You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This PR tightens PR test selection for inputs that were unnecessarily selecting the full regular PR-CI matrix. The audit used select-tests-selection-Linux artifacts so fork PRs and PRs without selector comments were included.
The rule of thumb stays conservative: if an input can affect broad build/test behavior, or if the consumer boundary is unclear, it still selects ALL.
What changed
Class
New behavior
Artifact producer workflows
.github/workflows/build-packages.yml selects NuGet artifact consumers; build-cli-native-archives.yml selects native CLI archive consumers. Native dashboard validation is only on the CLI-archive route.
Dev/AzDO/scheduled-only inputs
.config/dotnet-tools.json, eng/Version.Details.xml, and scheduled/deployment-only local actions are skipped by the regular GitHub PR-CI prefilter.
eng/common
All eng/common/** changes select ALL because this is shared Arcade/build infrastructure.
Regular PR-CI local actions
enumerate-tests selects all managed .NET test projects only; check-changed-files and select-tests select Infrastructure.Tests; setup-deno selects Hosting.JavaScript and extension E2E; macOS keychain setup remains ALL.
Broad/safety-sensitive inputs
Aspire.slnx, .gitattributes, shared MSBuild/build inputs, shared test fixtures, and matrix/runner infrastructure still select ALL.
Safety checks added
Artifact-consuming test projects and selector-gated jobs are derived from the evaluated graph and tests.yml wiring.
DOTNET_TESTS is pinned to managed test projects only and does not trigger non-.NET derived jobs.
Regular PR-CI local actions are tested against their explicit consumer routes.
eng/common/**, .gitattributes, and Aspire.slnx full-matrix behavior is pinned.
New skip-entirely paths have focused prefilter assertions.
Notes for reviewers
src/Shared/Utf8JsonWriterExtensions.cs was identified as an orphan shared-source file that can hit the run-all fallback when touched. This PR does not remove or enforce orphan shared files; that should be investigated separately if needed.
The catch-all ALL rules are split by rationale so future changes can narrow one class without re-auditing unrelated inputs.
This pattern accepts any directory segment named Shared, not specifically src/Shared. For example, the existing $(RepoRoot)tests\Shared\Playwright\TestUtils.cs include matches and contributes Playwright/TestUtils.cs; an orphan with that relative path under src/Shared would therefore pass this guard. Resolve or otherwise validate each captured include against src/Shared before adding its tail to the matcher.
The audit's own exemption list treated Aspire.slnx as correct-by-design
alongside genuinely build-wide inputs like Directory.Packages.props. A
local dry run against main -- run with the in-flight check disabled and
no knowledge of PR microsoft#20322 -- proved that reasoning wrong: Layer 1 already
roots its project graph at Aspire.slnx at the PR head, so an added
project carries no signal the graph does not already have, and only the
removal direction still needs the run-all fallback.
That analogy is exactly the failure mode the exemption list already
warns against for .gitattributes: a file exempted because it "sounds
build-wide" rather than because its actual consumers were read. Drop
Aspire.slnx from the list and cite the reasoning inline, so it is judged
like any other candidate.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Ankit Jain (radical)
changed the title
fix(ci): stop four inputs from escalating PR test selection to ALL
fix(ci): tighten PR test selection to avoid unnecessary full runs
Sep 23, 2026
The guard can pass without protecting the intended pattern: StartsWith("*.verified.*") accepts a different pattern such as *.verified.*.bak, and substring matching accepts an unrelated attribute such as foo=eol=lf. Parse whitespace-delimited fields and require the exact pattern and exact eol=lf token.
This issue also appears on line 41 of the same file.
This guard only finds consumers when the flags appear literally in each .csproj. The repository's CI-property contract also allows RequiresNugets/RequiresCliArchive to be set in Directory.Build.props (eng/testing/CITestsProperties.props:13), so a future consumer declared there can be omitted from BUILD_ARTIFACT_CONSUMERS while this test still passes. Evaluate the effective MSBuild properties or include the supported imported props in the consumer discovery.
This pattern accepts any path containing a Shared segment, including tests/Shared, and then matches only the captured tail against src/Shared. A tests/Shared/Foo.cs Compile Include could therefore make an unrelated orphaned src/Shared/Foo.cs appear consumed, allowing the guard to pass while the selector still escalates that source change to ALL. Resolve each Include against its containing project/import file and only add entries whose resolved path is under src/Shared.
Tighten the curated CI selector map so clear-cut infrastructure changes
no longer force the whole PR matrix when a narrower consumer set is known.
Artifact producer workflows now route to the regular PR jobs that consume
those artifacts instead of selecting ALL. Dev-only, AzDO-only, and
scheduled-only inputs are either ignored by the selector or dropped by the
shared CI prefilter so they do not fall into the run-all fallback.
Keep conservative routing for inputs that can affect the whole build or
where the boundary is intentionally broad. In particular, eng/common/** now
selects ALL because it is shared Arcade/build infrastructure that can be
updated as a unit outside this repo.
Add DOTNET_TESTS as a selector sentinel for infrastructure that enumerates
only the managed test-project matrix. enumerate-tests uses this target so it
re-runs every .NET test project without also selecting extension, installer,
polyglot, or other non-.NET PR-gated jobs.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Add regression coverage for the narrowed selector routes so future map
changes fail loudly when they over-select or under-select.
The tests now pin artifact producer consumers, local composite action
routing, eng/common full-matrix behavior, and the DOTNET_TESTS sentinel. The
DOTNET_TESTS coverage verifies the exact failure mode this target is meant to
avoid: selecting every managed test project without selecting non-.NET jobs
or triggering derived job targets.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
This PR tightens PR test selection for inputs that were unnecessarily selecting the full regular PR-CI matrix. The audit used
select-tests-selection-Linuxartifacts so fork PRs and PRs without selector comments were included.The rule of thumb stays conservative: if an input can affect broad build/test behavior, or if the consumer boundary is unclear, it still selects
ALL.What changed
.github/workflows/build-packages.ymlselects NuGet artifact consumers;build-cli-native-archives.ymlselects native CLI archive consumers. Native dashboard validation is only on the CLI-archive route..config/dotnet-tools.json,eng/Version.Details.xml, and scheduled/deployment-only local actions are skipped by the regular GitHub PR-CI prefilter.eng/commoneng/common/**changes selectALLbecause this is shared Arcade/build infrastructure.enumerate-testsselects all managed .NET test projects only;check-changed-filesandselect-testsselectInfrastructure.Tests;setup-denoselects Hosting.JavaScript and extension E2E; macOS keychain setup remainsALL.Aspire.slnx,.gitattributes, shared MSBuild/build inputs, shared test fixtures, and matrix/runner infrastructure still selectALL.Safety checks added
tests.ymlwiring.DOTNET_TESTSis pinned to managed test projects only and does not trigger non-.NET derived jobs.eng/common/**,.gitattributes, andAspire.slnxfull-matrix behavior is pinned.Notes for reviewers
src/Shared/Utf8JsonWriterExtensions.cswas identified as an orphan shared-source file that can hit the run-all fallback when touched. This PR does not remove or enforce orphan shared files; that should be investigated separately if needed.ALLrules are split by rationale so future changes can narrow one class without re-auditing unrelated inputs.Verification
Result:
273/273passed.Fixes # (issue)
Checklist
<remarks />and<code />elements on your triple slash comments?