Skip to content

Restrict CI package publishing to Windows Release - #10496

Open
mmitche wants to merge 3 commits into
mainfrom
mmitche-templating-single-publisher
Open

mmitche wants to merge 3 commits into
mainfrom
mmitche-templating-single-publisher

Conversation

@mmitche

@mmitche mmitche commented Sep 21, 2026

Copy link
Copy Markdown
Member

Problem

Multiple OS/configuration legs can publish the same packages to shared PackageArtifacts/BlobArtifacts containers. Main already suppresses Debug publishing in azure-pipelines-pr.yml, but its Linux and macOS Release legs still publish. The alternate azure-pipelines.yml product path also permits multiple publishers.

Solution

  • Disable publishing for Linux and macOS Release in azure-pipelines-pr.yml, retaining existing Debug suppression and Windows Release publishing.
  • In azure-pipelines.yml, append /p:Publish=false for every Linux/macOS configuration and every non-Release Windows configuration, on both Windows PR and non-PR paths.
  • Preserve existing build, test, integration-test, pack and signing coverage, log/test-result publishing, localization, and the templating-official-ci assetless path.

The CI wrappers inject Publish=true; the trailing caller property overrides it. Legacy pipeline-publishing settings are unchanged.

Checks:

  • Added unit tests

YAML-only change: validated 64 local YAML scenarios covering public/internal, PR/non-PR, product/official paths, and Release/Debug/Checked configurations; 216 product legs had exactly one publisher per product scenario, Windows Release. Confirmed 16 assetless scenarios unchanged and all other expanded local YAML structure preserved. Four actual MSBuild probes confirmed trailing Publish=false overrides Publish=true independently of the legacy DotNetPublishUsingPipelines setting. Scoped git diff --check passed.

Validation used a local expression evaluator, not Azure server expansion; external templates were not expanded and no live CI run was performed.

Keep build and test coverage while preventing concurrent package artifact uploads across operating systems and configurations.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@mmitche
mmitche requested a review from a team as a code owner September 21, 2026 20:44
mmitche and others added 2 commits September 21, 2026 13:53
Leave azure-pipelines.yml unchanged as requested in review.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep both pipeline files in scope as confirmed in review.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
mmitche added a commit that referenced this pull request Sep 23, 2026
…10501)

### Problem
<!-- Add the issue number if exists. Describe the problem otherwise. -->
Backport of #10496 to release/10.0.4xx. Multiple OS/configuration legs
can publish the same packages to shared PackageArtifacts/BlobArtifacts
containers.

### Solution
<!-- Describe the solution. -->
Semantically adapt the publishing restriction to this release branch
rather than blindly cherry-picking main:
- In azure-pipelines-pr.yml, add the Windows Debug publishing
suppression missing from this branch and disable publishing for every
Linux/macOS configuration. Windows Release remains the publisher.
- In azure-pipelines.yml, append /p:Publish=false for every non-Release
Windows configuration on both PR and non-PR paths, and for every
Linux/macOS configuration.
- Preserve this branch's older official product pipeline structure,
signing, source-build settings, build/test/integration-test coverage,
package creation, diagnostic artifact/test-result publishing, and
localization. Do not introduce main's newer assetless official-pipeline
routing.

CI wrappers enable publishing before caller arguments; the trailing
Publish=false override suppresses package publishing without changing
legacy DotNetPublishUsingPipelines settings.

### Checks:
- [ ] Added unit tests

YAML-only change. Reused the existing release validator, scoped
exclusively to release/10.0.4xx: 96 local scenarios and 388 build legs
passed, covering public/internal, PR/non-PR, pipeline names, source
branches, and Release/Debug/Checked configurations (including
Debug-only). Exactly one publisher, Windows Release, remains when a
Release leg exists; Debug-only parameterized scenarios have none. The
validator confirmed identical build-leg coverage and non-publishing YAML
structure, plus caller-property ordering in both CI wrappers/build
scripts. Independent YAML parsing and structural comparison confirmed
only the intended publishing overrides changed. Scoped git diff --check
passed.

Refreshed origin/release/10.0.4xx and confirmed the existing backport
commit remains based on its current head. Validation is a local
expression-subset evaluation, not Azure server expansion; external
templates were not expanded. No dependency installs, full builds, live
CI runs, or CI retries were performed.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
mmitche added a commit that referenced this pull request Sep 23, 2026
…10500)

### Problem
<!-- Add the issue number if exists. Describe the problem otherwise. -->
Backport #10496 to `release/9.0.3xx`. Multiple build legs can publish
packages concurrently to the shared `PackageArtifacts`/`BlobArtifacts`
containers.

### Solution
<!-- Describe the solution. -->
Semantically adapt the publishing restriction to this release branch
rather than blindly cherry-picking the main-branch patch:
- Add the previously missing Windows Debug/non-Release publishing
suppression in both pipeline YAMLs, with an empty override for Windows
Release.
- Append `/p:Publish=false` to macOS and Linux builds in both YAMLs.
- Keep existing official/product build behavior, signing, source-build
settings, build/test coverage, per-leg diagnostic/log artifacts, and
localization unchanged. Windows overrides follow internal build
arguments so the publishing restriction wins.

Reuses existing backport commit
`d0e7905c585d7db9b20b149050bd5ced51347432`. Only
`azure-pipelines-pr.yml` and `azure-pipelines.yml` change (+15 lines).

### Checks:
- [ ] Added unit tests

Pipeline-only change; no unit tests added. Refreshed
`origin/release/9.0.3xx` and verified it remains the commit's parent.
The existing local release validator, scoped to this branch, passed 96
scenarios / 388 build legs, including Release-only,
Release+Debug+Checked, and Debug-only configuration lists across
public/internal, PR/non-PR, pipeline-definition, and source-branch
combinations. It verifies Windows Release-only publishing, unchanged
build-leg coverage and all non-publishing YAML structure, and wrapper
argument ordering. `git diff --check` passed.

Validation limitations: local YAML-expression subset only; external
templates and Azure server expansion were not exercised. No dependency
installs, full builds, or live CI runs/retries were performed.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
mmitche added a commit that referenced this pull request Sep 23, 2026
…10499)

### Problem
<!-- Add the issue number if exists. Describe the problem otherwise. -->
Backport #10496 to release/10.0.1xx. Concurrent product legs can upload
packages to the shared PackageArtifacts/BlobArtifacts containers.

### Solution
<!-- Describe the solution. -->
Reuse commit 04b73e5, semantically
adapted from the main change rather than blindly cherry-picked. This
release branch lacks main's existing Debug publishing suppression and
retains the older official product build layout.

In both azure-pipelines-pr.yml and azure-pipelines.yml, pass
/p:Publish=false for macOS/Linux builds and suppress publishing for
Windows non-Release builds. Keep Windows Release as the only product
package publisher. Add the missing Windows Debug matrix arguments and
apply the official pipeline's non-Release guard to both PR and non-PR
Windows command paths.

Preserve existing official product builds, signing, source-build
configuration, test coverage and /p:Test=false behavior, diagnostic
artifact/log publishing, and localization. No shared templates are
changed.

### Checks:
- [ ] Added unit tests

Pipeline-only change; no unit tests added. Refreshed
origin/release/10.0.1xx and confirmed the existing commit is exactly one
commit ahead, with only 15 added lines across the two pipeline YAMLs.
git diff --check passed. Both YAML files parse successfully. Reused the
existing local release validator, restricted to this branch: 96
scenarios and 388 product legs passed, including Release/Debug/Checked
and Debug-only configurations. It reproduced 68 previously multi-writer
scenarios and verified unchanged job coverage and all non-publishing
YAML structure. Checked build-script forwarding of trailing publishing
overrides.

Validation limitations: local YAML expression-subset evaluation only; no
external-template or Azure server expansion, dependency installs, full
builds, or live CI run/retry performed.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
mmitche added a commit that referenced this pull request Sep 23, 2026
…10497)

### Problem
<!-- Add the issue number if exists. Describe the problem otherwise. -->
Backport #10496 to release/8.0.4xx. Multiple build legs can publish
packages to the shared PackageArtifacts/BlobArtifacts containers,
causing concurrent uploads.

### Solution
<!-- Describe the solution. -->
Semantically adapt #10496 rather than blindly cherry-picking the
main-branch patch: this release branch also lacks Windows Debug
publishing suppression. Both pipeline YAMLs now pass `/p:Publish=false`
for macOS and Linux and use `_ExtraBuildArgs` to suppress publishing for
Windows Debug/non-Release configurations. Windows Release keeps its
existing publishing behavior.

Preserve this branch's existing official product-build path
(`/p:Test=false`), PR integration tests, signing, source-build
configuration, diagnostic/test artifact settings, localization, and
post-build processing. Reuse commit
2b49f7b; no unrelated checkout changes
are included.

### Checks:
- [ ] Added unit tests

Validation: refreshed `origin/release/8.0.4xx` and confirmed the
backport is one commit ahead with no base divergence. `git diff --check`
passes. Both YAMLs parse with PyYAML; assertions check the Windows
Release/Debug publishing arguments and both Unix build commands.
Removing only the intended publishing additions yields parsed YAML
identical to the refreshed release baseline. The diff is limited to 15
added lines across `azure-pipelines.yml` and `azure-pipelines-pr.yml`.

Limitations: static validation only; no live Azure Pipelines template
expansion, full builds, unit/integration test execution, or CI retries
were performed.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
mmitche added a commit that referenced this pull request Sep 23, 2026
…10498)

### Problem
<!-- Add the issue number if exists. Describe the problem otherwise. -->
Backport #10496 to release/8.0.1xx. Multiple build legs can publish
packages concurrently to the shared PackageArtifacts/BlobArtifacts
containers.

### Solution
<!-- Describe the solution. -->
Reuse commit 8c6657d, semantically
adapting the original change rather than blindly cherry-picking main:
- Disable package publishing on Linux and macOS in both pipeline YAMLs
with `/p:Publish=false`.
- Add the Windows Debug/non-Release suppression missing from this
release branch. The legacy PR matrix assigns `_ExtraBuildArgs` per
configuration; the official pipeline applies a non-Release configuration
guard and forwards the argument in both Windows command paths. Windows
Release keeps its existing publishing behavior.
- Preserve the branch's official product build, signing, source-build,
test, diagnostic/log artifact, localization, and post-build
configuration. No shared templates or product code change.

### Checks:
- [ ] Added unit tests

Validation: refreshed origin/release/8.0.1xx and confirmed the existing
backport is one commit ahead with no base-only commits. Parsed both
YAMLs, checked every Windows and Unix build command and the
Release/Debug argument assignments, and structurally compared against
the refreshed base after removing only the intended publishing
additions; all remaining pipeline semantics match. `git diff --check`
passes, and the committed diff contains only the two pipeline YAMLs (+15
lines).

Limitations: static validation only; no Azure DevOps template expansion,
full builds, dependency installs, or live CI retry. No unit tests added
for this YAML-only backport. Unrelated local long-path checkout
deletions were not touched or committed.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
nagilson added a commit that referenced this pull request Sep 24, 2026
…10502)

### Problem
<!-- Add the issue number if exists. Describe the problem otherwise. -->
Backport #10496 to `release/9.0.1xx`. Multiple OS/configuration legs can
publish the same packages to shared PackageArtifacts/BlobArtifacts
containers.

### Solution
<!-- Describe the solution. -->
Semantically adapt the publishing restriction to this release branch
rather than blindly cherry-picking main, because this branch lacks
main's existing Debug suppression:
- In `azure-pipelines-pr.yml`, add Windows Debug suppression and disable
publishing for every Linux/macOS configuration, leaving Windows Release
publishing unchanged.
- In `azure-pipelines.yml`, suppress publishing for non-Release Windows
configurations on both PR and non-PR paths and for every Linux/macOS
configuration.
- Preserve this branch's older official product pipeline, signing,
source-build, build/pack/test/integration-test coverage, log/test-result
publishing, localization, and legacy pipeline-publishing settings. Do
not introduce main's newer assetless official-path structure.

The CI wrappers inject Publish=true; the trailing /p:Publish=false
property overrides it. Reuses the existing backport commit
`203ebb5413c16b9fceb756c363f971744d64909d` unchanged.

### Checks:
- [ ] Added unit tests

YAML-only change. Refreshed `origin/release/9.0.1xx` and verified it
remains an ancestor of the backport. Reused the existing release
validator, restricted to this branch: 96 local YAML scenarios / 388 legs
passed, covering public/internal, PR/non-PR, both pipeline definition
names, main/release source-branch conditions, and Release/Debug/Checked
configurations (including Debug-only). Only Windows Release publishes
when present; Debug-only configurable runs have no publisher. All
non-publishing expanded YAML and build-leg coverage were preserved. Also
parsed both YAML files, checked wrapper argument ordering, verified
exact two-file scope (+15 lines), and passed scoped `git diff --check`.

Validation uses a local expression evaluator, not Azure server
expansion. External templates were not expanded; no dependencies
installed, full builds, or live CI retries were performed.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants