Skip to content

Document the internal NuGet feed needed to run tests on a corp machine - #746

Merged
Nikola Metulev (nmetulev) merged 2 commits into
mainfrom
azchohfi-document-internal-nuget-feed
Aug 13, 2026
Merged

Nikola Metulev (nmetulev) merged 2 commits into
mainfrom
azchohfi-document-internal-nuget-feed

Conversation

@azchohfi

Copy link
Copy Markdown
Collaborator

Problem

api.nuget.org is unreachable from Microsoft corporate machines, so any test that downloads Microsoft.Windows.SDK.BuildTools — most of the PackageCommand, SignCommand and MsixService coverage — fails with:

Failed to install Microsoft.Windows.SDK.BuildTools: The SSL connection could not be established

That is indistinguishable from a transient network fault, and nothing in AGENTS.md said otherwise. The natural conclusion is "flaky, re-run it" or "environmental, let CI decide" — both wrong, and both waste real time. I hit this exact trap on #745: I saw the SSL error, probed api.nuget.org to confirm it was unreachable, and reported the failures as environmental. The probe confirmed my hypothesis instead of testing it, and I never asked the question that would have settled it in one grep — how does CI run these same tests successfully?

Change

Documentation only. A new section under Developer workflows covering:

  • That this is a known limitation, not a flaky test — with an explicit "do not re-run hoping it passes".
  • The three WINAPP_NUGET_* values, matching what .pipelines/templates/build.yaml already sets in CI.
  • The VSS_NUGET_ACCESSTOKEN step, and the detail that auth is Basic VssSessionToken:<token> applied only to URLs under the auth prefix.
  • A one-line probe to confirm the feed answers before committing to a multi-minute run.
  • The general rule this is an instance of: if it fails locally but passes in CI, the difference is configuration, not luck.

The capability already existed — NugetService falls back to api.nuget.org only when these are unset. It was simply never written down for anyone working outside CI.

Verification

Followed the documented steps from a clean shell, then re-ran the two tests that had failed:

CreateMsixPackageAsync_WithExternalManifestAndMismatchedCertificate_ShouldFail
CreateMsixPackageAsync_AutoSignWithGenerateDevCert_GeneratesAndSignsWithDevCertificate

Test run summary: Passed!
  total: 2, failed: 0, succeeded: 2

The probe command is also verified — it returns 379 versions of Microsoft.Windows.SDK.BuildTools.

Note

AGENTS.md is the only instruction file in the repo (no CONTRIBUTING.md, copilot-instructions.md or CLAUDE.md), so this is the single place it needs to live.

api.nuget.org is unreachable from Microsoft corporate machines, so every test
that downloads Microsoft.Windows.SDK.BuildTools fails with an SSL error. The
failure looks exactly like a transient network fault, and nothing in AGENTS.md
said otherwise -- so the natural reading is "flaky, re-run it", which is wrong
and wastes a lot of time.

NugetService already supports the internal feed via WINAPP_NUGET_*, and CI sets
those in .pipelines/templates/build.yaml. That was just never written down for
anyone working locally.

Adds the values, the token step, a probe to check the feed answers before
committing to a long run, and the general rule this is an instance of: if it
fails locally but passes in CI, the difference is configuration, not luck.
Copilot AI balanced review requested due to automatic review settings August 13, 2026 17:52

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Documents the internal NuGet feed configuration required to run package-dependent tests on Microsoft corporate machines.

Changes:

  • Adds feed environment variables, authentication setup, and connectivity probe.
  • Clarifies that NuGet failures require matching CI configuration rather than retries.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 1 out of 1 changed files in this pull request and generated no new comments.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants