Conversation
* Enhance resource management for connection strings Introduces the `IResourceWithoutLifetime` interface for resources without a lifetime, such as parameters and connection strings. Updates `ParameterResource` to implement this interface and adds the `ConnectionStringParameterResource` class for better management of connection string parameters. Implements the `AddConnectionString` method in `ConnectionStringBuilderExtensions` and updates `ApplicationOrchestrator` to handle resources without a lifetime correctly. Tests have been added and modified to verify the new functionality, and `Program.cs` has been updated to demonstrate the new connection string capabilities, including the addition of a second connection string with a parameter value. These changes improve the overall resource management in the application, particularly for connection strings and parameters. Add support for waiting on referenced resources in connection strings
* [ci] Remove codecoverage from the pipeline as it is not being used * Remove unneeded MinCodeCoverage property * Remove ProjectStaging.targets * remove more code coverage report references * fix build * address review feedback from @ eerhardt
`##[error]1. Credential Scanner Error CSCAN-MSFT0090 - File: tests/Aspire.Hosting.MySql.Tests/MySqlFunctionalTests.cs. Line: 483. Column 1. ` `##[error]2. Credential Scanner Error CSCAN-MSFT0090 - File: tests/Aspire.Hosting.MySql.Tests/MySqlFunctionalTests.cs. Line: 491. Column 1.` Fixes microsoft#7855 .
* WIP: handling orphan apphost. * Rename dummy process to stub process. * Test AppHost behavior via TestDistributedApplicationBuilder. * Remove redundant argument for now. * Remove random console write used for debugging. * Moved time provider to be an injected parameter.
…age (microsoft#7864) * Include Aspire.Hosting.Analyzers in Aspire.Hosting.AppHost nuget package This was broken when the Aspire.Hosting.AppHost package multi-targeted to net8 and net9. The AnalyzerAssemblyPath was no longer being populated in the multi-targeted build. The fix is to explicitly get the TargetPath from the Analyzer project and use it to add to the analyzers folder. * PR feedback
* Use Kafbat/kafkaui * Update src/Aspire.Hosting.Kafka/KafkaContainerImageTags.cs Co-authored-by: Alireza Baloochi <alireza.baloochi1380@gmail.com> * Update src/Aspire.Hosting.Kafka/KafkaContainerImageTags.cs Co-authored-by: Alireza Baloochi <alireza.baloochi1380@gmail.com> --------- Co-authored-by: Alireza Baloochi <alireza.baloochi1380@gmail.com>
…ft#7789) * Support processing --useHttps flag on Functions applications * Fix test
Bumps the azure group with 3 updates: [Microsoft.Azure.Cosmos](https://github.com/Azure/azure-cosmos-dotnet-v3), [Microsoft.Azure.Functions.Worker.Sdk](https://github.com/Azure/azure-functions-dotnet-worker) and [Microsoft.Azure.AppConfiguration.AspNetCore](https://github.com/Azure/Azconfig-DotnetProvider). Updates `Microsoft.Azure.Cosmos` from 3.47.1 to 3.47.2 - [Release notes](https://github.com/Azure/azure-cosmos-dotnet-v3/releases) - [Changelog](https://github.com/Azure/azure-cosmos-dotnet-v3/blob/master/changelog.md) - [Commits](https://github.com/Azure/azure-cosmos-dotnet-v3/commits) Updates `Microsoft.Azure.Functions.Worker.Sdk` from 2.0.0 to 2.0.1 - [Release notes](https://github.com/Azure/azure-functions-dotnet-worker/releases) - [Changelog](https://github.com/Azure/azure-functions-dotnet-worker/blob/main/release_notes.md) - [Commits](Azure/azure-functions-dotnet-worker@2.0.0...http-aspnetcore-extension-2.0.1) Updates `Microsoft.Azure.AppConfiguration.AspNetCore` from 8.0.0 to 8.1.1 - [Release notes](https://github.com/Azure/Azconfig-DotnetProvider/releases) - [Commits](Azure/AppConfiguration-DotnetProvider@8.0.0...8.1.1) --- updated-dependencies: - dependency-name: Microsoft.Azure.Cosmos dependency-type: direct:production update-type: version-update:semver-patch dependency-group: azure - dependency-name: Microsoft.Azure.Functions.Worker.Sdk dependency-type: direct:production update-type: version-update:semver-patch dependency-group: azure - dependency-name: Microsoft.Azure.AppConfiguration.AspNetCore dependency-type: direct:production update-type: version-update:semver-minor dependency-group: azure ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* Add 9.2 option to templates * Remove 9.0 option from templates
Based on feedback from @ russkie .
* Fix Aspire CLI test failures on Windows. * Typo. * Use TCS * Run async continuations.
…: Build ID 2654685 (microsoft#7853) * Localized file check-in by OneLocBuild Task: Build definition ID 1309: Build ID 2653960 * Localized file check-in by OneLocBuild Task: Build definition ID 1309: Build ID 2653960
) Bumps [peter-evans/create-pull-request](https://github.com/peter-evans/create-pull-request) from 7.0.6 to 7.0.7. - [Release notes](https://github.com/peter-evans/create-pull-request/releases) - [Commits](peter-evans/create-pull-request@67ccf78...dd2324f) --- updated-dependencies: - dependency-name: peter-evans/create-pull-request dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…t#7575) * update qdrant public api tests * update redis public api tests * update python public api tests * update testing public api tests * update sql server public api tests * update rabbitMQ public api tests * update postgre sql public api tests * update nodeJs public api tests * update nats public api tests * update my sql public api tests * update mongo db public api tests * update milvus public api tests * update keycloak public api tests * update kafka public api tests * update garnet public api tests * update elasticsearch public api tests * add azure aI open aI public api tests * update azure data tables public api tests * update messaging event hub public api tests * update messaging service bus public api tests * update messaging web pub sub public api tests * update search documents public api tests * update security key vault public api tests * update storage blobs public api tests * update storage queues public api test * update confluent kafka public api test * update elastic clients elasticsearch public api test * update keycloack authentication public api test * update microsoft azure cosmos public api tests * change HostApplicationBuilder to Host.CreateEmptyApplicationBuilder * change IHostApplicationBuilder to var * update microsoft data sql client public api tests * update microsoft entity framework core cosmos public api tests * update microsoft entity framework core sql server public api tests * update milvus client public api tests * update mongo db driver public api tests * update my sql connector public api tests * update nats net public api tests * update confluent kafka public api tests * update npgsql entity framework core postgre sql public api tests * update npgsql public api tests * update open ai public api tests * update oracle entity framework core public api tests * update pomelo entity framework core my sql public api tests * update qdrant client public api tests * update rabbit mq client public api tests * update seq public api tests * update stack exchange redis distributed caching public api tests * update stack exchange redis output caching public api tests * update stack exchang redis public api tests * update extensions service discovery public api tests * fix python tests * update oracle public api tests * update valkey public api tests * update app configuration, app containers, application insights, cognitive services, cosmos db public api tests * add Aspire.Hosting.Azure.Tests * fix duplicate * Fix MR by feedback
* Add tests for seq * Update tests GH action * Add functional tests * saved sln --------- Co-authored-by: Dan Moseley <danmose@microsoft.com>
* Fix Windows StubProcess implementation. * Move over to remote executor.
…ilename]` (microsoft#7874) * Make CLI packable. * Remove unnecessary StopApplication call. * Remove IsPackable
* Add Password for Garnet * Update tests * Update playground manifest * Fix up merge * PR feedback 1. Don't use special characters until azd gets fixed 2. Refactor code to be simplified --------- Co-authored-by: Eric Erhardt <eric.erhardt@microsoft.com>
…rosoft#7753)" (microsoft#7888) This reverts commit 76063a6.
Remove the if condition since is unnecessary.
* Default WriteToManifest for AzureBicepResource We have this duplicated code every time we want to create an Azure resource. It makes more sense to consolidate it in one spot - when the resource is created. * Revert the changes in the obsolete PublishAs methods for Redis, Sql, and Postgres. These are still necessary since we need to add the annotation to the InnerResource's Annotations.
* Add --project option and automatically detect apphost. * Add IsAotCompatible and IsPackable. * Array.Empty<string>()
* Add policy to close & re-open github-action PRs * Fix syntax * Fix spacing * Avoid recursion * Add comment * Fix language * Capitalization
…)" (microsoft#7981) This reverts commit d4df609.
* Don't trigger codeql pipeline for preview/rc branches * Remove '*rc*' from branch exclusion list
* Revert "Revert "Add policy to close & re-open github-action PRs (microsoft#7723)" (microsoft#7981)" This reverts commit 3aca7b7. * Enable triggerOwnActions in GitHub Action policy * Fix typo in GitHub Action policy file * Update event responder task configuration
.. and use independent jobs to get list of tests for Windows, and Linux.
.. and disable tests that need that, on windows/ci.
radical
pushed a commit
that referenced
this pull request
Feb 25, 2026
) * Add aspire start shortcut for detached AppHost launch - Add detached AppHost launch to 'aspire start' when no resource specified - Share detached launch behavior between start and run via AppHostLauncher - Register --no-build option on StartCommand and forward to child process - Restore JSON-safe detached output (human-readable to stderr for --format json) - Restore detached child diagnostics (--log-file generation and error surfacing) - Forward --no-build from 'aspire run --detach' to the detached child process Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Address review feedback: refactor AppHostLauncher, fix string references - Make TimeProvider required (registered in DI as TimeProvider.System) - Add period to log message (nit) - Use option Name properties instead of hardcoded strings for --project/--isolated - Extract BuildChildProcessArgs, StopExistingInstancesAsync, HandleLaunchFailure, DisplayLaunchResultAsync, and LaunchAndWaitForBackchannelAsync as separate methods - Add s_projectOption to AppHostLauncher for shared use - Display error when project not found (item #4) - Fix string references: use SharedCommandStrings for relocated strings - Fix async void to async Task on DisplayLaunchResultAsync Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
radical
added a commit
that referenced
this pull request
Apr 24, 2026
- Precompile regex patterns during config load instead of on every match; invalid patterns log warnings and disable the rule (comments #2-3) - Add note to doc examples clarifying they are snippets, not standalone configs (comment #1) - Dispose JsonDocument with 'using' in 3 test methods (comments #4-6) - Guard artifact extraction against zip-slip and symlink attacks by skipping symlinks and verifying resolved paths stay within trxDir (comment #7) - Cap test_pattern_matched_tests output to 50 entries and drop unused testProject field to avoid GH Actions size limits (comment #8) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
radical
added a commit
that referenced
this pull request
Apr 27, 2026
…osoft#16446) * feat(ci): add test failure retry patterns with config validation and pattern matching Add eng/test-retry-patterns.json with initial transient failure patterns (ECONNRESET, DNS failures, SSL errors, timeouts, Windows 0xC0000142). Add pattern matching functions to auto-rerun-transient-ci-failures.js: - loadRetryPatternsConfig: reads and validates JSON config - validateRetryPatternsConfig: schema validation + regex compilation - extractFailedTestsFromTrx: regex-based TRX XML parsing - matchesRetryPattern: string/regex matching with case-insensitive support - matchTestFailurePatterns: AND-within/OR-across rule matching - matchJobLogPattern: job name + log text pattern matching Add 30 tests in Infrastructure.Tests covering: - Config JSON structure and schema validation (C#) - Regex compilation validation via Node.js harness (V8 engine) - Pattern matching: substring, regex, AND/OR logic, disabled rules - TRX parsing: failed test extraction, output cap, XML entity decoding - Validation edge cases: unknown props, wrong version, missing reason Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * feat(ci): add test failure retry support to auto-rerun workflow Extend the auto-rerun-transient-ci-failures workflow to detect transient test failures in addition to infrastructure failures. Two new matching paths: 1. Job log pattern matching: analyzeFailedJobs now accepts an optional retryPatternsConfig and runs a 3rd classification pass using matchJobLogPattern for test-execution-failure jobs. 2. TRX-based pattern matching: After job classification, the YAML workflow downloads the All-TestResults artifact, extracts .trx files, and matches failed test output against testFailurePatterns from eng/test-retry-patterns.json. When matches are found, all skipped test-execution-failure jobs are promoted to retryable. New exported JS functions: - hasTestExecutionFailureStep: checks if a job has test execution steps - analyzeTrxFiles: parses TRX contents, matches against patterns, dedupes - promoteTestExecutionFailureJobs: pure function to move jobs to retryable - selectTestResultsArtifact: picks newest non-expired artifact under cap Safety rails: - Existing maxRetryableJobs cap (default 5) applies to promoted jobs - 3-attempt budget shared with infrastructure retries - Artifact download failures are non-fatal - 100MB artifact size cap, 200 TRX file limit, 50MB per-file limit Updated summary and PR comment formatting to distinguish infrastructure retries from test-pattern retries. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * docs(ci): rewrite auto-rerun CI docs with practical how-to guide Restructure the documentation from a behavior contract into a user-facing guide that explains: - How the rerun system works at a glance (flow diagram) - The four analysis passes and what each does - When it triggers (automatic vs manual) - How to add/modify test failure retry patterns in eng/test-retry-patterns.json with worked examples - Rule field reference tables for both pattern types - Matching semantics (AND/OR, substring vs regex, dedup) - Tips for writing good patterns - How to verify with dry run - Safety rails summarized in a table - Architecture and file layout - How to run the tests Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * feat(ci): add MCR rate limiting patterns to test-retry-patterns.json Add patterns to detect transient MCR (mcr.microsoft.com) rate limiting failures that cause both test and infrastructure CI failures: testFailurePatterns: - MCR 403 Forbidden (regex scoped to mcr.microsoft.com) - MCR 'The request is blocked' HTML response (regex scoped) - CONTAINER1016 (.NET SDK container publish failure) - 'pull access denied for mcr.microsoft.com' (Docker pull denial) jobFailurePatterns: - MCR 403 Forbidden (regex scoped to mcr.microsoft.com) - MCR 'The request is blocked' HTML response (regex scoped) Regex patterns use [\s\S]{0,500} to require mcr.microsoft.com within 500 chars of the error text, preventing false matches on non-MCR 403s. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * fix: decodeXmlEntities double-decoding and sanitize markdown in PR comments - Fix decodeXmlEntities replacement ordering: move & decode to last position to prevent double-decoding of &quot; and &apos; - Add sanitizeMarkdown helper to escape backticks/pipes in test names rendered in PR comment markdown (defense-in-depth) - Add test covering double-encoded XML entity decoding Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Address PR review feedback - Precompile regex patterns during config load instead of on every match; invalid patterns log warnings and disable the rule (comments #2-3) - Add note to doc examples clarifying they are snippets, not standalone configs (comment #1) - Dispose JsonDocument with 'using' in 3 test methods (comments #4-6) - Guard artifact extraction against zip-slip and symlink attacks by skipping symlinks and verifying resolved paths stay within trxDir (comment #7) - Cap test_pattern_matched_tests output to 50 entries and drop unused testProject field to avoid GH Actions size limits (comment #8) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
radical
added a commit
that referenced
this pull request
May 12, 2026
…te tightening, GHA cache Apply review findings from the GPT-5.5 + Opus 4.7 dual-model pre-merge review on microsoft#16965. 1. Codegen fixture enumeration (review finding #1, both reviewers, High): The deleted test-{python,go,java,typescript}-playground.sh scripts iterated every tests/PolyglotAppHosts/<Integration>/<Language>/ fixture (50 Python, 49 Go, 50 Java, 50 TypeScript) and ran 'aspire restore --apphost' + per-language compile against each, catching codegen regressions specific to individual integrations (Kafka, MongoDB, every Aspire.Hosting.Azure.*, etc.). The initial replacement only ran one Redis+SqlServer scenario per language and dropped that per-integration coverage. Add a RestoreAndCompileAllValidationFixtures [Fact] method to each of the four *CodegenValidationTests classes (Python/Go/Java/TypeScript). Each new test mounts tests/PolyglotAppHosts read-only into the test container via additionalVolumes, then runs a shared bash loop (PolyglotFixtureValidation.RunFixtureLoopAsync) that copies each fixture to a writable temp dir, runs 'aspire restore', and runs the per-language compile (py_compile / go build / javac @sources.txt / npm install + tsc --noEmit). The loop aggregates per-fixture pass/fail and exits non-zero if any fixture fails or if zero fixtures are found. Because SplitTestsOnCI=true splits at the class level, the new [Fact]s share a runner with the existing single-scenario tests rather than spinning up four new runners. 2. Redis pulls from Docker Hub (review finding #2, GPT-5.5, Medium): The deleted bash smoke scripts called .with_image_registry('netaspireci.azurecr.io') on the Redis resource to avoid Docker Hub anonymous-pull rate limits in CI; the initial C# rewrite omitted the override. Re-add it in PythonPolyglotTests/GoPolyglotTests/RustPolyglotTests so CI continues to pull Redis from the Aspire CI registry mirror. 3. Per-image gates were case-insensitive substring matches (review finding #3, Opus, Medium): GitHub Actions 'contains()' is case-insensitive, so 'contains(testShortName, "Go")' matched every KubernetesDeployWithMongoDB* / KubernetesDeployWithPostgres* class, downloading the Go image (and load-ing it into docker) for every unrelated job. The Java gate had the same problem against JavaScriptPublishTests. Replace the four 'contains()' gates in run-tests.yml with explicit endsWith() enumerations of the polyglot test classes that actually need each image (PolyglotTests, CodegenValidationTests, plus JavaEmptyAppHostTemplateTests). The --require-* flags passed to load-cli-e2e-images.sh use the same gating. 4. New polyglot images skipped GHA buildx cache (review finding #4, Opus, Medium): build_extended_polyglot_image used plain 'DOCKER_BUILDKIT=1 docker build' with no --cache-from / --cache-to, so the multi-stage 'FROM golang:1' / 'FROM rust:1' stages re-pulled ~800MB from Docker Hub on every CI build. Route the helper through 'docker buildx build --load --cache-from type=gha,scope=... --cache-to type=gha,scope=...,mode=max,ignore-error=true' with per-image cache scopes (cli-e2e-polyglot-{java,python,go,rust}). The existing Java helper is migrated to the same pattern. Review findings deferred to follow-up (preserve existing bash-script behavior; not regressions introduced by this PR): - #6 'docker ps | grep redis' false-positive risk on developer machines. - #7 SIGKILL of aspire run bypasses graceful cleanup. - #8 [QuarantinedTest] URL on RustPolyglotTests points at the feature issue. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
radical
added a commit
that referenced
this pull request
May 19, 2026
A post-merge review of microsoft#17166 (saved under .squad/log) flagged five issues in the prebuilt + DotNet-based AppHost restore paths that survived the `origin/main` merge. This addresses them. **#1 (HIGH) — Project-ref restore replaced ambient nuget.config for any non-Local explicit channel.** `BuildIntegrationClosureManifestAsync` called `TryCreateTemporaryNuGetConfigAsync` for every explicit channel, which emitted `<RestoreConfigFile>` and replaced nuget.config discovery wholesale. A user with a private/internal feed in their ambient nuget.config and a `daily` or `pr-*` channel pin would silently lose that feed during project-ref restore. Now only synthesize a temp nuget.config when `--source` is set; otherwise add channel sources via `<RestoreAdditionalProjectSources>` so the ambient nuget.config is preserved. **#2 (HIGH) — DotNetBasedAppHostServerProject accepted `packageSourceOverride` but ignored it.** The in-repo / dogfood path (selected whenever `AspireRepositoryDetector.DetectRepositoryRoot` returns non-null) declared the parameter to satisfy `IAppHostServerProject` but never threaded it into restore. The template factory was unconditionally telling users `--source was used for the initial scaffold restore only…` even when the override had been silently dropped. Thread the override through `CreateProjectFilesAsync` and prepend it to the `<RestoreAdditionalProjectSources>` list so the hive is the first source NuGet evaluates. This path does not use Package Source Mappings (PSM) like `PrebuiltAppHostServer` does — in dev mode most Aspire.* dependencies come from `ProjectReference` and the override is best- effort for the rare `PackageReference` fallback. Documented inline. **#3 (MED) — Restore-failure footer showed the original `--source`, not the auto-discovered effective one.** When `--source` was not passed but `ResolveLocalPackageSourceOverrideAsync` auto-discovered a local hive, the catches in `PrepareAsync` passed the original (unset) `packageSourceOverride` argument to `AppendRestoreContextOnFailure`. The user saw only the channel name and had no signal that a local hive participated in the failed restore. Lift `effectivePackageSourceOverride` to outer scope and pass it to the catches. **#4 (MED) — `BundleNuGetService` logged raw `--source` to the debug log.** The full restore args (including credentialed feed URLs) were emitted as a single debug line that downstream `RedactSourceForDisplay` never touched. Now build a redacted copy of the args specifically for the log line — the verbatim args still go to the process. Handles repeated `--source` flags and a missing trailing value defensively. **#5 (MED) — `RedactSourceForDisplay` failed open on malformed credentialed URLs.** `Uri.TryCreate` returns false for `https://user:p@ss@host/path` and `https://user:p#word@host/` (confirmed empirically), and the redactor's parse-failure branch returned the raw input. Such inputs were guaranteed to leak credentials into the failure footer that ships in bug reports. Fail closed for HTTP-shaped inputs by detecting `http://` / `https://` prefix before parsing and returning `<unparseable http source>` when the parse fails. Plain non-HTTP inputs (local paths, file://, etc.) still pass through unchanged. Refactor: extract `RedactSourceForDisplay` into a shared `PackageSourceRedactor` utility so the same redaction is applied wherever sources appear in user-visible output. `PrebuiltAppHostServer` keeps the internal static alias for back-compat with existing tests. Tests added: - `PrepareAsync_WithProjectReferencesAndExplicitChannelButNoOverride_UsesAdditionalSourcesNotRestoreConfigFile` - `PrepareAsync_RestoreFailure_WithAutoDiscoveredLocalSource_FooterShowsEffectiveSource` - `RedactSourceForDisplay_FailsClosedForMalformedHttpButPassesThroughLocalPaths` (5 inline cases) - `CreateProjectFiles_WithPackageSourceOverride_PrependsOverrideToRestoreAdditionalProjectSources` - `CreateProjectFiles_WithoutPackageSourceOverride_DoesNotInjectExtraSource` All 3297 tests in Aspire.Cli.Tests pass (0 failures, 20 platform skips). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
radical
added a commit
that referenced
this pull request
May 19, 2026
…ource (microsoft#17166) * fix(cli): honor source for guest language package restore aspire new aspire-empty --language typescript --source <pr-hive> --version <pr-version> parsed --source, but the empty AppHost TypeScript scaffolding path dropped it before the prebuilt AppHost restored Aspire.Hosting and TypeScript code-generation packages. The bundled restore then searched channel sources, missed the requested PR hive packages, and NuGet floated to a stale preview package set, which later failed with TypeLoadException when the generator loaded against the PR CLI's Aspire.TypeSystem. Flow TemplateInputs.Source into ScaffoldContext, pass it to IAppHostServerProject.PrepareAsync, and have PrebuiltAppHostServer add that source to package and closure restores. When a source override is present, use exact version ranges so restore fails rather than silently resolving a different Aspire prerelease. Fixes microsoft#17159 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * chore(cli): remove source restore diff noise Remove whitespace-only changes that are unrelated to the source restore fix, keeping the PR focused on the explicit package source propagation. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * fix(cli): constrain source override restore behavior When an explicit package source is passed to guest AppHost restore, keep the exact-version pinning scoped to Aspire packages because that is the source mapping being overridden. Non-Aspire integration packages should retain normal NuGet minimum-version restore semantics. Also apply the temporary NuGet.config to the project-reference closure restore path instead of only adding sources to the synthetic project. That keeps package source mapping and channel-specific restore settings active when package and project integrations are restored together. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * fix(cli): keep --source override exclusive for Aspire packages When `aspire new aspire-empty --source <pr-hive>` ran without an explicit `--channel`, the temp NuGet.config built for restore folded in every explicit channel's `Aspire* -> channelSource` mapping alongside the override's `Aspire* -> packageSourceOverride`. NuGet treats same-pattern mappings on multiple sources as co-eligible, so Aspire packages could still resolve from a channel feed and silently defeat the override's fail-fast intent. Exact-version pinning masked this in practice because the requested PR-hive version was usually unique, but the package source mapping itself was no longer exclusive to the override. In the override branch of `TryCreateTemporaryNuGetConfigAsync`, only fold in mappings from an explicitly-requested, matched channel (skip the catch-all "all explicit channels" fallback baked into `GetExplicitRestoreChannelsAsync`), and drop any `Aspire*`-prefixed mappings from that matched channel before merging. Non-Aspire patterns (`CommunityToolkit*`, catch-all `*`) are preserved so non-Aspire transitives keep their channel feeds. Mirror the same gating in `GetNuGetSourcesAsync` so the bundled NuGet service's `sources` list doesn't broadcast every channel feed when `--source` is the override mechanism. Add seven `TryCreateTemporaryNuGetConfig_*` test cases covering the override-with-channels matrix (no channel, matched channel, channel with `Aspire*` mapping, channel with all-packages mapping, lookup failure, requested-channel threading) plus a `PrepareAsync_*` integration check for the NuGet.org fallback. `TestPackagingService` gains a `LastRequestedChannelName` observable so the new `PassesRequestedChannelToPackagingService` test can assert the override branch threads `requestedChannel` into the packaging service. Touch the comments near `NuGetOrgSource` and the `RestoreConfigFile`/`RestoreAdditionalProjectSources` split so they describe the actual constraint ("cannot float to NuGet.org or any other co-eligible feed"). Refs microsoft#17159 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * fix(cli): warn that aspire-empty --source is one-shot at scaffold Running `aspire new aspire-empty --language <non-csharp> --source <X>` succeeds at scaffold time but the override is consumed only for the initial restore inside `PrebuiltAppHostServer`. The scaffolded project persists only the channel and SDK version, so a follow-up `aspire add` or `aspire restore` in the same project resolves Aspire packages from the channel feeds in `aspire.config.json` rather than `<X>` — and silently produces a different package set, or fails when the channel does not carry the requested version. Emit a yellow warning immediately after the scaffold succeeds (when `inputs.Source` is non-empty on the non-C# branch) so users supplying `--source <pr-hive>/packages` are not surprised when subsequent commands miss the override. Persisting the feed into a generated `nuget.config` (and also honoring `--source` on the C# empty path, which silently drops it today) is left as a follow-up. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * fix(cli): include --source/channel context in scaffold restore failures When the prebuilt AppHost scaffold restore fails, the displayed output is the only debugging surface most users see. Previously it carried only the raw NuGet stderr ("Failed to prepare: Package restore failed: ..."), with no record of which `--source`, channel, or package versions had been in play. Reproducing the failure required a verbose re-run with diagnostic logging just to recover the inputs. Append the override source, the requested channel, and a short preview of the package list to the `OutputCollector` from both of `PrepareAsync`'s catch blocks (`AppHostServerPrepareFailedException` and the catch-all wrapper around `RestoreNuGetPackagesAsync`). When neither `--source` nor a channel was specified the helper is a no-op, so existing failure messages without these inputs are unchanged. Add an end-to-end `PrepareAsync` test that wires `--source` together with a channel whose `Aspire*` mapping conflicts with the override and asserts the temp `nuget.config` actually passed to the restore invocation drops the channel's `Aspire*` mapping, pinning that the override is authoritative for `Aspire*` packages end-to-end (and not only at the temp-config generator unit boundary). Add a `PrepareAsync_RestoreFailure_OutputIncludesSourceAndChannelContext` test that fails the restore via a non-zero exit and asserts the override path, channel name, and package id are present in the returned output. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * fix(cli): honor --source override for guest-language starter templates `aspire new aspire-{ts,py,go}-starter --source <pr-hive> --version <pr>` hit the same TypeLoadException class of failure as `aspire-empty` did before the fix landed in this branch: the override was plumbed into PrebuiltAppHostServer.PrepareAsync for the empty-template path only, while starter templates went through GuestAppHostProject.BuildAndGenerateSdkAsync → PrepareAppHostServerAsync without forwarding the override, so Aspire packages restored from channel feeds rather than the requested source. Thread `packageSourceOverride` through IGuestAppHostSdkGenerator.BuildAndGenerateSdkAsync and the GuestAppHostProject prepare helper, then pass `inputs.Source` from all three guest starter templates. Hoist the "override is not persisted" warning into a shared helper on CliTemplateFactory so the empty and starter paths emit the same message; the warning fires only after a successful scaffold so it doesn't add noise behind a more prominent restore failure. Tests: - Expand the empty-template warning test to a [Theory] covering TypeScript and Java (the latter behind the experimental polyglot flag). - Add starter-template coverage for both the warning+plumb-through happy path and the failed-restore-suppresses-warning path. - Pin the restore-failure context footer shape (`--source:`, `channel:`, `packages:` labels) and the >5-package truncation behavior. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * chore(cli): rename EmptySourceOverrideNotPersistedWarning resource The shared `DisplaySourceOverrideNotPersistedWarningIfNeeded` helper on `CliTemplateFactory` is invoked by both `aspire-empty` and the three guest-language starter templates (TypeScript, Python, Go), so the `Empty*` prefix on the resource key is stale. Drop the prefix while the string is still pre-release and re-translation has not yet been triggered for translators. Renames the resource in `.resx`, `.Designer.cs`, the single production call site in `CliTemplateFactory.cs`, and four references in `NewCommandTests.cs` (empty and starter happy-path + suppression cases). `dotnet build /t:UpdateXlf src/Aspire.Cli/Aspire.Cli.csproj` regenerates the 13 `*.xlf` files to pick up the new `trans-unit id`. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * fix(cli): align --source argument list with temp NuGet.config in PrebuiltAppHostServer `TryCreateTemporaryNuGetConfigAsync` already drops the matched channel's `Aspire*` mapping in the override branch, pinning Aspire package restoration to `--source` exclusively. But `GetNuGetSourcesAsync` — which builds the `--source` CLI argument list passed alongside the temp config — was still iterating every mapping in the matched channel and adding each mapping URL, including the channel's Aspire feed. The bundled NuGet tool treats `--source` CLI args as co-eligible with config mappings (which is why the original "don't fold in every explicit channel" comment exists in this method), so re-adding the channel's Aspire feed silently undoes the temp config's PSM drop and lets Aspire packages still resolve from the channel feed. A second, smaller divergence: when the matched channel had no `*` (AllPackages) mapping, the temp config added `* -> NuGet.org` as a catch-all but the sources list's `sources.Count == 1` heuristic only added NuGet.org in the no-channel case, leaving a mismatched catch-all whenever a matched channel contributed any non-Aspire mapping (e.g. `CommunityToolkit*`, `Microsoft.*`). In the matched-channel loop, skip mappings whose `PackageFilter` starts with "Aspire" when an override is set, and observe whether the matched channel supplied its own AllPackages mapping. After the loop, fall back to NuGet.org only when no AllPackages mapping was seen — the same rule the temp config uses for its catch-all. Tests: - `GetNuGetSources_WithPackageSourceOverrideAndMatchedChannel_OmitsChannelAspireFeedFromSources` pins that the channel's Aspire feed URL does NOT appear in the `--source` argument list, even though the channel maps `Aspire*` to it. This is the inverse assertion of the existing `TryCreateTemporaryNuGetConfig_WithPackageSourceOverride_DropsRequestedChannelAspireMappings` test on the config side. - `..._KeepsChannelSourceAndAddsNuGetOrgFallback` covers the `CommunityToolkit*` case: non-Aspire channel mapping stays, and NuGet.org is added because the matched channel has no AllPackages mapping. - `..._OmitsNuGetOrgFallback` covers a channel that already supplies `* -> channelSource`: NuGet.org should NOT be added, because the channel's own AllPackages mapping is the catch-all in both the temp config and the sources list. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * fix(cli): redact credentials from --source in restore-failure output The new restore-failure context block introduced earlier in this branch echoes `--source: <user-supplied URL>` into the OutputCollector that ScaffoldingService displays on a failed scaffold. NuGet feed URLs routinely carry credentials — `https://name:pat@host/...` for token-auth feeds or SAS-style `?sv=...&sig=...` query tokens for blob-storage feeds — and that block is exactly the text users copy verbatim into GitHub issues, Teams chats, and CI failure transcripts. Add a `RedactSourceForDisplay` helper that strips UserInfo, Query, and Fragment from http/https URIs before display, and route the override through it from `AppendRestoreContextOnFailure`. Plain URLs without credentials/query are detected via early-return and pass through unchanged; local paths and `file://`-style sources bypass the URI branch and are emitted as-is. The redaction is only for the display copy — the actual restore invocation still receives the original source string. Cover the helper with a `[Theory]` exercising the no-redaction path (plain URL, Unix path, Windows path), the userinfo-only case, the query-only case, the combined userinfo+query case, and the fragment case. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * fix(cli): auto-discover local Aspire source from requested channel When --source isn't supplied, PrebuiltAppHostServer now resolves the requested channel and, if it has a hive-backed Aspire* mapping pointing at an existing local directory, uses that as the package source override for both package-only and project-reference restore. That closes the dogfood gap where `aspire new aspire-empty --language typescript` from a PR/local CLI would resolve Aspire packages through the ambient channel feed instead of the CLI's own hive, surfacing as TypeLoadException during code generation. Channel-lookup failures are swallowed-and-logged (mirroring the existing defensive catches in TryCreateTemporaryNuGetConfigAsync and GetNuGetSourcesAsync); OperationCanceledException is re-thrown. Tests cover the explicit-channel-only path, the explicit-source-wins path, and that http-backed channels keep their existing non-exact restore behavior. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * fix(cli): close 5 findings from PR microsoft#17166 post-merge review A post-merge review of microsoft#17166 (saved under .squad/log) flagged five issues in the prebuilt + DotNet-based AppHost restore paths that survived the `origin/main` merge. This addresses them. **#1 (HIGH) — Project-ref restore replaced ambient nuget.config for any non-Local explicit channel.** `BuildIntegrationClosureManifestAsync` called `TryCreateTemporaryNuGetConfigAsync` for every explicit channel, which emitted `<RestoreConfigFile>` and replaced nuget.config discovery wholesale. A user with a private/internal feed in their ambient nuget.config and a `daily` or `pr-*` channel pin would silently lose that feed during project-ref restore. Now only synthesize a temp nuget.config when `--source` is set; otherwise add channel sources via `<RestoreAdditionalProjectSources>` so the ambient nuget.config is preserved. **#2 (HIGH) — DotNetBasedAppHostServerProject accepted `packageSourceOverride` but ignored it.** The in-repo / dogfood path (selected whenever `AspireRepositoryDetector.DetectRepositoryRoot` returns non-null) declared the parameter to satisfy `IAppHostServerProject` but never threaded it into restore. The template factory was unconditionally telling users `--source was used for the initial scaffold restore only…` even when the override had been silently dropped. Thread the override through `CreateProjectFilesAsync` and prepend it to the `<RestoreAdditionalProjectSources>` list so the hive is the first source NuGet evaluates. This path does not use Package Source Mappings (PSM) like `PrebuiltAppHostServer` does — in dev mode most Aspire.* dependencies come from `ProjectReference` and the override is best- effort for the rare `PackageReference` fallback. Documented inline. **#3 (MED) — Restore-failure footer showed the original `--source`, not the auto-discovered effective one.** When `--source` was not passed but `ResolveLocalPackageSourceOverrideAsync` auto-discovered a local hive, the catches in `PrepareAsync` passed the original (unset) `packageSourceOverride` argument to `AppendRestoreContextOnFailure`. The user saw only the channel name and had no signal that a local hive participated in the failed restore. Lift `effectivePackageSourceOverride` to outer scope and pass it to the catches. **#4 (MED) — `BundleNuGetService` logged raw `--source` to the debug log.** The full restore args (including credentialed feed URLs) were emitted as a single debug line that downstream `RedactSourceForDisplay` never touched. Now build a redacted copy of the args specifically for the log line — the verbatim args still go to the process. Handles repeated `--source` flags and a missing trailing value defensively. **#5 (MED) — `RedactSourceForDisplay` failed open on malformed credentialed URLs.** `Uri.TryCreate` returns false for `https://user:p@ss@host/path` and `https://user:p#word@host/` (confirmed empirically), and the redactor's parse-failure branch returned the raw input. Such inputs were guaranteed to leak credentials into the failure footer that ships in bug reports. Fail closed for HTTP-shaped inputs by detecting `http://` / `https://` prefix before parsing and returning `<unparseable http source>` when the parse fails. Plain non-HTTP inputs (local paths, file://, etc.) still pass through unchanged. Refactor: extract `RedactSourceForDisplay` into a shared `PackageSourceRedactor` utility so the same redaction is applied wherever sources appear in user-visible output. `PrebuiltAppHostServer` keeps the internal static alias for back-compat with existing tests. Tests added: - `PrepareAsync_WithProjectReferencesAndExplicitChannelButNoOverride_UsesAdditionalSourcesNotRestoreConfigFile` - `PrepareAsync_RestoreFailure_WithAutoDiscoveredLocalSource_FooterShowsEffectiveSource` - `RedactSourceForDisplay_FailsClosedForMalformedHttpButPassesThroughLocalPaths` (5 inline cases) - `CreateProjectFiles_WithPackageSourceOverride_PrependsOverrideToRestoreAdditionalProjectSources` - `CreateProjectFiles_WithoutPackageSourceOverride_DoesNotInjectExtraSource` All 3297 tests in Aspire.Cli.Tests pass (0 failures, 20 platform skips). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * fix(cli): degrade restore on channel-lookup failure + cover gaps from microsoft#17227 merge PR microsoft#17227's defensive catch around the channel-lookup helper had two call sites; only the auto-discovery one survived the merge into this branch. The PSM-temp-config no-override path still propagates a transient `IPackagingService.GetChannelsAsync` failure out to `PrepareAsync`'s outer catch, turning a transient packaging-service hiccup (malformed `aspire.config.json`, unexpected feed probe error) into a hard `aspire new` scaffold failure. Mirror the existing defensive catch into the no-override branch of `TryCreateTemporaryNuGetConfigAsync`: cancellation rethrows, anything else logs and returns null so restore falls through to the ambient nuget.config + caller-resolved channel sources path, matching the catch in `ResolveLocalPackageSourceOverrideAsync` and the long-standing catch in `GetNuGetSourcesAsync`. Restore the dropped degrade test (`PrepareAsync_WhenPackagingService- ThrowsDuringAutoDiscovery_DegradesGracefully`) so a future refactor can't silently regress this back. Also add two negative-path tests for `aspire-empty --language <guest>` source-coherence: - `PrepareAsync_WithHiveBackedChannelPointingAtMissingLocalDirectory_- DoesNotApplyOverride` pins that a stale `aspire.config.json` (user deleted the local hive but the channel pin remains) does not pin Aspire packages to a non-existent directory or emit exact-pin / NuGet.org fallback. - Extend `NewCommandWithEmptyTemplateAndSourceOverrideWarnsThatOverride- IsNotPersisted` to also cover python, go, and rust, matching the five guest languages registered in `DefaultLanguageDiscovery`. Refs microsoft#17159 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * fix(cli): address source-restore review feedback Keep cancellation tokens last on the guest AppHost prepare/source APIs now that both requested channel and source override are threaded through the same calls. Move the staging-unavailable guard before temporary NuGet.config creation so the source-override project-reference restore path cannot silently fall back to NuGet.org when staging cannot be synthesized. Also update the project-reference restore comment to describe both explicit --source and auto-discovered local channel sources. Add direct PackageSourceRedactor coverage for happy paths, malformed HTTP inputs, whitespace-prefixed HTTP sources, and non-HTTP source forms. Trim HTTP inputs before detection/parsing so indented feed URLs are still redacted or fail closed. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * fix(cli): persist aspire new source overrides An explicit `aspire new --source <source>` previously only affected the initial scaffold restore. The generated project did not record that source, so later `aspire add` or `aspire restore` could fall back to channel or ambient NuGet configuration and lose the Aspire package source selected at creation time. Persist source overrides into the generated project's NuGet.config by mapping `Aspire*` to the explicit source and keeping non-Aspire fallback sources from the resolved channel, or NuGet.org when no channel fallback is available. The persisted config remains self-contained: it does not import parent, user, or global NuGet sources, mappings, disabled sources, or credentials; only an existing project-local NuGet.config is merged. Remove the stale warning that source overrides are not persisted, share the source-override mapping logic with the prebuilt restore path, and add tests covering empty templates, starter templates, .NET templates, existing config merge behavior, and ambient-config non-absorption. Refs microsoft#17159 Refs microsoft#17225 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * fix(cli): reject credentialed new sources before persistence Persisting `aspire new --source` into a project NuGet.config makes the source durable project state. Credential-bearing HTTP URLs should not be written there because the generated file can be committed accidentally. Reject HTTP(S) sources that contain user info, query strings, or fragments before project creation starts, and keep the lower-level mapping helper from persisting those sources if it is called directly. The error points users at NuGet credential providers or user-level NuGet configuration instead of embedding secrets in the feed URL. Refs microsoft#17159 Refs microsoft#17225 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * fix(cli): update PR-hive NuGet config snapshots The NuGet config merger no longer maps wildcard package resolution to the PR hive when a separate fallback source already owns `*`. Update the PR-hive snapshots so CI expects Aspire packages only from the hive and keeps the fallback mapping on the appropriate source. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
radical
pushed a commit
that referenced
this pull request
May 30, 2026
* Show idle AppHosts in Aspire pane with Run/Debug context menu * Rename view ID from runningAppHosts to appHosts * Rename context key from noRunningAppHosts to noAppHosts * Keep panel visible when stopped AppHost has workspace candidates When an AppHost stops, the noAppHosts context key now considers workspace candidates. This ensures the panel shows idle AppHosts instead of the empty welcome view after a running AppHost is stopped. * Fix noAppHosts assertions: workspace candidates keep panel visible The _updateWorkspaceContext change (0e312f9) added !hasWorkspaceCandidates to the noAppHosts condition, meaning the panel stays visible when idle AppHosts are discovered. Two tests asserted noAppHosts=true after describe exit, but the legacy format candidate is treated as buildable (toAppHostCandidate defaults null status to 'buildable'), so workspace candidates persist and noAppHosts is correctly false. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Make workspace AppHosts expandable with launch actions * Address review feedback for PR microsoft#17506 Fix #1: Rename command IDs in package.json menus and walkthrough so they target the new aspire-vscode.runAppHostCommand and aspire-vscode.debugAppHostCommand registrations introduced in this PR. Without this the editor title bar, explorer context menu, and Get Started walkthrough Run/Debug buttons silently no-op. Fix #2: Wrap vscode.debug.startDebugging in try/catch in AppHostLaunchService.launch so a 'false' return value (debug adapter rejected) or thrown error clears the launching state. Otherwise the tree item is stuck showing the 'Starting...' spinner forever and the user cannot retry. Fix #3: Make AspireAppHostTreeProvider.runAppHost async and await launch so launch failures surface via showErrorMessage instead of being dropped as unhandled promise rejections. Fix #4: In workspace mode with multiple candidate AppHost paths, match running AppHosts to candidates by directory equivalence (isMatchingAppHostPath) rather than exact path. This is the same matching used elsewhere in AppHostDataRepository when correlating 'aspire ps' output to candidate paths, so canonicalization differences (case, separators, trailing slashes) no longer cause a running AppHost to display as idle. Fix #5: Introduce aspire.noRunningAppHosts context key so the Open Dashboard palette command is only enabled when at least one AppHost is actually running. Previously the palette appeared when only idle candidates were known and then silently no-oped. Fix #6: Widen the workspaceResources contextValue regex in package.json so the read-only 'Open AppHost Source' and 'Copy AppHost Path' actions appear on bare 'workspaceResources' items, not only on 'workspaceResources:hasAppHost'. The destructive 'Stop AppHost' menu remains gated on :hasAppHost. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: Adam Ratzman <adam@adamratzman.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Please include a summary of the changes and the related issue. Please also include relevant motivation and context. List any dependencies that are required for this change.
Fixes # (issue)
Checklist
<remarks />and<code />elements on your triple slash comments?breaking-changetemplate):doc-ideatemplate):