Skip to content

[release/13.6] Fix duplicate inherited ATS method exports - #20443

Closed
David Pine (IEvangelist) wants to merge 9 commits into
release/13.6from
ievangelist-automatic-guacamole
Closed

David Pine (IEvangelist) wants to merge 9 commits into
release/13.6from
ievangelist-automatic-guacamole

Conversation

@IEvangelist

@IEvangelist David Pine (IEvangelist) commented Sep 24, 2026 •

Copy link
Copy Markdown
Member

Description

Backport of #20438 to release/13.6 fixing false duplicate-capability diagnostics from inherited ATS methods, plus a distinct Radius overload target-specificity defect. These block strict SDK inspection/API ingestion in microsoft/aspire.dev#1599.

The initial fix is an exact cherry-pick -x of cbaabf400506c0b36d3fbc8748b6076dfe0673cd, committed as 320eed42f85a7d4b090a9429b98c7a6a8547a4b8 on release base a11eca9611073f7cf66fa87faac63c2119e87713. Radius follow-up: 435fd4eb7d06ef99702ae5106cf01c10f5c6a780, also ported/tested on the main PR as 5482164dc1225f3c2a1a93bf5055e11b720117e9. No version edits or unrelated main/14.0 changes are included. Only three files change: the ATS scanner, existing scanner test class, and inheritance regression file.

The scan-scope-aware guard skips an inherited method projection only when an exported base included in the scan owns the same capability ID. It preserves aliases, unexported/unscanned bases, assembly-level exports and overrides. Genuine conflicting declarations still produce errors. Generated IDs/public API/schema and the separate AtsContextFilter diagnostic-ownership behavior remain unchanged.

Radius follow-up: inherited target specificity

Radius has a ProjectResource-specific withContainerImage export and a generic IDotnetProgramResource export with the same intended guest name. Exact ProjectResource precedence already worked. But CSharpAppResource inherits ProjectResource: neither declared target exactly matched the subclass, so collision handling globally removed the generic capability, including its nonconflicting DotnetProjectResource target.

When no exact target exists, recognize a unique strictly more-specific declared target and reuse existing per-target shadowing. Unrelated/equally specific targets still produce ambiguity diagnostics. No Radius allowlist, source-package mutation, or error suppression.

Compatibility: both wire IDs stay unchanged: Aspire.Hosting.Radius/withContainerImage for ProjectResource/CSharpAppResource and Aspire.Hosting.Radius/withDotnetProgramContainerImage for DotnetProjectResource. The guest API remains .withContainerImage(image). No Radius export attribute/public signature changes. Ignoring the legacy overload would instead remove an existing dispatch ID.

Observable behavior

Real metadata-only dumps using the locally corrected release host and genuine 13.6.0-preview.1.26473.12 packages:

Package/context CLI exit Diagnostics Result
Network 0 0 8,075 capabilities; three correct AddTo IDs
Kusto 0 0 654 capabilities
Radius + Dotnet supporting context 0 0 Both real Radius image capability IDs, correct receiver targets

Radius canonical TypeScript export also exits 0 with genuine generator 13.6.0-preview.1.26473.12+a11eca9611073f7cf66fa87faac63c2119e87713. Its single-package context is not represented as including Dotnet; compound raw scanning supplies that support context. No output JSON was modified or synthetic method invented.

Shipping dependencies

Draft pending maintainer review, merge-order approval, latest-commit CI and official release packaging. #20438 remains open and was not merged by us. This PR does not claim final release readiness.

The local layout is a test harness, not a coherent published bundle. After official rebuilding, repeat exact-version Network/Kusto full/scoped and Radius+Dotnet compound checks against distributed CLI/RemoteHost binaries before promoting docs API data.

Fixes # (issue)

Checklist

  • Is this feature complete?
    • Yes. Ready to ship.
    • No. Follow-up changes expected.
  • Are you including unit tests for the changes and scenario tests if relevant?
    • Yes
    • No
  • Did you add public API?
    • Yes
      • If yes, did you have an API Review for it?
        • Yes
        • No
      • Did you add <remarks /> and <code /> elements on your triple slash comments?
        • Yes
        • No
    • No
  • Does the change make any security assumptions or guarantees?
    • Yes
      • If yes, have you done a threat model and had a security review?
        • Yes
        • No
    • No

Implementation is complete; readiness remains "No" because review/CI/official packaging gates are outstanding.

Customer Impact

Network/Kusto false duplicate exports break fail-closed inspection and cause first-wins inherited ownership. Radius's subclass collision also removes a legitimate generic SDK method from unrelated implementing resources. These fixes preserve actual APIs and wire compatibility rather than permitting partial dumps.

Testing

  • 215 targeted tests passed on actual release source at 435fd4eb7d06ef99702ae5106cf01c10f5c6a780, 0 failed/skipped: scanner, dispatcher, context-filter and API-export classes. Quarantined/outerloop excluded. Equivalent main follow-up independently passed 215.
  • Includes the initial 11 inheritance cases plus base/child/grandchild specificity, unrelated implementing resources, both scan entry paths, registered MethodInfo invocation and retained unrelated-interface ambiguity. New specificity regression failed before the correction.
  • Genuine exact Radius/Hosting/Dotnet package fixture verifies both wire IDs, image-annotation replacement and same-builder semantics. Complete generated TypeScript SDK and .withContainerImage() usage compile.
  • Targeted local corrected managed RemoteHost rebuild succeeded with 0 warnings/errors and honest 13.6.0-dev identity; not a full product build or pack/publish run.
  • Real compound Radius+Dotnet dump and canonical Radius export passed as above; normal prebuilt-host package loading, not repository project substitution or identity spoofing.
  • Earlier actual Network/Kusto metadata dumps and all three AddTo dispatch checks passed; git diff --check clean.

The harness's existing dashboard/DCP entries are discovery-only; no application/cloud workload, dashboard, DCP workload, provisioning or deployment ran. Only metadata-scanning RPC hosts ran. Official release-binary validation remains required.

Risk

Bounded shared ATS discovery changes with coverage for aliases, absent bases, overrides, assembly-level exports, specific inherited targets and genuine ambiguities. No public API/schema or guest/wire rename. CI and official rebuilt-binary validation remain necessary.

Regression?

Failures reproduced with genuine 13.6.0-preview.1.26473.12 packages. The Radius issue predates the AddTo fix and stems from missing inherited concrete-target precedence. No confirmed introducing version is claimed for the original duplicate-export defect.

## Description

Please include a summary of the changes and the related issue. Please
also include relevant motivation and context. List any dependencies that
are required for this change.

Fixes # (issue)

## Checklist

- Is this feature complete?
  - [ ] Yes. Ready to ship.
  - [ ] No. Follow-up changes expected.
- Are you including unit tests for the changes and scenario tests if
relevant?
  - [ ] Yes
  - [ ] No
- Did you add public API?
  - [ ] Yes
    - If yes, did you have an API Review for it?
      - [ ] Yes
      - [ ] No
- Did you add `<remarks />` and `<code />` elements on your triple slash
comments?
      - [ ] Yes
      - [ ] No
  - [ ] No
- Does the change make any security assumptions or guarantees?
  - [ ] Yes
    - If yes, have you done a threat model and had a security review?
      - [ ] Yes
      - [ ] No
  - [ ] No
Backport of #19847 to release/13.6

/cc @eerhardt

## Customer Impact

Bundled (Native AOT) Aspire CLI installs run NuGet search, restore, and
manifest generation through the `aspire-managed` helper, which pollutes
the dependencies in `aspire-managed`. As a result, user's integrations
dependencies can get mangled with NuGet's dependencies. This change
moves those operations into the CLI process, which calls NuGet.Client
directly with credential providers enabled. It also removes a
helper-process launch from every NuGet operation. Everything else
behaves as before.

## Testing

- Unit tests for the in-process client and its callers:
search/restore/manifest parity, source mapping, `NUGET_PACKAGES` and
`globalPackagesFolder`, signature-verification scoping, and
restore-cache reuse. On release/13.6, all 221 tests in the affected
`Aspire.Cli.Tests` classes pass (2 skipped), and `Aspire.Managed.Tests`
and `Aspire.Hosting.RemoteHost.Tests` pass.
- Native AOT publish on release/13.6 produces no IL diagnostics.
- Full CI passed on main.
- Manual end-to-end validation of the PR build against the main daily
build
([report](#19847 (comment)))
covered:
  - .NET and TypeScript create, search, add, update, and start
  - cold and warm restore
  - an authenticated Azure Artifacts feed
  - package source mapping, and search with one feed unreachable
  - RID-specific, native, and satellite assets
  - `aspire doctor` right after a fresh install

Search results, manifests, and generated TypeScript were identical to
main.

## Risk

Medium. The change is large (42 files) and replaces the NuGet search,
restore, and manifest code that every bundled CLI uses, and it moves the
CLI to NuGet.Client 7.12.0-rc.25. It was checked line by line against
the helper and compared end to end with main. The only intended behavior
change is credential-provider support. One side effect: a feed that
can't be authenticated non-interactively now waits on the credential
provider, as `dotnet restore` does, instead of failing immediately with
401.

## Regression?

No.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: baa86aab-4a9f-44c7-a92e-34f6498c9e4e
…ion name (#20407)

Backport of #20299 to release/13.6

/cc @JamesNK

## Customer Impact

Dashboards sharing a hostname could interfere with one another’s
authentication and antiforgery cookies. Resource-collapse preferences
could also collide for application names with the same sanitized form.
Existing users will need to sign in again and will initially lose their
saved resource expansion state.

## Testing

Dashboard and component test CI passed on Windows and Linux for this
backport; Ubuntu x64 native-AOT Dashboard validation passed. The source
PR reports focused cookie/storage tests and manual browser checks of
same-name and different-name dashboard isolation. Live OpenID Connect
and HTTPS browser flows were not manually exercised.

## Risk

Medium. Cookie and storage names change across dashboard authentication
modes; existing cookies and collapsed-resource preferences are not
migrated, requiring reauthentication and resetting those preferences.

## Regression?

Unknown — please confirm.

---------

Co-authored-by: James Newton-King <james@newtonking.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Backport of #20363 to release/13.6

/cc @JamesNK

## Customer Impact

An explicitly empty secondary OTLP API key could allow a request with an
empty `x-otlp-api-key` header to authenticate. This prevents that
unintended access while still allowing an unset optional secondary key.

## Testing

Dashboard test CI passed on Windows and Linux for this backport; Ubuntu
x64 native-AOT Dashboard validation passed. The source PR adds
configuration, authentication-handler, and OTLP HTTP endpoint coverage
for empty keys and a null optional secondary key.

## Risk

Medium. This changes OTLP authentication and startup validation:
configurations with explicitly empty keys that were previously accepted
will now fail validation; no public API changes.

## Regression?

Unknown — please confirm.

---------

Co-authored-by: James Newton-King <james@newtonking.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Backports #20360, #20341, and #20362 to release/13.6.

## Customer Impact

Dashboard users can encounter popups that are misaligned, overflow the
viewport, or disappear while metric dimensions update. Resource graph
context menus may not reopen immediately after dismissal, and terminal
auto-fit can move focus away from the active control.

## Testing

Validated on the release/13.6 backport branch: 570
Aspire.Dashboard.Components.Tests and 1,892 Aspire.Dashboard.Tests
passed, excluding quarantined and outerloop tests. The source changes
also include targeted Playwright coverage for resources, terminal,
navigation, authentication, accessibility, and popup behavior. `git diff
--check` passes.

## Risk

Medium. The production changes are localized to Dashboard popup, focus,
and component-state behavior with no public API changes, but this
combines three related changes and a broad component-test migration.

## Regression?

Yes — fixes Dashboard behavior and test regressions introduced by the
Fluent UI v5 migration.
…20405)

Backport of #20158 to release/13.6

/cc @karolz-ms

## Customer Impact

## Testing

## Risk

## Regression?

---------

Co-authored-by: Karol Zadora-Przylecki <karolz@microsoft.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Reuse inherited method exports only when the same capability ID is owned by a base context included in the scan. Preserve namespace and ExposeMethods aliases, unscanned bases, overrides, and genuine duplicate diagnostics.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
(cherry picked from commit cbaabf4)
@github-actions

Copy link
Copy Markdown
Contributor

🚀 Dogfood this PR with:

⚠️ WARNING: Do not do this without first carefully reviewing the code of this PR to satisfy yourself it is safe.

curl -fsSL https://raw.githubusercontent.com/microsoft/aspire/main/eng/scripts/get-aspire-cli-pr.sh | bash -s -- 20443

Or

  • Run remotely in PowerShell:
iex "& { $(irm https://raw.githubusercontent.com/microsoft/aspire/main/eng/scripts/get-aspire-cli-pr.ps1) } 20443"

@aspire-repo-bot
aspire-repo-bot Bot requested a balanced review from Copilot September 24, 2026 19:15
@github-actions github-actions Bot added the needs-area-label An area label is needed to ensure this gets routed to the appropriate area owners label Sep 24, 2026
@github-actions

This comment has been minimized.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The shared ATS discovery change requires the outstanding official rebuilt release-binary validation before approval.

Review effort: Balanced
Findings: None

What changed in this PR

Backports the ATS scanner fix that prevents false duplicate-capability diagnostics for inherited exported methods.

Changes:

  • Adds scan-aware inherited method deduplication.
  • Preserves aliases, overrides, unscanned bases, and genuine conflict diagnostics.
  • Adds 11 focused inheritance regression cases.
File Description
src/​Aspire.Hosting.RemoteHost/​AtsCapabilityScanner.cs Tracks scanned exports and skips duplicate inherited projections.
tests/​Aspire.Hosting.RemoteHost.Tests/​AtsCapabilityScannerTests.cs Makes the test class partial.
tests/​Aspire.Hosting.RemoteHost.Tests/​AtsCapabilityScannerTests.Inheritance.cs Adds inheritance regression coverage.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

@github-actions

Copy link
Copy Markdown
Contributor

Retrying the failed CI jobs for this pull request from the CI run attempt. The rerun is being tracked in the rerun attempt.

Extend existing concrete-target precedence through CLR inheritance. This prevents Radius CSharpAppResource collisions from globally dropping the generic IDotnetProgramResource export while preserving both wire IDs and guest method names. Cover derived targets, unrelated implementations, dispatch, and genuinely ambiguous interfaces.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@github-actions

Copy link
Copy Markdown
Contributor

Tests selector

8 / 99 PR test projects · 4 PR jobs, from 3 changed files.

Selected PR test projects (8 / 99)

Aspire.Cli.EndToEnd.Tests, Aspire.Hosting.CodeGeneration.Go.Tests, Aspire.Hosting.CodeGeneration.Java.Tests, Aspire.Hosting.CodeGeneration.Python.Tests, Aspire.Hosting.CodeGeneration.Rust.Tests, Aspire.Hosting.CodeGeneration.TypeScript.Tests, Aspire.Hosting.RemoteHost.Tests, Aspire.Managed.Tests

Selected PR jobs (4)

cli-starter-validation, extension-e2e, polyglot, typescript-api-compat


How these were chosen — grouped by what changed

🔧 src/Aspire.Hosting.RemoteHost/AtsCapabilityScanner.cs (changed source)
→ 1 directly: Aspire.Hosting.RemoteHost.Tests
→ 6 via the project graph: Aspire.Hosting.CodeGeneration.Go.Tests, Aspire.Hosting.CodeGeneration.Java.Tests, Aspire.Hosting.CodeGeneration.Python.Tests, Aspire.Hosting.CodeGeneration.Rust.Tests, Aspire.Hosting.CodeGeneration.TypeScript.Tests, Aspire.Managed.Tests (2 hops)

📦 affected project Aspire.Hosting.RemoteHost
→ 1 test: Aspire.Cli.EndToEnd.Tests

🧪 tests/Aspire.Hosting.RemoteHost.Tests/AtsCapabilityScannerTests.Inheritance.cs (changed test)
→ 1 directly: Aspire.Hosting.RemoteHost.Tests

🧪 tests/Aspire.Hosting.RemoteHost.Tests/AtsCapabilityScannerTests.cs (changed test)
→ 1 directly: Aspire.Hosting.RemoteHost.Tests

Job reasons

Job Triggered by
cli-starter-validation affected project Aspire.Managed
extension-e2e • src/Aspire.Hosting.RemoteHost/AtsCapabilityScanner.cs
• affected project Aspire.Hosting.RemoteHost
polyglot affected project Aspire.Hosting.RemoteHost
typescript-api-compat affected project Aspire.Hosting.RemoteHost

Selection computed for commit 435fd4e.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Core ATS dispatch behavior is release-sensitive, and latest CI plus official rebuilt-binary validation remain pending.

Review effort: Balanced
Findings: None

David Pine (IEvangelist) added a commit to microsoft/aspire.dev that referenced this pull request Sep 29, 2026
Follow-up to #1780, which merged with two open checkboxes. Both are now
validated against the latest staging build.

This is a single commit on top of the current `release/13.6` tip
(`5589ce6d`), so it merges cleanly.

- [x] Generated API catalog refreshed from genuine 13.6 packages,
including the late `WithRepl` additions and removed attributes.
- [x] REPL samples and all other new samples checked against the real
13.6 SDK, not stale Twoslash types.

## Provenance

- **Feed:** `darc-pub-microsoft-aspire-f4c27f2d`
(`https://pkgs.dev.azure.com/dnceng/public/_packaging/darc-pub-microsoft-aspire-f4c27f2d/nuget/v3/index.json`).
- **Source:** microsoft/aspire `release/13.6` at
`f4c27f2d43ddc1cacd0dd083b30d1fea1cee7a62`, the newest staging build.
Every regenerated official TS module records `sourceCommit: f4c27f2d…`,
and the restored nuspecs (for example Redis, Blazor and
CodeGeneration.TypeScript) report that commit.
- **Versions:** stable packages are `13.6.0`; prerelease packages are
`13.6.0-preview.1.26478.8`. The codegen package is
`Aspire.Hosting.CodeGeneration.TypeScript 13.6.0`, mapped exclusively to
the staging feed. nuget.org has no `13.6.0`, so resolution is
unambiguous.
- **Scanner:** a locally fixed CLI/ATS scanner, built from `a11eca96`
plus `320eed42` (the microsoft/aspire#20438 content) and `435fd4eb` (the
microsoft/aspire#20443 content). Both upstream PRs are still unmerged.
- Nothing in `a11eca96..f4c27f2d` touches `AtsCapabilityScanner`,
`Aspire.TypeSystem` or `Aspire.Hosting.CodeGeneration.TypeScript`. The
last two commits (microsoft/aspire#20566 and microsoft/aspire#20562)
only change dashboard layout code and Dockerfiles.
- The layout's `dashboard` and `dcp` folders are copies from the
`8230626c` staging CLI bundle. Layout discovery requires them, but they
aren't used for scanning or code generation.
- **Isolation:** the stable version number didn't change between builds,
so generation used fresh process-local `NUGET_PACKAGES`, HTTP cache,
`TEMP` and `ASPIRE_HOME` folders. That rules out reusing `e8fd6fbb`
bits. `ASPIRE_REPO_ROOT` and `ASPIRE_REPO_PATH` were unset, and there
was no source-project substitution.
- **Pipeline:** the repo's own pipeline, in this order:
`update:integrations` → `generate-package-json.ps1` →
`normalize:api-data -- --pkgs` → `update:ts-api` (with Twoslash `.d.ts`)
→ `validate:api-data`.
- Generated JSON and `d.ts` were not hand-edited, and nothing from 14.x
was imported.

### Deviation: no `ASPIRE_RELEASE_VERSION` pin

Pinning `13.6.0` left the 50 prerelease packages stale. The feed is
commit-specific, so the unpinned run resolves every package from the
same build.

### Packages absent from the feed

These seven official packages aren't in this build, so they are carried
forward unchanged:

- `Aspire.Elastic.Clients.Elasticsearch` 13.3.0
- `Aspire.Hosting.AgentFramework.DevUI` 1.22.0-preview.260918.1
- `Aspire.Hosting.AWS` 13.7.2
- `Aspire.Hosting.ClickHouse` 13.5.3
- `Aspire.Hosting.DocumentDB` 0.116.0
- `Aspire.Hosting.Elasticsearch` 13.3.0
- `Aspire.Hosting.GitHub.Models` 13.5.4

## Changes

- **Generated data:** regenerated `aspire-integrations.json` (still 217
packages; 82 at `13.6.0` and 50 at `13.6.0-preview.1.26478.8`), `pkgs/`
(210 succeeded, 0 failed), `ts-modules/` (146 succeeded, 0 failed) and
`twoslash/aspire.d.ts`. `integration-docs.json` needed no change.
- **Generator fix** (`generate-package-json.ps1`): the 24 Provisioning
overlays restored `Aspire.Hosting` at the overlay's own prerelease
version, which doesn't exist now that `Aspire.Hosting` is stable
`13.6.0`. The script now uses the resolved `Aspire.Hosting` version, via
a new `-HostingVersion` parameter with a feed-lookup fallback for
selective runs.
- **Blazor docs:** `AddDotnetProjectBlazorGateway` and
`WithBlazorClientApp` report their own `ASPIREDOTNETPROJECT001`
diagnostic. `ASPIREBLAZOR001` applies to other experimental Blazor
hosting types, such as `BlazorWasmAppResource`.
- A compile check with the pragma removed reports only
`ASPIREDOTNETPROJECT001`, on exactly those two methods.
- The previous wording, from #1564, said the gateway methods carry both
diagnostics.
- **Dashboard docs (microsoft/aspire#20562):** the dashboard no longer
has a terminal button in the header or a terminal entry in the mobile
menu.
- `dashboard/explore.mdx` and the What's new bullet now describe the
backtick key as the way to open and hide the terminal dock.

## Validation

- **`WithRepl` coverage:** present in the C# and TS API data for all six
REPL packages (PostgreSQL, MySql, MongoDB, SqlServer, Redis, Valkey) and
in `aspire.d.ts`.
- **C# compile:** every new sample compiles with 0 warnings and 0 errors
against exact packages from the `f4c27f2d` feed (16 at `13.6.0`, 9 at
`26478.8`). This covers REPL×6, Rust, ConnectorNamespace, Foundry
Toolbox, Radius, CSI, Helm, Blazor (now matching #1564's
`WithExternalHttpEndpoints` sample), Provisioning and Dotnet. The Dotnet
samples need no `ASPIREDOTNETPROJECT001` suppression.
- **TS compile:** the SDK was generated by a real `aspire restore`
(codegen `13.6.0`, `Aspire.Hosting.Redis/13.6.0` and
`Aspire.Hosting.Blazor/13.6.0-preview.1.26478.8`, all at `f4c27f2d`).
Strict `tsc` (NodeNext) passes for all 18 `.mts` samples, including the
new Blazor gateway TS sample. A negative control (`withReplz`) fails
with TS2551.
- **Scanner warnings:**
- Radius reports no collisions; the earlier `withContainerImage`
collision on `CSharpAppResource` is gone.
- The `createRoleAssignment` overload collisions remain in 16
Provisioning overlays. They are recorded here, not suppressed; no doc
sample calls this method.
- **Tests:** `pnpm validate:api-data` passes (217 identities, 146
modules matched to C# provenance). These suites pass:
`test:unit:structured-data` (82), `api-reference` (55), `api-markdown`
(30), `ts-api` (31), `twoslash-types` (12), `twoslash-blocks` (2),
`llms-txt` (12) and `docs` (2).
- No local `pnpm build` was run; CI covers it.

## Not done

- **Contributors:** `update:release-contributors` needs the `v13.6.0`
tag, which doesn't exist yet. This is left for after the release is
tagged.

Co-authored-by: David Pine <7679720+IEvangelist@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
David Negstad (danegsta) added a commit to microsoft/aspire.dev that referenced this pull request Sep 29, 2026
[![aspire.dev vnext
(13.6)](https://img.shields.io/badge/aspire.dev-vnext_(13.6)-512BD4?style=flat&logoColor=white&logo=...)](https://aka.ms/aspire/vnext)

## Summary

Prepare the Aspire 13.6 documentation release. The release article is
reconciled against [`microsoft/aspire` release/13.6 at
`a11eca9611073f7cf66fa87faac63c2119e87713`](https://github.com/microsoft/aspire/tree/a11eca9611073f7cf66fa87faac63c2119e87713),
compared with `v13.5.0`. The inventory contains 402 first-parent history
entries, including maintenance, merges, and reversions—not 402 distinct
shipped features.

Highlights cover dashboard persistence/run history and terminals; Java,
Rust, Connector Namespace and Sandboxes; coordinated .NET builds; CLI
and VS Code workflows; deployment and integration improvements; emulator
images; and migration guidance for Cosmos DB, Front Door,
connection-string aliases, and terminal namespaces.

### Published documentation and ingestion work

- `94b5f0c19`: migrate Java guides from Toolkit to first-party hosting,
document typed Azure provisioning customization and VS Code agent
lifecycle tools, and refresh 34 container-image records from the pinned
release source. Default tag changes: App Configuration `1.0.2 → 1.2.0`,
Cosmos DB `stable → vnext-latest`.
- `27e2db77a`: exact release-version selection, ATS-only package
metadata, union and canonical SDK enum handling, empty C# navigation
filtering, and fail-closed handling of SDK dump errors.
- `0b64558c1`: reconcile all 29 contributors against the pinned release
snapshot.
- `2696e2207`: recognize const-object enum declarations, retain
colliding enum-name literals in the shared Twoslash bundle while
preserving exact package-specific JSON, and increase the full
example-audit time budget for the larger dataset.
- `7ab5f74bd`: include the exact Dotnet package as supporting scan
context for Radius's generic .NET program export; subtract
core/supporting modules without dropping Radius's real IDs or receiver
targets.
- **`44b9819bb`: publish the complete, validated 13.6 catalog, mappings,
C#/TypeScript API data, and Twoslash bundle together.**
- Concurrent release updates are preserved, including the environment
badge and #1745's agent lifecycle options. Isolation/launch-profile
inputs were confirmed in the pinned 13.6 source.
- Related product changes: microsoft/aspire#18033,
microsoft/aspire#19675, and microsoft/aspire#19134.

The maintainer-set planned release date remains September 29, 2026
(#1690). Published package constants remain separate from prerelease
ingestion. Release membership comes from product source, not merely a
docs PR's target; #1740 documents microsoft/aspire#20231 (14.0), not a
13.6 feature.

### Generated data and provenance

The published snapshot contains **217 catalog entries**, **161
documentation mappings** (including the 26 new mappings), **210 C#
records**, **146 TypeScript modules**, and the rebuilt Twoslash bundle.
There are 132 official packages at exact version
`13.6.0-preview.1.26473.12`, with **no 14.x imports**. Independently
versioned packages retain their selected catalog versions.

Generation used genuine pinned packages from the public dotnet9 feed and
an isolated, locally built **13.6** CLI/RemoteHost. Package provenance
remains `a11eca9611073f7cf66fa87faac63c2119e87713`; the scanner fixes
are separate development-build provenance, not a claim that an official
corrected CLI has shipped.

- Full TypeScript ingestion with the inherited-method fix
(`320eed42f85a7d4b090a9429b98c7a6a8547a4b8`) produced 146 modules, 0
failures, and 7 explicit skips.
- Core/Radius regeneration with the additional target-specificity fix
(`435fd4eb7d06ef99702ae5106cf01c10f5c6a780`) succeeded. The real
compound Radius + exact Dotnet SDK dump has no diagnostics and retains
both `withContainerImage` and `withDotnetProgramContainerImage`
capability IDs.
- ProjectResource/CSharpAppResource use the concrete Radius export;
DotnetProjectResource uses the generic export. Dotnet's APIs are not
attributed to Radius. No source-package attributes, capability
identities, or missing-export checks were altered to force validation
through.

## Third-party links and affiliations

- Radius documentation — no material affiliation.
- Source/specification links remain within `microsoft/aspire`; Java
debugger links point to the corresponding Visual Studio Marketplace
extensions. No new material affiliation claims.

## Validation

- All **25 authored TypeScript guide/release examples** pass against the
final declaration bundle; guide samples were also compiled with the
genuine generated SDK.
- The **complete annotated-site Twoslash audit passes**, with no
diagnostic suppression.
- Final semantic validation passes: 217 package identities, 146
module-provenance matches, 74 DTO shapes, and 2,873 handle inheritance
chains.
- **82 structured-data tests**, **75
API-reference/declaration-generator/API-route tests**, and **17 ATS
transformer tests** pass. The final API-reference gate resolves the
Radius exports without exceptions or aliases.
- Earlier compile-only C# validation covered 24 guide methods and one
type declaration without warnings or errors. Browser checks covered
Java, Azure customization, VS Code and AI-agent routes and language
tabs.
- Source scanner/dispatcher/context-filter/API-export regressions: **215
pass on each product branch**, including exact-package dispatch and
generated-SDK compilation checks.
- No local production site build, cloud deployment, destructive cleanup
scenario, CLI self-update, or release workflow was run. Current-head CI
must still complete after the latest pushes.

## Remaining release gates

- **Main scanner fix: microsoft/aspire#20438**, ready for review, latest
commit `5482164dc1225f3c2a1a93bf5055e11b720117e9`. **13.6 backport:
microsoft/aspire#20443**, draft, latest commit
`435fd4eb7d06ef99702ae5106cf01c10f5c6a780`. Both require human
review/merge; neither has been merged or released by this session.
Latest-commit CI is still being monitored.
- Official shipping requires the corrected RemoteHost-containing
CLI/bundle. Rebuilding Network or Radius alone is insufficient. Local
documentation generation does not replace that packaging gate.
- The Express diagnostic short link requires owner action:
#1599 (comment).
- Complete current-head docs CI and final release/runtime acceptance.
Keep this PR draft until the release gates are satisfied.

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: aspire-repo-bot[bot] <268009190+aspire-repo-bot[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: James Newton-King <james@newtonking.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: JamesNK <303201+JamesNK@users.noreply.github.com>
Co-authored-by: David Pine <7679720+IEvangelist@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Maddy Montaquila <maddy@pi.hole>
Co-authored-by: Eric Erhardt <eric.erhardt@microsoft.com>
Co-authored-by: Ella Hathaway <ellahathaway@microsoft.com>
Co-authored-by: aspire-repo-bot[bot] <aspire-repo-bot[bot]@users.noreply.github.com>
Co-authored-by: David Aniebo <aniebovictor001@gmail.com>
Co-authored-by: Alistair Matthews <alistairwebdojo@live.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Maddy Montaquila <maddy@MadBook-Pro-20.local>
Co-authored-by: Ella Hathaway <67609881+ellahathaway@users.noreply.github.com>
Co-authored-by: David Pine <dapine@microsoft.com>
Co-authored-by: Nell Shamrell-Harrington <nellshamrell@gmail.com>
Co-authored-by: David Negstad <50252651+danegsta@users.noreply.github.com>
Co-authored-by: Sébastien Ros <sebastienros@gmail.com>
Co-authored-by: David Negstad <David.Negstad@microsoft.com>
Co-authored-by: Sébastien Ros <1165805+sebastienros@users.noreply.github.com>
Co-authored-by: karolz-ms <15271049+karolz-ms@users.noreply.github.com>
Co-authored-by: Karol Zadora-Przylecki <karolz@microsoft.com>
Co-authored-by: Mitch Denny <midenn@microsoft.com>
Co-authored-by: Mitch Denny <midenn@orangecake.local>
Co-authored-by: Mitch Denny <midenn@Mac.localdomain>
Co-authored-by: Jose Perez Rodriguez <joperezr@microsoft.com>
Co-authored-by: Maddy Montaquila <maddyleger1@gmail.com>
Co-authored-by: Maddy Montaquila <maleger@microsoft.com>
Copilot-Session: b0007635-1ab8-4ffc-9c7b-8c09439c79f6
Copilot-Session: 9ecc352e-ddd2-4c3e-9c4a-eafcc2a74157
Copilot-Session: b8ebe88c-337e-4d4a-aa80-e14c2c76289b
Copilot-Session: 5b0c81a3-d822-462e-8cf5-8eb6debfe968
Copilot-Session: b156fe61-0b1c-460c-9735-1eaeaa356b0a
Copilot-Session: 41298945-9592-4284-be9e-be0c58f31fad
Copilot-Session: 5eeee6c8-e0b2-4836-96ff-a9726e92b2ee
Copilot-Session: 829e510d-2b06-4301-9759-3bd760c45e5c
@IEvangelist
David Pine (IEvangelist) force-pushed the ievangelist-automatic-guacamole branch from 435fd4e to 82dc035 Compare October 1, 2026 17:49
@aspire-repo-bot
aspire-repo-bot Bot requested a balanced review from Copilot October 1, 2026 17:49

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The supplied diff contradicts the stated ATS-only, three-file backport and includes extensive unrelated release changes.

Review effort: Balanced
Findings: 1 Low severity

Open (1)

<ItemGroup>
<!-- unit test dependencies -->
<PackageVersion Include="bUnit" Version="1.36.0" /> <!-- Can't update passed to 1.37.x versions as those lift up LTS versions when targeting net8 -->
<PackageVersion Include="bUnit" Version="2.11.3" />
David Pine (IEvangelist) added a commit to microsoft/aspire.dev that referenced this pull request Oct 5, 2026
)

## Summary

<!-- Describe what this pull request changes and why. -->

Fixes the failing scheduled [Integration Data Updater
run](https://github.com/microsoft/aspire.dev/actions/runs/36928288291/job/110590941798),
and makes API regeneration faster and more resilient.

**Root cause.** The TypeScript API phase failed with `144 succeeded, 2
failed, 7 skipped`. The two failures were
`Aspire.Hosting.Azure.Provisioning.Kusto` and
`Aspire.Hosting.Azure.Provisioning.Network`
(`13.6.0-preview.1.26479.8`).

The shipped Aspire CLI (`13.6.0+56f3e9c0d`) exports an inherited `AddTo`
once per derived proxy type, all under the base type's capability ID. It
reports every collision as a `Duplicate capability` error and exits 1,
although it still writes the dump. Since #1599 the generator fails
closed on any dump error, so the whole run aborted. The scanner fix is
microsoft/aspire#20443.

### Changes

- **Narrow tolerance (AtsJsonGenerator).** The new
`--tolerate-known-scanner-diagnostics` flag accepts only the inherited
duplicate-capability diagnostic. Both definitions must be in the
capability's namespace, on different types, with the same member name,
and that name must match the capability method. Each defining type must
also be a handle type in the dump that is the type owning the capability
ID or lists it in `HandleTypes.BaseTypeHierarchy`, so unrelated types
that share a capability ID still fail. Each tolerated message is
printed, and any other error diagnostic still fails.
- **Fail-closed script wiring.** `generate-ts-api-json.ps1` passes the
flag only when the CLI exits nonzero without timing out and still writes
a dump. The package fails if nothing was actually tolerated.
- **Reporting (orchestrator).** `update-integration-data.ps1` emits a
`::warning` annotation for tolerated diagnostics. It also adds a
**Tolerated ATS scanner diagnostics** section and a review checklist
item to the PR body it generates. The section lists the packages and has
a collapsible list of diagnostics.
- **Faster, more resilient TypeScript generation.**
`generate-ts-api-json.ps1` processes packages concurrently in dependency
waves:
  1. core
  2. independent packages
  3. packages that need a supporting scan context

Up to `min(cores, 8)` packages run at a time. Set
`ASPIRE_TS_API_PARALLELISM` to override this; `-AspireRepoPath` runs
stay sequential. Each Aspire CLI `dump` and `export` call has a
10-minute timeout and gets up to 3 attempts. The transformer and the
enum supplement each have a 5-minute timeout. Each package's log is
printed as a block when that package finishes, so logs stay readable.
- **Faster C# generation.** `generate-package-json.ps1` restores package
graphs concurrently and retries each restore up to 3 times. It honors
`-Parallelism` and `-Sequential`, and its output and summary format are
unchanged.
- **Docs.** Updated the `update-integrations` skill and both generator
READMEs.

### Reviewer notes

- Remove the tolerance once the CLI that the workflow installs includes
microsoft/aspire#20443. `KnownScannerDiagnostics.cs` says this too.
- nuget.org replaced `13.6.0-preview.1.26478.8` with
`13.6.0-preview.1.26479.8`. The first bot PR will bump the 50 catalog
entries that are pinned to `26478.8`; this PR doesn't include that bump.
- The next bot PR will remove an export from the `Aspire.Hosting.Radius`
module. This isn't caused by this PR.
- With the stable CLI, the regenerated module drops
`withDotnetProgramContainerImage`, the `IDotnetProgramResource` overload
of `withContainerImage`. This happens even with the
`Aspire.Hosting.Dotnet` scan context, and the script on `main` drops it
too.
- The semantic validator doesn't check whether every export is present,
so it won't flag this.
- After merging, run `gh workflow run update-integration-data.yml --repo
microsoft/aspire.dev` instead of waiting for the next scheduled run.

## Third-party links and affiliations

<!--
List any third-party links added or changed by this pull request and
disclose any
material affiliation with the linked organizations, such as employment,
sponsorship, or ownership. Write "None" if this pull request doesn't add
or
change third-party links.
-->

None

## Validation

<!-- List the checks you ran or explain why validation isn't needed. -->

All runs used the same Aspire CLI as CI (`13.6.0+56f3e9c0d`, set via
`ASPIRE_CLI_PATH`) on a 20-core Windows machine. The default parallelism
there was 8; CI's 4-vCPU runner will use 4.

- `dotnet test tests/AtsJsonGenerator.Tests`: passed (37/37). This
includes new tests that accept and report matching diagnostics. They
also reject look-alike and unrelated errors, unrelated types that share
a capability ID, and defining types missing from the dump's
`HandleTypes`.
- After the review fix, I re-dumped Kusto and Network with the stable
CLI and ran the transformer with `--tolerate-known-scanner-diagnostics`.
Both exited 0, with 5 and 2 diagnostics tolerated. Without the flag,
both still fail.
- Upstream runners were backed up, so I also ran the PR checks that
support `workflow_dispatch` on my fork at `eca5c048`. All passed: [Tools
Tests](https://github.com/IEvangelist/aspire.dev/actions/runs/37017188918)
(41 PackageJsonGenerator and 37 AtsJsonGenerator tests), [Forbidden
Words](https://github.com/IEvangelist/aspire.dev/actions/runs/37017241429)
over `96fb149d..eca5c04`, and
[CodeQL](https://github.com/IEvangelist/aspire.dev/actions/runs/37017691344)
(no C# alerts; the only JS/TS alert is in existing code this PR doesn't
touch). Upstream Frontend Build and Frontend validation passed on the
first commit, and the review fix doesn't touch `src/frontend`.
- `pnpm exec vitest run --config vitest.config.ts
tests/unit/update-integrations.vitest.test.ts` (in `src/frontend`):
passed (42/42).
- **End-to-end replay of the regeneration phases.** I temporarily bumped
the catalog to `26479.8`, used a cold NuGet cache, and pointed
`ASPIRE_API_*` at a staging directory.
- `pwsh src/tools/PackageJsonGenerator/generate-package-json.ps1
-OutputDir <stage>/pkgs`: `Done! Success: 210 | Failed: 0 | Skipped: 7`
in 3:21.
  - `pnpm run normalize:api-data -- --pkgs`: passed.
- `pnpm run update:ts-api`: `Complete: 146 succeeded, 0 failed, 7
skipped` in 4:05 (3:47 of it generation). It tolerated 5 Kusto and 2
Network diagnostics.
- `pnpm run validate:api-data`: passed. It reconciled 217 package
identities, matched 146 modules to C# provenance, checked 74 DTO shapes
and 2,873 inheritance chains, and checked attribute payloads against
HEAD.
- Run against the real `update:ts-api` log, the orchestrator's parsing
and PR-body code rendered both packages, all 7 diagnostics, and the
`::warning` annotation.
- **Comparison with the scripts on `main`, using the same inputs:**
- TypeScript: 3:48 in parallel vs 13:46 sequentially. All 122 modules
that both runs produced are byte-identical. Both runs had the same
failures for packages pinned to the deleted `26478.8` builds.
- C#: 3:21 in parallel with a cold cache vs 8:28 sequentially with a
warm cache. Both runs reported `Success: 210 | Failed: 0 | Skipped: 7`,
and 208 of 210 files are byte-identical. The other 2 (`Aspire.Hosting`
and `Aspire.Hosting.JavaScript` 13.6.0) differ only in `sourceCommit`,
because my warm cache held a pre-release build of those packages.
- For reference, the failed CI job spent 8m02s in C# generation and
12m46s in TypeScript generation before it failed.

---------

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-area-label An area label is needed to ensure this gets routed to the appropriate area owners

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants