested via -nodeReuse. + if (-not $PSBoundParameters.ContainsKey('nodeReuse')) { $nodeReuse = $false } } diff --git a/eng/common/build.sh b/eng/common/build.sh index e37edd6cff34ad..109d83ff73f778 100755 --- a/eng/common/build.sh +++ b/eng/common/build.sh @@ -43,6 +43,7 @@ usage() echo " --pipelinesLog Promote msbuild errors/warnings to Azure Pipelines timeline issues; defaults to on in CI (short: -pl)" echo " --prepareMachine Prepare machine for CI run, clean up processes after build" echo " --nodeReuse Sets nodereuse msbuild parameter ('true' or 'false')" + echo " --msbuildMultiThreaded Sets MSBuild's multi-threaded mode, i.e. the -mt switch ('true' or 'false') (short: --mt)" echo " --warnAsError Sets warnaserror msbuild parameter ('true' or 'false')" echo " --warnNotAsError Sets a semi-colon delimited list of warning codes that should not be treated as errors" echo " --buildCheck Sets /check msbuild parameter" @@ -84,7 +85,9 @@ clean=false warn_as_error=true warn_not_as_error='' -node_reuse=true +# Empty means "not specified"; tools.sh defaults these to on for local builds and off on CI. +node_reuse='' +msbuild_multi_threaded='' build_check=false binary_log=false binary_log_name='' @@ -199,6 +202,10 @@ while [[ $# -gt 0 ]]; do node_reuse=$2 shift ;; + -msbuildmultithreaded|-mt) + msbuild_multi_threaded=$2 + shift + ;; -buildcheck) build_check=true ;; @@ -224,11 +231,6 @@ fi if [[ "$ci" == true ]]; then pipelines_log=true - # Disable node reuse on CI unless explicitly opted in via MSBUILD_NODEREUSE_ENABLED. - # Internal testing only; this env var will be replaced with a switch (https://github.com/dotnet/arcade/issues/17013) and must not be depended on. - if [[ "${MSBUILD_NODEREUSE_ENABLED:-}" != "1" ]]; then - node_reuse=false - fi if [[ "$exclude_ci_binary_log" == false ]]; then binary_log=true fi diff --git a/eng/common/core-templates/job/helix-job-monitor.yml b/eng/common/core-templates/job/helix-job-monitor.yml index 0e92fb1f477f0c..a65b50d0a787f8 100644 --- a/eng/common/core-templates/job/helix-job-monitor.yml +++ b/eng/common/core-templates/job/helix-job-monitor.yml @@ -26,6 +26,11 @@ parameters: type: string default: '' +# Whether failures in the monitor job should allow the pipeline to continue. +- name: continueOnError + type: boolean + default: false + # NuGet package id of the Helix job monitor tool. - name: toolPackageId type: string @@ -103,6 +108,7 @@ jobs: - job: HelixJobMonitor displayName: Monitor Helix Jobs timeoutInMinutes: ${{ parameters.timeoutInMinutes }} + continueOnError: ${{ parameters.continueOnError }} ${{ if ne(length(parameters.dependsOn), 0) }}: dependsOn: ${{ parameters.dependsOn }} ${{ if ne(parameters.condition, '') }}: diff --git a/eng/common/core-templates/job/onelocbuild.yml b/eng/common/core-templates/job/onelocbuild.yml index 2816d2905a064c..4f5653d73ac76a 100644 --- a/eng/common/core-templates/job/onelocbuild.yml +++ b/eng/common/core-templates/job/onelocbuild.yml @@ -14,6 +14,15 @@ parameters: # exist, and any pipeline that sets this to '' fall back to PAT-based auth via the CeapexPat parameter. CeapexServiceConnection: 'dnceng-onelocbuild-ceapex' + # GitHub App authentication for the OneLoc check-in PR (dnceng/internal only). + # The infrastructure identifiers are centralized here and the App path is enabled by default. + # DevDiv requires its own project-scoped service connection before this path can be enabled there. + UseGitHubAppAuthentication: true + GitHubAppServiceConnection: 'dnceng-oneloc-githubapp' + GitHubAppClientId: 'Iv23lijBU8x3gc9lDOc9' + GitHubAppKeyVaultName: 'EngKeyVault' + GitHubAppKeyName: 'oneloc-localization-app-key' + SourcesDirectory: $(System.DefaultWorkingDirectory) CreatePr: true AutoCompletePr: false @@ -89,6 +98,20 @@ jobs: outputVariableName: 'CeapexEntraToken' condition: ${{ parameters.condition }} + # Mint a short-lived GitHub App installation token for the loc check-in PR (dnceng/internal only). + # All other projects fall back to PAT-based auth, since the app service connection is scoped to dnceng/internal. + - ${{ if and(eq(parameters.RepoType, 'gitHub'), eq(parameters.UseGitHubAppAuthentication, true), eq(variables['System.TeamProject'], 'internal')) }}: + - template: /eng/common/core-templates/steps/get-github-app-token.yml + parameters: + is1ESPipeline: ${{ parameters.is1ESPipeline }} + azureSubscription: ${{ parameters.GitHubAppServiceConnection }} + keyVaultName: ${{ parameters.GitHubAppKeyVaultName }} + keyName: ${{ parameters.GitHubAppKeyName }} + appClientId: ${{ parameters.GitHubAppClientId }} + installationOwner: ${{ parameters.GitHubOrg }} + outputVariableName: 'GitHubAppInstallationToken' + condition: ${{ parameters.condition }} + - task: OneLocBuild@2 displayName: OneLocBuild env: @@ -110,7 +133,10 @@ jobs: patVariable: ${{ parameters.CeapexPat }} ${{ if eq(parameters.RepoType, 'gitHub') }}: repoType: ${{ parameters.RepoType }} - gitHubPatVariable: "${{ parameters.GithubPat }}" + ${{ if and(eq(parameters.UseGitHubAppAuthentication, true), eq(variables['System.TeamProject'], 'internal')) }}: + gitHubPatVariable: "$(GitHubAppInstallationToken)" + ${{ if or(eq(parameters.UseGitHubAppAuthentication, false), ne(variables['System.TeamProject'], 'internal')) }}: + gitHubPatVariable: "${{ parameters.GithubPat }}" ${{ if ne(parameters.MirrorRepo, '') }}: isMirrorRepoSelected: true gitHubOrganization: ${{ parameters.GitHubOrg }} diff --git a/eng/common/core-templates/job/publish-build-assets.yml b/eng/common/core-templates/job/publish-build-assets.yml index 4229288d3d38a2..330225ae09385a 100644 --- a/eng/common/core-templates/job/publish-build-assets.yml +++ b/eng/common/core-templates/job/publish-build-assets.yml @@ -58,8 +58,6 @@ jobs: parameters: is1ESPipeline: ${{ parameters.is1ESPipeline }} - ${{ if and(eq(parameters.runAsPublic, 'false'), ne(variables['System.TeamProject'], 'public'), notin(variables['Build.Reason'], 'PullRequest')) }}: - - group: Publish-Build-Assets - - group: AzureDevOps-Artifact-Feeds-Pats - name: runCodesignValidationInjection value: false # unconditional - needed for logs publishing (redactor tool version) diff --git a/eng/common/core-templates/post-build/common-variables.yml b/eng/common/core-templates/post-build/common-variables.yml index db298ae16bae64..a3a8480e254abb 100644 --- a/eng/common/core-templates/post-build/common-variables.yml +++ b/eng/common/core-templates/post-build/common-variables.yml @@ -1,6 +1,4 @@ variables: - - group: Publish-Build-Assets - # Whether the build is internal or not - name: IsInternalBuild value: ${{ and(ne(variables['System.TeamProject'], 'public'), contains(variables['Build.SourceBranch'], 'internal')) }} diff --git a/eng/common/core-templates/stages/renovate.yml b/eng/common/core-templates/stages/renovate.yml index edab2818258573..cfa9683794ad3d 100644 --- a/eng/common/core-templates/stages/renovate.yml +++ b/eng/common/core-templates/stages/renovate.yml @@ -81,6 +81,8 @@ resources: extends: template: v1/1ES.Official.PipelineTemplate.yml@1ESPipelineTemplates parameters: + settings: + networkIsolationPolicy: Permissive pool: ${{ parameters.pool }} sdl: sourceAnalysisPool: ${{ parameters.sdlPool }} diff --git a/eng/common/core-templates/steps/enable-internal-sources.yml b/eng/common/core-templates/steps/enable-internal-sources.yml index 51af9a017091ff..843cdff7821e67 100644 --- a/eng/common/core-templates/steps/enable-internal-sources.yml +++ b/eng/common/core-templates/steps/enable-internal-sources.yml @@ -19,7 +19,7 @@ steps: displayName: Setup Internal Feeds inputs: filePath: $(System.DefaultWorkingDirectory)/eng/common/SetupNugetSources.ps1 - arguments: -ConfigFile $(System.DefaultWorkingDirectory)/NuGet.config -Password $Env:Token + arguments: -ConfigFile $(System.DefaultWorkingDirectory)/NuGet.config env: Token: ${{ parameters.legacyCredential }} - task: Bash@3 @@ -28,7 +28,7 @@ steps: inputs: targetType: inline script: | - "$(System.DefaultWorkingDirectory)/eng/common/SetupNugetSources.sh" "$(System.DefaultWorkingDirectory)/NuGet.config" "$Token" + "$(System.DefaultWorkingDirectory)/eng/common/SetupNugetSources.sh" "$(System.DefaultWorkingDirectory)/NuGet.config" env: Token: ${{ parameters.legacyCredential }} # If running on dnceng (internal project), just use the default behavior for NuGetAuthenticate. @@ -58,13 +58,17 @@ steps: displayName: Setup Internal Feeds inputs: filePath: $(System.DefaultWorkingDirectory)/eng/common/SetupNugetSources.ps1 - arguments: -ConfigFile $(System.DefaultWorkingDirectory)/NuGet.config -Password $(dnceng-artifacts-feeds-read-access-token) + arguments: -ConfigFile $(System.DefaultWorkingDirectory)/NuGet.config + env: + Token: $(dnceng-artifacts-feeds-read-access-token) - task: Bash@3 condition: and(succeeded(), ne(variables['Agent.Os'], 'Windows_NT')) displayName: Setup Internal Feeds inputs: filePath: $(System.DefaultWorkingDirectory)/eng/common/SetupNugetSources.sh - arguments: $(System.DefaultWorkingDirectory)/NuGet.config $(dnceng-artifacts-feeds-read-access-token) + arguments: $(System.DefaultWorkingDirectory)/NuGet.config + env: + Token: $(dnceng-artifacts-feeds-read-access-token) # This is required in certain scenarios to install the ADO credential provider. # It installed by default in some msbuild invocations (e.g. VS msbuild), but needs to be installed for others # (e.g. dotnet msbuild). diff --git a/eng/common/core-templates/steps/get-github-app-token.yml b/eng/common/core-templates/steps/get-github-app-token.yml new file mode 100644 index 00000000000000..6d42a48d3c3671 --- /dev/null +++ b/eng/common/core-templates/steps/get-github-app-token.yml @@ -0,0 +1,79 @@ +# Mints a short-lived GitHub App installation access token by signing a JWT +# with a private key stored in Azure Key Vault (RSA, RS256). The JWT is +# exchanged with the GitHub API for a token scoped to a single installation. +# +# Requirements (per GitHub App you want to authenticate as): +# - A GitHub App with its private key uploaded into Key Vault as an RSA key +# (PEM converted to a key, NOT stored as a secret). +# - The Azure service connection passed via `azureSubscription` must be +# granted the `Key Vault Crypto User` role (or at minimum `Sign` action) +# on that key. +# - The App must be installed on the target organization/account +# (`installationOwner`) with the permissions/repositories you need. +# +# Output: a secret pipeline variable named ${{ parameters.outputVariableName }} +# containing the installation access token. Token lifetime is ~1 hour and is +# automatically scrubbed from logs. Installation tokens are exempt from the +# enterprise classic-PAT lifetime policy. + +parameters: +# Azure DevOps service connection (federated) that can call +# `az keyvault key sign` on the App's signing key. +- name: azureSubscription + type: string + +# Name of the Key Vault that holds the GitHub App's RSA signing key. +- name: keyVaultName + type: string + +# Name of the RSA key inside the Key Vault (the App's private key). +- name: keyName + type: string + +# The GitHub App's Client ID (the value to put in the `iss` JWT claim). +# Prefer this over the numeric App ID; GitHub accepts either, but Client ID +# is the documented form going forward. +- name: appClientId + type: string + +# Login of the organization or user account whose installation we should +# mint the token for (e.g. `dotnet`, `microsoft`). +- name: installationOwner + type: string + +# Name of the pipeline variable that will receive the installation token. +- name: outputVariableName + type: string + +- name: is1ESPipeline + type: boolean + +- name: stepName + type: string + default: getGitHubAppInstallationToken + +- name: condition + type: string + default: '' + +- name: displayName + type: string + default: Get GitHub App installation token + +steps: +- task: AzureCLI@2 + displayName: ${{ parameters.displayName }} + name: ${{ parameters.stepName }} + ${{ if ne(parameters.condition, '') }}: + condition: ${{ parameters.condition }} + inputs: + azureSubscription: ${{ parameters.azureSubscription }} + scriptType: pscore + scriptLocation: inlineScript + inlineScript: | + & "$(System.DefaultWorkingDirectory)/eng/common/Get-GitHubAppToken.ps1" ` + -KeyVaultName '${{ parameters.keyVaultName }}' ` + -KeyName '${{ parameters.keyName }}' ` + -AppClientId '${{ parameters.appClientId }}' ` + -InstallationOwner '${{ parameters.installationOwner }}' ` + -OutputVariableName '${{ parameters.outputVariableName }}' diff --git a/eng/common/core-templates/steps/publish-logs.yml b/eng/common/core-templates/steps/publish-logs.yml index c496f3d0dc7a01..2c1e0ab11620c7 100644 --- a/eng/common/core-templates/steps/publish-logs.yml +++ b/eng/common/core-templates/steps/publish-logs.yml @@ -30,8 +30,6 @@ steps: -TokensFilePath '$(System.DefaultWorkingDirectory)/eng/BinlogSecretsRedactionFile.txt' -runtimeSourceFeed https://ci.dot.net/internal -runtimeSourceFeedKey '$(dotnetbuilds-internal-container-read-token-base64)' - '$(publishing-dnceng-devdiv-code-r-build-re)' - '$(akams-client-id)' '$(System.AccessToken)' ${{parameters.CustomSensitiveDataList}} continueOnError: true @@ -56,4 +54,3 @@ steps: condition: always() retryCountOnTaskFailure: 10 # for any files being locked isProduction: false # logs are non-production artifacts - diff --git a/eng/common/msbuild.ps1 b/eng/common/msbuild.ps1 index 495d533a909828..b6dfb570ea50e0 100644 --- a/eng/common/msbuild.ps1 +++ b/eng/common/msbuild.ps1 @@ -3,6 +3,7 @@ Param( [string] $verbosity = 'minimal', [bool] $warnAsError = $true, [bool] $nodeReuse = $true, + [bool][Alias('mt')]$msbuildMultiThreaded = $false, [switch] $ci, [switch] $prepareMachine, [switch] $excludePrereleaseVS, @@ -13,12 +14,9 @@ Param( . $PSScriptRoot\tools.ps1 try { - if ($ci) { - # Disable node reuse on CI unless explicitly opted in via MSBUILD_NODEREUSE_ENABLED. - # Internal testing only; this env var will be replaced with a switch (https://github.com/dotnet/arcade/issues/17013) and must not be depended on. - if ($env:MSBUILD_NODEREUSE_ENABLED -ne "1") { - $nodeReuse = $false - } + # Node reuse isn't used on CI unless it was explicitly requested via -nodeReuse. + if ($ci -and -not $PSBoundParameters.ContainsKey('nodeReuse')) { + $nodeReuse = $false } MSBuild @extraArgs diff --git a/eng/common/msbuild.sh b/eng/common/msbuild.sh index 333be3232fcf82..a40c101237b1aa 100755 --- a/eng/common/msbuild.sh +++ b/eng/common/msbuild.sh @@ -14,7 +14,9 @@ scriptroot="$( cd -P "$( dirname "$source" )" && pwd )" verbosity='minimal' warn_as_error=true -node_reuse=true +# Empty means "not specified"; tools.sh defaults these to on for local builds and off on CI. +node_reuse='' +msbuild_multi_threaded='' prepare_machine=false extra_args='' @@ -33,6 +35,10 @@ while (($# > 0)); do node_reuse=$2 shift 2 ;; + --msbuildmultithreaded|--mt) + msbuild_multi_threaded=$2 + shift 2 + ;; --ci) ci=true shift 1 @@ -50,13 +56,5 @@ done . "$scriptroot/tools.sh" -if [[ "$ci" == true ]]; then - # Disable node reuse on CI unless explicitly opted in via MSBUILD_NODEREUSE_ENABLED. - # Internal testing only; this env var will be replaced with a switch (https://github.com/dotnet/arcade/issues/17013) and must not be depended on. - if [[ "${MSBUILD_NODEREUSE_ENABLED:-}" != "1" ]]; then - node_reuse=false - fi -fi - MSBuild $extra_args ExitWithExitCode 0 diff --git a/eng/common/templates-official/steps/get-github-app-token.yml b/eng/common/templates-official/steps/get-github-app-token.yml new file mode 100644 index 00000000000000..c89f3641a4dbe0 --- /dev/null +++ b/eng/common/templates-official/steps/get-github-app-token.yml @@ -0,0 +1,7 @@ +steps: +- template: /eng/common/core-templates/steps/get-github-app-token.yml + parameters: + is1ESPipeline: true + + ${{ each parameter in parameters }}: + ${{ parameter.key }}: ${{ parameter.value }} diff --git a/eng/common/templates/steps/get-github-app-token.yml b/eng/common/templates/steps/get-github-app-token.yml new file mode 100644 index 00000000000000..79e182c64167af --- /dev/null +++ b/eng/common/templates/steps/get-github-app-token.yml @@ -0,0 +1,7 @@ +steps: +- template: /eng/common/core-templates/steps/get-github-app-token.yml + parameters: + is1ESPipeline: false + + ${{ each parameter in parameters }}: + ${{ parameter.key }}: ${{ parameter.value }} diff --git a/eng/common/tools.ps1 b/eng/common/tools.ps1 index da07386ff1fe6c..e84033dad90c93 100644 --- a/eng/common/tools.ps1 +++ b/eng/common/tools.ps1 @@ -31,11 +31,16 @@ # Set to true to reuse msbuild nodes. Recommended to not reuse on CI. [bool]$nodeReuse = if (Test-Path variable:nodeReuse) { $nodeReuse } else { !$ci } +# Set to true to build with MSBuild's multi-threaded mode (-mt). Opt-in for now, so off unless it was +# explicitly requested. It's intended to become the default for local builds once it has proven out. +[bool]$msbuildMultiThreaded = if (Test-Path variable:msbuildMultiThreaded) { $msbuildMultiThreaded } else { $false } + # Configures warning treatment in msbuild. [bool]$warnAsError = if (Test-Path variable:warnAsError) { $warnAsError } else { $true } # Specifies semi-colon delimited list of warning codes that should not be treated as errors. -[string]$warnNotAsError = if (Test-Path variable:warnNotAsError) { $warnNotAsError } else { '' } +# Defaults to NuGet Audit warning codes NU1901-NU1904. +[string]$warnNotAsError = if ((Test-Path variable:warnNotAsError) -and $warnNotAsError) { $warnNotAsError } else { 'NU1901;NU1902;NU1903;NU1904' } # Specifies which msbuild engine to use for build: 'vs', 'dotnet' or unspecified (determined based on presence of tools.vs in global.json). [string]$msbuildEngine = if (Test-Path variable:msbuildEngine) { $msbuildEngine } else { $null } @@ -808,8 +813,8 @@ function MSBuild() { $cmdArgs = "$($buildTool.Command) /m /nologo /clp:Summary /v:$verbosity /nr:$nodeReuse /p:ContinuousIntegrationBuild=$ci" - # Add -mt flag for MSBuild multithreaded mode if enabled via environment variable - if ($env:MSBUILD_MT_ENABLED -eq "1") { + # Build with MSBuild's multi-threaded mode. + if ($msbuildMultiThreaded) { $cmdArgs += ' -mt' } diff --git a/eng/common/tools.sh b/eng/common/tools.sh index 20f791c11dee0b..4d14b100b06388 100755 --- a/eng/common/tools.sh +++ b/eng/common/tools.sh @@ -1,5 +1,15 @@ #!/usr/bin/env bash +# Normalizes the value of a boolean build argument. Accepts 1/0 in addition to true/false so that +# the same value works with the PowerShell scripts, whose [bool] parameters only bind 1/0. +function NormalizeBoolArg { + case "${1:-}" in + 1) echo true ;; + 0) echo false ;; + *) echo "${1:-}" ;; + esac +} + # Initialize variables if they aren't already defined. # CI mode - set to true on CI server for PR validation build or official build. @@ -43,17 +53,25 @@ restore=${restore:-true} verbosity=${verbosity:-'minimal'} # Set to true to reuse msbuild nodes. Recommended to not reuse on CI. +node_reuse=$(NormalizeBoolArg "${node_reuse:-}") if [[ "$ci" == true ]]; then node_reuse=${node_reuse:-false} else node_reuse=${node_reuse:-true} fi +# Set to true to build with MSBuild's multi-threaded mode (-mt). Opt-in for now, so off unless it was +# explicitly requested. It's intended to become the default for local builds once it has proven out. +msbuild_multi_threaded=$(NormalizeBoolArg "${msbuild_multi_threaded:-}") +msbuild_multi_threaded=${msbuild_multi_threaded:-false} + # Configures warning treatment in msbuild. +warn_as_error=$(NormalizeBoolArg "${warn_as_error:-}") warn_as_error=${warn_as_error:-true} # Specifies semi-colon delimited list of warning codes that should not be treated as errors. -warn_not_as_error=${warn_not_as_error:-''} +# Defaults to NuGet Audit warning codes NU1901-NU1904. +warn_not_as_error="${warn_not_as_error:-NU1901;NU1902;NU1903;NU1904}" # True to attempt using .NET Core already that meets requirements specified in global.json # installed on the machine instead of downloading one. @@ -587,9 +605,9 @@ function MSBuild { } } - # Add -mt flag for MSBuild multithreaded mode if enabled via environment variable + # Build with MSBuild's multi-threaded mode. local mt_switch="" - if [[ "${MSBUILD_MT_ENABLED:-}" == "1" ]]; then + if [[ "$msbuild_multi_threaded" == true ]]; then mt_switch="-mt" fi diff --git a/eng/native/version/_version.c b/eng/native/version/_version.c index 48db7a434af794..1d37db484b0f76 100644 --- a/eng/native/version/_version.c +++ b/eng/native/version/_version.c @@ -1,7 +1,7 @@ // Licensed to the .NET Foundation under one or more agreements. // The .NET Foundation licenses this file to you under the MIT license. -#if defined(__GNUC__) && !defined(__clang__) && defined(TARGET_SUNOS) && defined(TARGET_AMD64) +#if defined(__GNUC__) && !defined(__clang__) && defined(__sun) && defined(__x86_64__) char sccsid[] __attribute__((used, weak)) = "@(#)No version information produced"; __asm__(".pushsection .init_array; .reloc ., R_X86_64_NONE, sccsid; .popsection"); #else diff --git a/global.json b/global.json index da838abda3a7fe..2e097b75ffe736 100644 --- a/global.json +++ b/global.json @@ -13,11 +13,11 @@ "dotnet": "11.0.100-preview.6.26359.118" }, "msbuild-sdks": { - "Microsoft.DotNet.Arcade.Sdk": "11.0.0-beta.26379.102", - "Microsoft.DotNet.Helix.Sdk": "11.0.0-beta.26381.1", - "Microsoft.DotNet.SharedFramework.Sdk": "11.0.0-beta.26379.102", + "Microsoft.DotNet.Arcade.Sdk": "11.0.0-beta.26411.119", + "Microsoft.DotNet.Helix.Sdk": "11.0.0-beta.26411.119", + "Microsoft.DotNet.SharedFramework.Sdk": "11.0.0-beta.26411.119", "Microsoft.Build.NoTargets": "3.7.0", "Microsoft.Build.Traversal": "3.4.0", - "Microsoft.NET.Sdk.IL": "11.0.0-rc.1.26379.102" + "Microsoft.NET.Sdk.IL": "11.0.0-rc.1.26411.119" } } diff --git a/src/libraries/System.Runtime.InteropServices/tests/LibraryImportGenerator.UnitTests/ConvertToLibraryImportFixerTests.cs b/src/libraries/System.Runtime.InteropServices/tests/LibraryImportGenerator.UnitTests/ConvertToLibraryImportFixerTests.cs index ccff8deaedfb15..77394fb396b111 100644 --- a/src/libraries/System.Runtime.InteropServices/tests/LibraryImportGenerator.UnitTests/ConvertToLibraryImportFixerTests.cs +++ b/src/libraries/System.Runtime.InteropServices/tests/LibraryImportGenerator.UnitTests/ConvertToLibraryImportFixerTests.cs @@ -1273,13 +1273,11 @@ partial class Test partial class Test { [LibraryImport("DoesNotExist")] - public static {|CS9388:safe|} partial void {|CS8795:Method|}(); + public static safe partial void {|CS8795:Method|}(); } """; - // The fixer test does not run the generator, so the `extern` implementing part that makes `safe` - // legal on this declaration is missing, the same way the implementation itself is (CS8795). await VerifyCodeFixAsync(source, fixedSource, updatedMemorySafetyRules: true); } diff --git a/src/mono/CMakeLists.txt b/src/mono/CMakeLists.txt index b71def00903dd2..0a83beb8f502e7 100644 --- a/src/mono/CMakeLists.txt +++ b/src/mono/CMakeLists.txt @@ -865,7 +865,7 @@ if(CMAKE_HOST_SYSTEM_NAME STREQUAL "Windows") else() if(NOT EXISTS "${VERSION_FILE_PATH}") file(WRITE "${VERSION_FILE_PATH}" - "#if defined(__GNUC__) && !defined(__clang__) && defined(TARGET_SUNOS) && defined(TARGET_AMD64)\n" + "#if defined(__GNUC__) && !defined(__clang__) && defined(__sun) && defined(__x86_64__)\n" "char sccsid[] __attribute__((used, weak)) = \"@(#)Version 42.42.42.42424 @Commit: AAA\";\n" "__asm__(\".pushsection .init_array; .reloc ., R_X86_64_NONE, sccsid; .popsection\");\n" "#else\n" diff --git a/src/mono/browser/README.md b/src/mono/browser/README.md index df9b4bfd8f767b..217c1e6311e936 100644 --- a/src/mono/browser/README.md +++ b/src/mono/browser/README.md @@ -258,7 +258,8 @@ Bumping Emscripten version involves these steps: * bump emscripten in https://github.com/dotnet/emsdk * bump docker images in https://github.com/dotnet/icu, update emscripten files in eng/patches/ * update version number in docs -* update `Microsoft.NET.Runtime.Emscripten..Node.win-x64` package name, version and sha hash in https://github.com/dotnet/runtime/blob/main/eng/Version.Details.xml and in https://github.com/dotnet/runtime/blob/main/eng/Versions.props. the sha is the commit hash in https://github.com/dotnet/emsdk and the package version can be found at https://dev.azure.com/dnceng/public/_packaging?_a=feed&feed=dotnet6 +* bump `EmsdkVersion` in https://github.com/dotnet/runtime/blob/main/eng/Versions.props +* update the version and sha hash of the `Microsoft.NET.Runtime.Emscripten.Internal` dependency in https://github.com/dotnet/runtime/blob/main/eng/Version.Details.xml. The sha is the commit hash in https://github.com/dotnet/emsdk and the package version can be found at https://dev.azure.com/dnceng/public/_packaging?_a=feed&feed=dotnet6. That package carries no files, it only tracks the version of the emsdk packages, whose own IDs contain the Emscripten version and the RID. * update packages in the workload manifest https://github.com/dotnet/runtime/blob/main/src/mono/nuget/Microsoft.NET.Workload.Mono.Toolchain.Current.Manifest/WorkloadManifest.json.in ## Upgrading NPM packages diff --git a/src/mono/mono/mini/llvm-intrinsics.h b/src/mono/mono/mini/llvm-intrinsics.h index 47b706297e06d2..848ef32a64bf82 100644 --- a/src/mono/mono/mini/llvm-intrinsics.h +++ b/src/mono/mono/mini/llvm-intrinsics.h @@ -116,10 +116,10 @@ INTRINS(BZHI_I32, x86_bmi_bzhi_32, X86) INTRINS(BZHI_I64, x86_bmi_bzhi_64, X86) INTRINS(BEXTR_I32, x86_bmi_bextr_32, X86) INTRINS(BEXTR_I64, x86_bmi_bextr_64, X86) -INTRINS(PEXT_I32, x86_bmi_pext_32, X86) -INTRINS(PEXT_I64, x86_bmi_pext_64, X86) -INTRINS(PDEP_I32, x86_bmi_pdep_32, X86) -INTRINS(PDEP_I64, x86_bmi_pdep_64, X86) +INTRINS_OVR(PEXT_I32, pext, Generic, LLVMInt32Type ()) +INTRINS_OVR(PEXT_I64, pext, Generic, LLVMInt64Type ()) +INTRINS_OVR(PDEP_I32, pdep, Generic, LLVMInt32Type ()) +INTRINS_OVR(PDEP_I64, pdep, Generic, LLVMInt64Type ()) INTRINS_OVR(SIMD_SQRT_R8, sqrt, Generic, sse_r8_t) INTRINS_OVR(SIMD_SQRT_R4, sqrt, Generic, sse_r4_t) diff --git a/src/tools/hotreload-delta-gen/Microsoft.DotNet.HotReload.Utils.Generator/Microsoft.DotNet.HotReload.Utils.Generator.csproj b/src/tools/hotreload-delta-gen/Microsoft.DotNet.HotReload.Utils.Generator/Microsoft.DotNet.HotReload.Utils.Generator.csproj index 9cdcb16066e2be..7730f5621fda8e 100644 --- a/src/tools/hotreload-delta-gen/Microsoft.DotNet.HotReload.Utils.Generator/Microsoft.DotNet.HotReload.Utils.Generator.csproj +++ b/src/tools/hotreload-delta-gen/Microsoft.DotNet.HotReload.Utils.Generator/Microsoft.DotNet.HotReload.Utils.Generator.csproj @@ -7,7 +7,7 @@ - + diff --git a/src/tools/illink/src/ILLink.CodeFix/Resources.resx b/src/tools/illink/src/ILLink.CodeFix/Resources.resx index b57478c2c8d08b..4753064074d672 100644 --- a/src/tools/illink/src/ILLink.CodeFix/Resources.resx +++ b/src/tools/illink/src/ILLink.CodeFix/Resources.resx @@ -132,6 +132,9 @@ Mark extern member 'unsafe' + + Mark member 'safe' + Mark documented member 'safe' diff --git a/src/tools/illink/src/ILLink.CodeFix/UnsafeModifierCodeFixHelpers.cs b/src/tools/illink/src/ILLink.CodeFix/UnsafeModifierCodeFixHelpers.cs index 501226003d9c61..7320b3169b78a9 100644 --- a/src/tools/illink/src/ILLink.CodeFix/UnsafeModifierCodeFixHelpers.cs +++ b/src/tools/illink/src/ILLink.CodeFix/UnsafeModifierCodeFixHelpers.cs @@ -27,8 +27,8 @@ internal static class UnsafeModifierCodeFixHelpers /// Registers an add-unsafe action for a supported declaration that has no existing safety modifier. /// /// - /// A declaration that documents why it is safe gets safe instead, so an audited member does not - /// become caller-unsafe and force its callers into unsafe contexts. + /// A destructor or a declaration that documents why it is safe gets safe instead, so the fixer does + /// not add a meaningless unsafe modifier or force callers of an audited member into unsafe contexts. /// internal static async Task RegisterAddUnsafeCodeFixAsync( CodeFixContext context, @@ -51,15 +51,21 @@ internal static async Task RegisterAddUnsafeCodeFixAsync( return; } - SyntaxKind modifier = SyntaxKind.UnsafeKeyword; + bool hasSafetyDocumentation = UnsafeMigrationSyntaxHelpers.HasSafetyDocumentation(declaration); + bool useSafeModifier = UnsafeMigrationSyntaxHelpers.SafeKeywordKind != SyntaxKind.None + && (declaration is DestructorDeclarationSyntax || hasSafetyDocumentation); + SyntaxKind modifier = useSafeModifier + ? UnsafeMigrationSyntaxHelpers.SafeKeywordKind + : SyntaxKind.UnsafeKeyword; string title = codeFixTitle.ToString(); string displayTitle = title; - if (UnsafeMigrationSyntaxHelpers.SafeKeywordKind != SyntaxKind.None - && UnsafeMigrationSyntaxHelpers.HasSafetyDocumentation(declaration)) + if (useSafeModifier) { - modifier = UnsafeMigrationSyntaxHelpers.SafeKeywordKind; + string resourceName = hasSafetyDocumentation + ? nameof(Resources.AddSafeToDocumentedMemberCodeFixTitle) + : nameof(Resources.AddSafeCodeFixTitle); displayTitle = new LocalizableResourceString( - nameof(Resources.AddSafeToDocumentedMemberCodeFixTitle), + resourceName, Resources.ResourceManager, typeof(Resources)).ToString(); } diff --git a/src/tools/illink/test/ILLink.RoslynAnalyzer.Tests/AddUnsafeToExternCodeFixTests.cs b/src/tools/illink/test/ILLink.RoslynAnalyzer.Tests/AddUnsafeToExternCodeFixTests.cs index 68a27088147b9f..bc47f0ad877849 100644 --- a/src/tools/illink/test/ILLink.RoslynAnalyzer.Tests/AddUnsafeToExternCodeFixTests.cs +++ b/src/tools/illink/test/ILLink.RoslynAnalyzer.Tests/AddUnsafeToExternCodeFixTests.cs @@ -128,7 +128,7 @@ class C """ class C { - extern unsafe ~C(); + extern safe ~C(); } """ }, diff --git a/src/tools/illink/test/ILLink.RoslynAnalyzer.Tests/RemoveUndocumentedUnsafeCodeFixTests.cs b/src/tools/illink/test/ILLink.RoslynAnalyzer.Tests/RemoveUndocumentedUnsafeCodeFixTests.cs index da6523059cc265..e7d524e1ee154c 100644 --- a/src/tools/illink/test/ILLink.RoslynAnalyzer.Tests/RemoveUndocumentedUnsafeCodeFixTests.cs +++ b/src/tools/illink/test/ILLink.RoslynAnalyzer.Tests/RemoveUndocumentedUnsafeCodeFixTests.cs @@ -46,6 +46,7 @@ class C public int P { {|IL5005:unsafe|} get => 0; + set { } } } """; @@ -55,6 +56,7 @@ class C public int P { get => 0; + set { } } } """; diff --git a/src/tools/illink/test/ILLink.RoslynAnalyzer.Tests/RequiresUnsafeCodeFixTests.cs b/src/tools/illink/test/ILLink.RoslynAnalyzer.Tests/RequiresUnsafeCodeFixTests.cs index aab096802e3cf5..01d24e40ad734d 100644 --- a/src/tools/illink/test/ILLink.RoslynAnalyzer.Tests/RequiresUnsafeCodeFixTests.cs +++ b/src/tools/illink/test/ILLink.RoslynAnalyzer.Tests/RequiresUnsafeCodeFixTests.cs @@ -329,7 +329,7 @@ public async Task CodeFix_InsideUnsafeClass() var test = """ using System.Diagnostics.CodeAnalysis; - public unsafe class C + public class C { public static unsafe int M1() => 0; @@ -343,7 +343,7 @@ public void M2() var fixedSource = """ using System.Diagnostics.CodeAnalysis; - public unsafe class C + public class C { public static unsafe int M1() => 0; diff --git a/src/tools/illink/test/ILLink.RoslynAnalyzer.Tests/UnsafeMemberMissingSafetyDocumentationAnalyzerTests.cs b/src/tools/illink/test/ILLink.RoslynAnalyzer.Tests/UnsafeMemberMissingSafetyDocumentationAnalyzerTests.cs index 35559d26bab9e7..0548ba1345d389 100644 --- a/src/tools/illink/test/ILLink.RoslynAnalyzer.Tests/UnsafeMemberMissingSafetyDocumentationAnalyzerTests.cs +++ b/src/tools/illink/test/ILLink.RoslynAnalyzer.Tests/UnsafeMemberMissingSafetyDocumentationAnalyzerTests.cs @@ -93,6 +93,7 @@ public unsafe partial void Partial() { } public int Accessor { unsafe get => 0; + set { } } public void Outer() @@ -114,8 +115,8 @@ public async Task IgnoresDeclarationsThatCannotExposeUnsafeContracts() var source = """ class C { - static unsafe C() { } - unsafe ~C() { } + static {|CS9377:unsafe|} C() { } + {|CS9377:unsafe|} ~C() { } } """;