Skip to content

CI-fix automation: Fix startup deadlines and producer helper guidance - #39188

Merged
kubaflo merged 3 commits into
mainfrom
pureween-ci-fix-startup-deadline
Oct 6, 2026
Merged

kubaflo merged 3 commits into
mainfrom
pureween-ci-fix-startup-deadline

Conversation

@PureWeen

@PureWeen PureWeen commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

Note

Are you waiting for the changes in this PR to be merged?
It would be very helpful if you could test the resulting artifacts from this PR and let us know in a comment if this change resolves your issue. Thank you!

Description of Change

Fix a confirmed startup-deadline regression in the CI-fix Azure DevOps dispatcher introduced by #39147, and correct a separate, pre-existing producer prompt contradiction that blocks mandatory safe-output registration.

Production evidence: run 37477952193 spent approximately 533 seconds between starting the 420-second deadline and completing trusted checkout; run 37485076087 spent approximately 494 seconds. Both then failed with The variable cannot be validated because the value 0 is not a valid value for the DispatcherBudgetSeconds variable.

Root cause: The script parameter [ValidateRange(1, 540)][int]$DispatcherBudgetSeconds and top-level $script:DispatcherBudgetSeconds are the same validated PowerShell variable. Clamping valid caller input 420 against an already-expired absolute deadline assigns 0 to that variable, triggering validation before explicit budget-exhaustion reporting can run. Extracted helper tests did not exercise this entrypoint initialization.

Correction:

  • Store the clamped runtime allowance in the distinct EffectiveDispatcherBudgetSeconds variable and update remaining-budget helpers and their extracted-test state consistently. Caller budget 0 remains invalid.
  • Fail startup explicitly with [dispatcher-budget-exhausted] when preparation has consumed the deadline, before PR discovery, authentication, HTTP, or sleep. Write a failed preparation/deadline job summary and state No queue POST was attempted. This also fails rather than claiming successful no-work reconciliation when the deadline is expired.
  • Limit trusted checkout to the standalone /.github/scripts/Queue-CiFixAzdoValidation.ps1 using non-cone sparse checkout. The existing SHA-pinned checkout v7.0.1 supports exact patterns and automatically uses blob:none for sparse fetches. Preserve github.sha, fetch-depth: 1, and persist-credentials: false; never fetch or execute PR code.
  • Document preparation behavior and limitations. Keep the absolute pre-checkout 420-second deadline and ten-minute hard job timeout unchanged; do not restart or extend either allowance.

Validation: Baseline dispatcher suite: 73 passed. Before the script correction, the six new actual-entrypoint cases produced four expected expired-deadline failures with the original validation exception and two passing caller-validation/future-deadline cases. After correction, all 79 tests passed, including existing helper/queue regressions. Expired cases assert the preparation summary, explicit prefix, no-POST message, and zero HTTP/sleep calls; a native PowerShell process asserts nonzero exit. The valid future deadline still produces the three verified offline pipeline payloads.

Exact final commands and results:

pwsh -NoProfile -Command '$env:PSModulePath = "/Users/shneuvil/.copilot/session-state/237fbb01-6532-4170-9f5e-6af14fa3a5e0/files/powershell-modules" + [IO.Path]::PathSeparator + $env:PSModulePath; Import-Module Pester -ErrorAction Stop; Invoke-Pester -Path .github/scripts/Queue-CiFixAzdoValidation.Tests.ps1 -Output Normal -CI'
# Passed: 79; failed/skipped: 0. Reused existing Pester; no dependency installation.

pwsh -NoProfile -Command '$files = @(".github/scripts/Queue-CiFixAzdoValidation.ps1", ".github/scripts/Queue-CiFixAzdoValidation.Tests.ps1"); foreach ($file in $files) { $tokens = $null; $errors = $null; [void][System.Management.Automation.Language.Parser]::ParseFile((Join-Path $PWD $file), [ref]$tokens, [ref]$errors); if ($errors.Count) { $errors | ForEach-Object { Write-Error $_ }; exit 1 }; Write-Output "Parse passed: $file" }'
# Passed: both PowerShell files parsed without errors.
actionlint .github/workflows/ci-fix-azdo-validation.yml
# Passed.
git diff --check
# Passed.

Limits: The sparse-checkout assertion is a static configuration/trust regression, not a hosted checkout timing measurement. Production checkout performance remains unproven; checkout or PowerShell startup exceeding the ten-minute hard guard can still cancel the job before a summary is written. No live Azure queue requests, manual workflow dispatches/reruns, /azp requests, or credential/permission/model-policy changes were performed. There is still no successful eligible-PR Azure canary evidence here; this PR does not establish Azure permissions or exact-head check linkage for any of the three pipelines.

Related producer blocker (pre-existing, not introduced by #39147): main producer run 37464881821 and net11 producer run 37465231994 concluded success but emitted missing_tool / report_incomplete. The net11 diagnostic explicitly says mandatory expectation registration requires PowerShell but the run instructions exclude it. The main diagnostic likewise reports the prompt-specific no-pwsh restriction, alongside separate unavailable cited Azure timeline evidence. This is an upstream producer blocker: a compliant PR cannot reach dispatcher validation if required registration is prohibited by its own prompt.

Both producers already allow pwsh in tools.bash, and Hard Rule 11 requires Register-CiFixSafeOutputExpectation.ps1 or atomic validation/registration via Test-CiFixTransport.ps1. Their bottom Environment constraints sections nevertheless said no pwsh. The mirrored correction changes only that prose: explicitly identify pwsh availability for those deterministic helpers, retain no gh / no python and curl + jq API guidance, and reiterate existing fail-closed registration/transport requirements. No tool allowlists, network, permissions, credentials, trust, model policy, or output gates change.

Added two assertions in the existing registration test suite protecting both producer twins. Both failed on the old contradictory guidance and pass after correction. Regenerated both locks with retained gh-aw v0.86.2, without manual edits or compiler upgrade; only body_hash changes. Frontmatter and all generated lock runtime content remain identical.

Additional exact validation commands and results:

pwsh -NoProfile -Command '$env:PSModulePath = "/Users/shneuvil/.copilot/session-state/237fbb01-6532-4170-9f5e-6af14fa3a5e0/files/powershell-modules" + [IO.Path]::PathSeparator + $env:PSModulePath; Import-Module Pester -ErrorAction Stop; $config = New-PesterConfiguration; $config.Run.Path = @(".github/scripts/Register-CiFixSafeOutputExpectation.Tests.ps1", ".github/scripts/Test-CiFixTransport.Tests.ps1", ".github/scripts/Queue-CiFixAzdoValidation.Tests.ps1"); $config.Run.Exit = $true; $config.Output.Verbosity = "Normal"; $config.TestResult.Enabled = $true; $config.TestResult.OutputPath = "/Users/shneuvil/.copilot/session-state/1e0cc90a-a521-4055-9e7a-9565cdaf5504/files/producer-and-dispatcher-pester-results.xml"; Invoke-Pester -Configuration $config'
# Passed after lock regeneration: 116 tests (6 registration, 31 transport, 79 dispatcher); 0 failed/skipped.

pwsh -NoProfile -Command '$file = Join-Path $PWD ".github/scripts/Register-CiFixSafeOutputExpectation.Tests.ps1"; $tokens = $null; $errors = $null; [void][System.Management.Automation.Language.Parser]::ParseFile($file, [ref]$tokens, [ref]$errors); if ($errors.Count) { $errors | ForEach-Object { Write-Error $_ }; exit 1 }; Write-Output "PowerShell parse passed"'
# Passed.
/Users/shneuvil/.copilot/session-state/237fbb01-6532-4170-9f5e-6af14fa3a5e0/files/tools/gh-aw-0.86.2/darwin-arm64 compile ci-status-fix ci-status-fix-net11 --strict --no-emit --no-check-update
# Passed: 2 workflows, 0 warnings.
/Users/shneuvil/.copilot/session-state/237fbb01-6532-4170-9f5e-6af14fa3a5e0/files/tools/gh-aw-0.86.2/darwin-arm64 compile ci-status-fix ci-status-fix-net11 --strict --no-check-update
# Passed: 2 workflows, 0 warnings; emitted body-hash-only changes.
actionlint .github/workflows/ci-status-fix.lock.yml .github/workflows/ci-status-fix-net11.lock.yml
# Nonzero both before and after regeneration: identical six baseline diagnostics.
# Each twin: concurrency.queue not recognized, ShellCheck SC2129 style, github.aw expression not recognized.
# No new lint findings; baseline/after outputs compared byte-identical.

Producer limits: These are static prompt/configuration assertions and offline helper tests, not a hosted agent behavior evaluation. Removing the contradiction does not guarantee that an agent will register correctly, find a viable product fix, create a PR, or attach Azure checks. Separate cited-timeline failures and other producer blockers are not fixed here. No live workflow or network validation tests were run.

Issues Fixed

Follow-up to #39147 for the production startup regression evidenced by the two linked dispatcher runs, plus the separate pre-existing producer helper-guidance contradiction evidenced by the two producer runs. No separate tracking issue is closed by this PR.

Separate the validated caller budget from effective remaining time and report expired preparation deadlines before discovery or authentication. Sparse-check out only the trusted standalone dispatcher script without changing the absolute deadline or hard job timeout.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 1e0cc90a-a521-4055-9e7a-9565cdaf5504
Copilot AI balanced review requested due to automatic review settings October 6, 2026 15:32
@PureWeen
PureWeen deployed to copilot-pat-pool October 6, 2026 15:32 — with GitHub Actions Active
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
1 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

🚀 Dogfood this PR with:

⚠️ WARNING: Do not do this without first carefully reviewing the code of this PR to satisfy yourself it is safe.

curl -fsSL https://raw.githubusercontent.com/dotnet/maui/main/eng/scripts/get-maui-pr.sh | bash -s -- 39188

Or

  • Run remotely in PowerShell:
iex "& { $(irm https://raw.githubusercontent.com/dotnet/maui/main/eng/scripts/get-maui-pr.ps1) } 39188"

@PureWeen
PureWeen deployed to copilot-pat-pool October 6, 2026 15:32 — with GitHub Actions Active
@PureWeen
PureWeen deployed to copilot-pat-pool October 6, 2026 15:38 — with GitHub Actions Active
@PureWeen
PureWeen deployed to copilot-pat-pool October 6, 2026 15:40 — with GitHub Actions Active

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Hosted checkout behavior and current CI results remain independently unverified for this privileged dispatcher workflow.

Review effort: Balanced
Findings: None

What changed in this PR

Fixes the CI-fix dispatcher startup-deadline regression introduced by #39147 without extending its time limits.

Changes:

  • Separates validated caller input from the effective runtime budget and explicitly reports startup exhaustion.
  • Restricts trusted checkout to the dispatcher script.
  • Adds entrypoint regression tests and documents preparation limits.
File Description
.github/​workflows/​ci-fix-azdo-validation.yml Adds exact-file sparse checkout.
.github/​scripts/​Queue-CiFixAzdoValidation.Tests.ps1 Tests startup deadlines and checkout configuration.
.github/​scripts/​Queue-CiFixAzdoValidation.ps1 Separates budget state and reports expired startup deadlines.
.github/​docs/​trigger-azdo-pipeline-setup.md Documents preparation behavior and timing limitations.

@PureWeen
PureWeen deployed to copilot-pat-pool October 6, 2026 15:41 — with GitHub Actions Active
@PureWeen
PureWeen deployed to copilot-pat-pool October 6, 2026 15:42 — with GitHub Actions Active
@kubaflo

This comment has been minimized.

@kubaflo

kubaflo commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
3 pipeline(s) were filtered out due to trigger conditions.

@github-actions github-actions Bot added the s/agent-review-in-progress AI review is currently running for this PR label Oct 6, 2026
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Note

🔍 /review started

AzDO build 15583776 is running for android.

The s/agent-review-in-progress label stays on this PR while the run is active. The final recommendation and outcome labels are posted only after Gate, expert review, and Deep UI tests finish.

@MauiBot

This comment has been minimized.

@MauiBot MauiBot added s/agent-review-incomplete AI review did not complete all expected phases s/agent-reviewed PR was reviewed by AI agent workflow (full 4-phase review) and removed s/agent-review-in-progress AI review is currently running for this PR labels Oct 6, 2026
Remove the prose contradiction that excludes an already allowed pwsh command required for deterministic safe-output registration and transport checks. Preserve tool and policy configuration, cover both producer prompts, and regenerate body hashes using gh-aw v0.86.2.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 1e0cc90a-a521-4055-9e7a-9565cdaf5504
Copilot AI balanced review requested due to automatic review settings October 6, 2026 18:04
@PureWeen PureWeen changed the title CI-fix dispatcher: Handle deadline exhaustion during startup CI-fix automation: Fix startup deadlines and producer helper guidance Oct 6, 2026
@kubaflo

This comment has been minimized.

@kubaflo

kubaflo commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
3 pipeline(s) were filtered out due to trigger conditions.

@github-actions github-actions Bot added the s/agent-review-in-progress AI review is currently running for this PR label Oct 6, 2026
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Note

🔍 /review started

AzDO build 15585506 is running for android.

The s/agent-review-in-progress label stays on this PR while the run is active. The final recommendation and outcome labels are posted only after Gate, expert review, and Deep UI tests finish.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Shared CI behavior still needs hosted validation and human review, with an unresolved test-portability defect.

Review effort: Balanced
Findings: None

Previously missed (1)

In code that hasn't changed since last review

Medium severity Support CRLF line endings in workflow assertion

.github/​scripts/​Queue-CiFixAzdoValidation.Tests.ps1:210

With a CRLF checkout (for example, Windows with core.autocrlf=true), this assertion fails even when the workflow is correct. Get-Content -Raw preserves the \r after false, but .NET's multiline $ anchor matches before \n, not before \r\n. The repository's .gitattributes does not force workflow files to LF. Allow \r? before the final $, matching the preceding lines' handling of line endings.

@MauiBot

This comment has been minimized.

@MauiBot MauiBot removed the s/agent-review-in-progress AI review is currently running for this PR label Oct 6, 2026
Accept the optional carriage return before the final multiline anchor and exercise the trusted sparse-checkout assertion with both LF and CRLF input. Reproduces and addresses top-level Copilot review 5432776264 without changing runtime behavior.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 1e0cc90a-a521-4055-9e7a-9565cdaf5504
Copilot AI balanced review requested due to automatic review settings October 6, 2026 20:35

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Hosted checkout and producer behavior remain unverified, so these shared CI automation changes require human approval.

Review effort: Balanced
Findings: None

@kubaflo

This comment has been minimized.

@kubaflo

kubaflo commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
3 pipeline(s) were filtered out due to trigger conditions.

@github-actions github-actions Bot added the s/agent-review-in-progress AI review is currently running for this PR label Oct 6, 2026
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Note

🔍 /review started

AzDO build 15588321 is running for android.

The s/agent-review-in-progress label stays on this PR while the run is active. The final recommendation and outcome labels are posted only after Gate, expert review, and Deep UI tests finish.

@MauiBot

MauiBot commented Oct 6, 2026

Copy link
Copy Markdown
Collaborator

AI Review Summary

@PureWeen — new AI review results are available based on commit ddc5d50.

Gate No Tests Confidence Unknown Platform Android


🗂️ Review Sessions — click to expand
🚦 Gate — Test Before & After Fix

Gate Result: ⚠️ SKIPPED

No tests were detected in this PR.

Recommendation: Add tests to verify the fix using the write-tests-agent.


📋 Pre-Flight — Context & Validation

⚠️ Pre-Flight did not produce output on this run.

The Copilot expert-review task ended before this phase was persisted, usually because the review-stage time budget expired or the CI agent encountered a transient authentication/runtime problem. Earlier completed sections remain valid, but this review is incomplete without this phase.

Next step: re-comment /review to retry on a fresh agent. If this repeats across runs, a maintainer should inspect the reviewer token and Task 3 logs.


🔬 Code Review — Deep Analysis

⚠️ Code Review did not produce output on this run.

The Copilot expert-review task ended before this phase was persisted, usually because the review-stage time budget expired or the CI agent encountered a transient authentication/runtime problem. Earlier completed sections remain valid, but this review is incomplete without this phase.

Next step: re-comment /review to retry on a fresh agent. If this repeats across runs, a maintainer should inspect the reviewer token and Task 3 logs.


🛠️ Try-Fix — Analysis & Comparison

⚠️ Try-Fix did not produce output on this run.

The Copilot expert-review task ended before this phase was persisted, usually because the review-stage time budget expired or the CI agent encountered a transient authentication/runtime problem. Earlier completed sections remain valid, but this review is incomplete without this phase.

Next step: re-comment /review to retry on a fresh agent. If this repeats across runs, a maintainer should inspect the reviewer token and Task 3 logs.


🏁 Report — Final Recommendation

⚠️ Report / Final Recommendation did not produce output on this run.

The Copilot expert-review task ended before this phase was persisted, usually because the review-stage time budget expired or the CI agent encountered a transient authentication/runtime problem. Earlier completed sections remain valid, but this review is incomplete without this phase.

Next step: re-comment /review to retry on a fresh agent. If this repeats across runs, a maintainer should inspect the reviewer token and Task 3 logs.


🧭 Next Steps — review latest findings

No alternative fix was selected for this run. Review the session findings and CI results before merging.

@MauiBot MauiBot removed the s/agent-review-in-progress AI review is currently running for this PR label Oct 6, 2026
@kubaflo
kubaflo merged commit 7d38fd0 into main Oct 6, 2026
8 of 11 checks passed
@kubaflo
kubaflo deleted the pureween-ci-fix-startup-deadline branch October 6, 2026 22:36
@github-actions github-actions Bot added this to the .NET 10 SR12 milestone Oct 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

s/agent-review-incomplete AI review did not complete all expected phases s/agent-reviewed PR was reviewed by AI agent workflow (full 4-phase review)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants