Skip to content

Automate CI-fix Azure DevOps validation - #39147

Merged
kubaflo merged 19 commits into
mainfrom
pureween-ci-fix-azdo-trigger
Oct 6, 2026
Merged

kubaflo merged 19 commits into
mainfrom
pureween-ci-fix-azdo-trigger

Conversation

@PureWeen

@PureWeen PureWeen commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

Summary

Automates Azure DevOps validation for the repository's generated CI-fix pull requests.

  • Adds strict same-repository gating for the automated fingerprint: github-actions[bot], ci-fix/** head, agentic-workflows label, and the correct title/base pairing for main and net11.0.
  • Uses trusted pull_request_target execution plus trusted-main workflow_run reconciliation for both fixer workflows, including cases where GitHub-token-created PR events are suppressed or approval-gated. Every configured PR event reconciles live eligible open PR heads rather than relying on stale webhook identities.
  • Refreshes nominated PRs individually and verifies each test-merge commit contains the refreshed source head as its second parent before queueing or deduplication. Missing, stale, or conflicting merge pairs produce explicit per-PR failures without blocking other verified heads; the overall run remains non-success when eligible work cannot be dispatched. Live eligibility and the head/merge pair are revalidated for each pipeline under the same partial-failure boundary as dedupe and queue operations.
  • Queues MAUI validation definitions 302 (maui-pr), 313 (maui-pr-uitests), and 314 (maui-pr-devicetests) with the verified PR merge ref/SHA, provider triggerInfo, and serialized system.pullRequest.* parameters matching observed normal Azure PR build payloads. The system parameters include the bare target branch used by pipeline conditions and the source head SHA. PR-head check association remains subject to live canary verification.
  • Adds per-pipeline/head-SHA deduplication, bounded retries, safe ambiguous-POST reconciliation, explicit partial-failure reporting, summaries, and build links. Nested PowerShell request timeouts enter reconciliation without repeating the POST; failed reconciliation preserves possible-acceptance uncertainty. Deduplication and both fixer instructions require the PR merge ref and exact source-head metadata when matching automatic builds.
  • Both fixer variants retain primary-pipeline whole-build validation for build-only fixes. When a build break originates in definition 313 or 314, merely observing its exact-head run is insufficient: all relevant originating platform build legs must be completed and successful before marking ready. Missing, unknown, pending, failed, or canceled relevant evidence stops readiness; unrelated test-leg flakes do not. Readiness audit comments identify the validated primary and originating pipeline/build evidence.
  • A shared seven-minute dispatch budget caps HTTP timeouts and backoff under the ten-minute job limit. Budget exhaustion, including during queue-time revalidation, preserves completed results and explicitly reports unprocessed work without implying those pipelines submitted a queue POST.
  • Never checks out or executes PR-controlled code; authentication uses the existing main-branch OIDC trust and no PAT.
  • Updates the CI-fixer descriptions, setup documentation, and compiled gh-aw lock files.

Validation

Completed locally:

  • 73 focused Pester tests passed at d0cf55b, independently rerun, including offline full-script reconciliation, delayed-event regressions, behavioral queue-response coverage, shared-budget exhaustion, and accurate partial-result reporting across multiple PRs. Coverage includes nested timeout exceptions with real duplicate identity matching, outer/nested JSON contract assertions for main and net11.0, stale/malformed merge-parent rejection, refreshed eligibility revocation, actual entrypoint mixed/all-unverifiable failure routing, preservation of completed results after queue-time revalidation failures, and dedupe/fixer source-head contract alignment. The readiness additions assert prompt requirements in both sources; they do not simulate agent execution.
  • A local stalled-HTTP-server repro confirms actual PowerShell Invoke-RestMethod timeout exceptions are recognized as transient after the fix. No Azure request was made by this repro.
  • PowerShell parse validation passed.
  • actionlint passed for the new dispatcher workflow. Direct linting of the generated fixer locks reports the same six pre-existing findings before and after this readiness change; the gh-aw actionlint wrapper returned tooling exit 125, not a clean lint result.
  • Both gh-aw v0.86.2 strict compile/no-emit checks passed for the readiness follow-up, and both locks were regenerated with zero compiler warnings. This follow-up changes only their body hashes, not workflow configuration.
  • Dry-run payload validation passed for all three pipeline definitions.
  • git diff --check passed.

Rollout notes

Merging enables the automation. Only pipeline 302 OIDC queueing has live proof so far. Azure DevOps Basic access and Queue builds permission for all three definitions, plus exact PR-head check association, remain rollout/canary requirements and should be verified after merge. No live build was queued by this PR-creation or review-follow-up work.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 5, 2026 17:00
@PureWeen
PureWeen deployed to copilot-pat-pool October 5, 2026 17:00 — with GitHub Actions Active
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

🚀 Dogfood this PR with:

⚠️ WARNING: Do not do this without first carefully reviewing the code of this PR to satisfy yourself it is safe.

curl -fsSL https://raw.githubusercontent.com/dotnet/maui/main/eng/scripts/get-maui-pr.sh | bash -s -- 39147

Or

  • Run remotely in PowerShell:
iex "& { $(irm https://raw.githubusercontent.com/dotnet/maui/main/eng/scripts/get-maui-pr.ps1) } 39147"

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
1 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@PureWeen
PureWeen deployed to copilot-pat-pool October 5, 2026 17:01 — with GitHub Actions Active
@PureWeen
PureWeen deployed to copilot-pat-pool October 5, 2026 17:02 — with GitHub Actions Active
@PureWeen
PureWeen deployed to copilot-pat-pool October 5, 2026 17:03 — with GitHub Actions Active
@PureWeen
PureWeen deployed to copilot-pat-pool October 5, 2026 17:05 — with GitHub Actions Active
@PureWeen
PureWeen deployed to copilot-pat-pool October 5, 2026 17:06 — with GitHub Actions Active

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Missing target-branch metadata can reduce net11 validation coverage, while concurrency and action-pinning issues weaken reliability and security.

Review effort: Balanced
Findings: 1 High severity · 2 Medium severity

Open (3)
What changed in this PR

Automates Azure DevOps validation for generated CI-fix PRs using trusted OIDC-based workflow execution.

Changes:

  • Queues three MAUI pipelines with deduplication and retry handling.
  • Adds Pester coverage for gating and queue payloads.
  • Updates fixer guidance, generated workflows, and setup documentation.
File Description
.github/​workflows/​ci-status-fix.md Documents automatic validation for main.
.github/​workflows/​ci-status-fix.lock.yml Regenerates the main compiled workflow.
.github/​workflows/​ci-status-fix-net11.md Documents automatic validation for net11.
.github/​workflows/​ci-status-fix-net11.lock.yml Regenerates the net11 compiled workflow.
.github/​workflows/​ci-fix-azdo-validation.yml Adds trusted validation orchestration.
.github/​scripts/​Queue-CiFixAzdoValidation.ps1 Implements authentication, gating, deduplication, and queueing.
.github/​scripts/​Queue-CiFixAzdoValidation.Tests.ps1 Tests fingerprinting, payloads, and reconciliation behavior.
.github/​docs/​trigger-azdo-pipeline-setup.md Documents configuration and token flow.

Comment thread .github/workflows/ci-fix-azdo-validation.yml Outdated
Comment thread .github/scripts/Queue-CiFixAzdoValidation.ps1
Comment thread .github/workflows/ci-fix-azdo-validation.yml

@kubaflo kubaflo left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

GPT-only empirical adversarial review of 820c6531907b - needs changes.

One additional P1 defect is documented inline: the workflow_run reconciliation path crashes before it can queue any validation. I reproduced it using actual public GitHub open-PR JSON and a real completed main-branch fixer payload, replaying only the HTTP response boundary locally with a noncredential placeholder. The full script's workflow_run -DryRun invocation throws Unexpected base repository ''. at line 106, reached through lines 232 and 553. Explicitly enumerating the same response changes one System.Object[] item into three PR objects and lets the scan complete.

Check Result
Existing PR Pester suite, Pester 5.9.0 28 passed
PowerShell parser; actionlint on the new workflow Passed
gh-aw v0.86.2 compile ci-status-fix ci-status-fix-net11 --no-emit --no-check-update --json Both passed
Full pull_request_target -DryRun path Produced the expected merge-ref, merge-SHA and source-head payloads for definitions 302, 313 and 314; no builds queued
Full workflow_run -DryRun path Reproduced the inline defect

CI evidence: required maui-pr is skipping, and there are no PR builds for definitions 302/313/314. PowerShell Script Tests has three failures, but all three are stale GPT-5.6 model assertions in unchanged base-branch inputs; I reproduced those same three failures locally and verified the relevant files are identical between this PR's base and head. This is not a clean-CI or live-rollout claim: OIDC queue permissions for all three definitions and actual PR-head check association still need a live canary.

I have not duplicated the existing action-pinning, target-branch metadata, or pending-concurrency feedback.

Comment thread .github/scripts/Queue-CiFixAzdoValidation.ps1 Outdated
@kubaflo

This comment has been minimized.

@kubaflo

kubaflo commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
3 pipeline(s) were filtered out due to trigger conditions.

@github-actions github-actions Bot added the s/agent-review-in-progress AI review is currently running for this PR label Oct 5, 2026
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Note

🔍 /review started

AzDO build 15570456 is running for android.

The s/agent-review-in-progress label stays on this PR while the run is active. The final recommendation and outcome labels are posted only after Gate, expert review, and Deep UI tests finish.

@MauiBot

This comment has been minimized.

@MauiBot MauiBot added s/agent-review-incomplete AI review did not complete all expected phases s/agent-reviewed PR was reviewed by AI agent workflow (full 4-phase review) and removed s/agent-review-in-progress AI review is currently running for this PR labels Oct 5, 2026
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 5, 2026 21:04

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment thread .github/workflows/ci-fix-azdo-validation.yml Outdated
Comment thread .github/workflows/ci-status-fix.md Outdated
Comment thread .github/scripts/Queue-CiFixAzdoValidation.ps1 Outdated
Comment thread .github/workflows/ci-status-fix.md Outdated
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 5, 2026 21:28
@kubaflo

This comment has been minimized.

@kubaflo

kubaflo commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

/azp run

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Deduplication can accept builds lacking the source-head metadata required by downstream fixer workflows, potentially stranding validation.

Review effort: Balanced
Findings: 1 High severity

Open (1)
Resolved since last review (1)

Comment thread .github/scripts/Queue-CiFixAzdoValidation.ps1 Outdated
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 6, 2026 07:43
@kubaflo

This comment has been minimized.

@kubaflo

kubaflo commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
3 pipeline(s) were filtered out due to trigger conditions.

@github-actions github-actions Bot added the s/agent-review-in-progress AI review is currently running for this PR label Oct 6, 2026
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Note

🔍 /review started

AzDO build 15580755 is running for android.

The s/agent-review-in-progress label stays on this PR while the run is active. The final recommendation and outcome labels are posted only after Gate, expert review, and Deep UI tests finish.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Both fixer variants can mark build-only UI/device fixes ready when the originating pipeline merely exists rather than completing successfully.

Review effort: Balanced
Findings: None

Resolved since last review (1)
Previously missed (2)

In code that hasn't changed since last review

Medium severity Require originating pipeline run to pass before advancing to T3

.github/​workflows/​ci-status-fix-net11.md:1220

This gate only checks that the originating UI/device pipeline build exists, then proceeds to T3 even if that matching run is still pending or has failed. A build-only fix for a 313/314 failure can therefore be marked ready without showing that the originating build break is fixed. Require the matching run’s relevant legs to be fully green before proceeding.

Medium severity Require originating pipeline run to pass before advancing to T3

.github/​workflows/​ci-status-fix.md:1204

This gate only checks that the originating UI/device pipeline build exists, then proceeds to T3 even if that matching run is still pending or has failed. A build-only fix for a 313/314 failure can therefore be marked ready without showing that the originating build break is fixed. Require the matching run’s relevant legs to be fully green before proceeding.

@MauiBot

This comment has been minimized.

@MauiBot MauiBot removed the s/agent-review-in-progress AI review is currently running for this PR label Oct 6, 2026
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 6, 2026 09:10

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The privileged CI infrastructure change still requires live canary verification for permissions and PR-check association.

Review effort: Balanced
Findings: None

@kubaflo

This comment has been minimized.

@kubaflo

kubaflo commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
3 pipeline(s) were filtered out due to trigger conditions.

@github-actions github-actions Bot added the s/agent-review-in-progress AI review is currently running for this PR label Oct 6, 2026
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Note

🔍 /review started

AzDO build 15581416 is running for android.

The s/agent-review-in-progress label stays on this PR while the run is active. The final recommendation and outcome labels are posted only after Gate, expert review, and Deep UI tests finish.

@MauiBot

MauiBot commented Oct 6, 2026

Copy link
Copy Markdown
Collaborator

AI Review Summary

@PureWeen — new AI review results are available based on commit d0cf55b.

Gate No Tests Confidence Unknown Platform Android


🗂️ Review Sessions — click to expand
🚦 Gate — Test Before & After Fix

Gate Result: ⚠️ SKIPPED

No tests were detected in this PR.

Recommendation: Add tests to verify the fix using the write-tests-agent.


📋 Pre-Flight — Context & Validation

⚠️ Pre-Flight did not produce output on this run.

The Copilot expert-review task ended before this phase was persisted, usually because the review-stage time budget expired or the CI agent encountered a transient authentication/runtime problem. Earlier completed sections remain valid, but this review is incomplete without this phase.

Next step: re-comment /review to retry on a fresh agent. If this repeats across runs, a maintainer should inspect the reviewer token and Task 3 logs.


🔬 Code Review — Deep Analysis

⚠️ Code Review did not produce output on this run.

The Copilot expert-review task ended before this phase was persisted, usually because the review-stage time budget expired or the CI agent encountered a transient authentication/runtime problem. Earlier completed sections remain valid, but this review is incomplete without this phase.

Next step: re-comment /review to retry on a fresh agent. If this repeats across runs, a maintainer should inspect the reviewer token and Task 3 logs.


🛠️ Try-Fix — Analysis & Comparison

⚠️ Try-Fix did not produce output on this run.

The Copilot expert-review task ended before this phase was persisted, usually because the review-stage time budget expired or the CI agent encountered a transient authentication/runtime problem. Earlier completed sections remain valid, but this review is incomplete without this phase.

Next step: re-comment /review to retry on a fresh agent. If this repeats across runs, a maintainer should inspect the reviewer token and Task 3 logs.


🏁 Report — Final Recommendation

⚠️ Report / Final Recommendation did not produce output on this run.

The Copilot expert-review task ended before this phase was persisted, usually because the review-stage time budget expired or the CI agent encountered a transient authentication/runtime problem. Earlier completed sections remain valid, but this review is incomplete without this phase.

Next step: re-comment /review to retry on a fresh agent. If this repeats across runs, a maintainer should inspect the reviewer token and Task 3 logs.


🧭 Next Steps — review latest findings

No alternative fix was selected for this run. Review the session findings and CI results before merging.

@MauiBot MauiBot removed the s/agent-review-in-progress AI review is currently running for this PR label Oct 6, 2026
@kubaflo
kubaflo merged commit f7530d0 into main Oct 6, 2026
7 of 10 checks passed
@kubaflo
kubaflo deleted the pureween-ci-fix-azdo-trigger branch October 6, 2026 10:38
@github-actions github-actions Bot added this to the .NET 10 SR12 milestone Oct 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

s/agent-review-incomplete AI review did not complete all expected phases s/agent-reviewed PR was reviewed by AI agent workflow (full 4-phase review)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants