Honor --source during template discovery - #19351
Adam Ratzman (adamint) merged 12 commits into
Conversation
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3eac62c7-af80-4c5b-b618-6a77db696f6c
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3eac62c7-af80-4c5b-b618-6a77db696f6c
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3eac62c7-af80-4c5b-b618-6a77db696f6c
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3eac62c7-af80-4c5b-b618-6a77db696f6c
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3eac62c7-af80-4c5b-b618-6a77db696f6c
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3eac62c7-af80-4c5b-b618-6a77db696f6c
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3eac62c7-af80-4c5b-b618-6a77db696f6c
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3eac62c7-af80-4c5b-b618-6a77db696f6c
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3eac62c7-af80-4c5b-b618-6a77db696f6c
|
🚀 Dogfood this PR with:
curl -fsSL https://raw.githubusercontent.com/microsoft/aspire/main/eng/scripts/get-aspire-cli-pr.sh | bash -s -- 19351Or
iex "& { $(irm https://raw.githubusercontent.com/microsoft/aspire/main/eng/scripts/get-aspire-cli-pr.ps1) } 19351" |
There was a problem hiding this comment.
Pull request overview
Updates template discovery and installation to honor aspire new --source, including relative local sources.
Changes:
- Replaces channel fallback feeds with the explicit source during discovery and installation.
- Resolves relative sources against the invocation directory.
- Adds focused unit and command tests.
Show a summary per file
| File | Description |
|---|---|
src/Aspire.Cli/Commands/InitCommand.cs |
Adapts template installation call. |
src/Aspire.Cli/Commands/NewCommand.cs |
Resolves and forwards source overrides. |
src/Aspire.Cli/Packaging/PackageChannel.cs |
Adds fallback-source replacement. |
src/Aspire.Cli/Packaging/PackageSourceOverrideMappings.cs |
Resolves relative source paths. |
src/Aspire.Cli/Templating/DotNetTemplateFactory.cs |
Forwards source during installation. |
src/Aspire.Cli/Templating/TemplateNuGetConfigService.cs |
Applies sources during discovery and installation. |
tests/Aspire.Cli.Tests/Commands/NewCommandTests.cs |
Tests command-level source handling. |
tests/Aspire.Cli.Tests/Packaging/PackageSourceOverrideMappingsTests.cs |
Tests Unix path resolution. |
tests/Aspire.Cli.Tests/Templating/TemplateNuGetConfigServiceTests.cs |
Tests fallback replacement. |
Review details
- Files reviewed: 9/9 changed files
- Comments generated: 1
- Review effort level: Balanced
|
Retrying the failed CI jobs for this pull request from the CI run attempt. The rerun is being tracked in the rerun attempt. |
|
Retrying the failed CI jobs for this pull request from the CI run attempt. The rerun is being tracked in the rerun attempt. |
|
Retrying the failed CI jobs for this pull request from the CI run attempt. The rerun is being tracked in the rerun attempt. |
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3eac62c7-af80-4c5b-b618-6a77db696f6c
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3eac62c7-af80-4c5b-b618-6a77db696f6c
Karol Zadora-Przylecki (karolz-ms)
left a comment
There was a problem hiding this comment.
Code review of --source handling during template discovery. 6 findings: 1 correctness gap that limits the fix to stable/implicit channels, 2 test-validity/robustness issues in the new E2E, 1 missing input validation, 1 API-hazard/doc-accuracy note, and 1 coverage gap.
No blocking objection to the direction — the implicit/stable path is clearly improved — but finding 1 is worth resolving or documenting before merge, since it means the reported scenario is still broken for daily/staging CLIs.
Make explicit sources exclusive for template discovery and installation, validate local directories, and cover pinned channels and real CLI traffic. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
f721513
into
microsoft:main
|
/backport to release/13.5 |
|
Started backporting to |
PR Testing ReportPR Information
Artifact Version Verification
Changes AnalyzedFiles ChangedSource (all under
Tests:
Change Categories
Mechanism (what the fix does)
Test Environment
Test Scenarios ExecutedScenario 1: Absolute
|
| Scenario | Coverage | Status | Key evidence |
|---|---|---|---|
1 — Absolute --source = PR hive |
Happy | ✅ Passed | discovery ran; apphost.cs; no nuget.org |
2 — Relative source-feed (staging emu) |
Happy (core) | ✅ Passed | searched only source-feed; relative resolved; no nuget.org |
| 2b — Successful staging synth | Happy (definitive) | ✅ Passed | searched [dnceng, source-feed]; NuGet.org catch-all replaced; no nuget.org |
3 — Invalid --source |
Unhappy | ✅ Passed | only bad source searched; no nuget.org fallback; clean fail (exit 1) |
Cross-cutting check: grep of all scenario logs for api.nuget.org → zero matches (matches the PR E2E's assertion ! grep -R -F 'api.nuget.org' logs).
Overall Result
✅ PR VERIFIED
--source is now honored throughout template version discovery and installation: it replaces the selected channel's NuGet.org catch-all (Scenario 2b), works with relative feed paths (Scenarios 2 & 3), and — critically for the reported bug — prevents any fallback to NuGet.org, whether the source is valid (Scenarios 1/2/2b) or invalid (Scenario 3). Behavior matches the PR's own E2E and unit tests.
Notes / Caveats
- Testing was performed on Windows using debug-log inspection for the "no NuGet.org" assertion (the network tripwire in the PR's Linux E2E is not reproducible on the host). Sources actually queried are logged verbatim by
aspire-managed nuget search, so the assertion is direct rather than inferred. aspire-emptyuses an embedded template body, so these scenarios validate the version-discovery / source-selection path (the code this PR changes). The end-to-end package install path via--sourceis covered by the PR's own unit/E2E tests.
Description
aspire new --sourcecurrently ignores the explicit source while resolving template versions and can contact NuGet.org from an isolated temporary configuration. This breaks project creation in environments where NuGet.org is blocked and package traffic must use an approved proxy.This change makes the explicit source exclusive for template discovery and installation, including pinned daily, staging, local, and PR channels. The selected channel identity stays unchanged when a channel is requested; without one, the implicit channel owns the result so stale hives cannot attach an unrelated channel identity.
Relative local sources are resolved against the invocation working directory. Missing local directories now fail before discovery or scaffolding, while HTTP sources and
file:URIs keep their existing forms.User-facing usage
With an explicit source, template discovery and installation use only that source. The generated project still maps
Aspire*to the explicit source and retains the selected channel's non-Aspire fallback for later restores.Validation
13.5.0+11a1277e...staging CLI.Aspire.ProjectTemplatesfrom one explicit local feed while TCP tripwires for NuGet.org andpkgs.dev.azure.comremain untouched.--source nuget.orgtypo.file:URIs, and Windows fully qualified paths.Aspire.Cli.Tests: 4,944 passed, 33 platform-specific skipped.Fixes #19338
Checklist
<remarks />and<code />elements on your triple slash comments?