Sitelet https://github.com/dotnet/maui/pull/39030
Skip to content

[release/11.0.1xx-rc2] Restrict private SDK updates to trusted internal builds - #39030

Closed
kubaflo wants to merge 1 commit into
release/11.0.1xx-rc2from
kubaflo-rc2-internal-sdk-only
Closed

kubaflo wants to merge 1 commit into
release/11.0.1xx-rc2from
kubaflo-rc2-internal-sdk-only

Conversation

@kubaflo

@kubaflo kubaflo commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Note

Are you waiting for the changes in this PR to be merged?
It would be very helpful if you could test the resulting artifacts from this PR and let us know in a comment if this change resolves your issue. Thank you!

Summary

Replaces closed #39023. The requested SDK 11.0.100-rc.2.26478.115 (BAR 334412) is internal-only and must not become the SDK that every public checkout tries to install.

  • Make the existing public RC2 SDK 11.0.100-rc.2.26475.137 (BAR 334092) the shared default in global.json, eng/Versions.props, and SDK dependency provenance. Keep the public .NET 10.0.13 compatibility feed available by default, including to device-test jobs that do not run the common provisioning template.
  • Replace the public fallback with internal-sdk.yml. It selects 11.0.100-rc.2.26478.115, updates SDK provenance to its source commit, and removes the public-only compatibility feed from the trusted job's checkout.
  • Invoke that template only within the existing gates for non-PR dotnet-maui / dotnet-maui-build builds in the internal project, both in common provisioning and the Helix monitor. skipInternalFeeds remains respected. No trust/authentication gates are broadened.
  • Leave runtime, ASP.NET Core, Arcade, Android, and Apple dependency pins unchanged.

Why change the default rather than add more fallbacks?

The earlier internal SDK change in #38972 required each public job to rewrite its checkout before using .NET. Device-test submission jobs and the Windows device-test build bypass that provisioning path and still attempted to download the internal SDK. In device-test build 1618167, the submission steps failed with public SDK download HTTP 404s before tests could run. The target branch also reproduced this with its older internal SDK in build 1617716.

A public default makes those jobs safe without adding fallback calls to every public pipeline. Internal SDK selection is now an explicit trusted-only operation, and its version/source commit are maintained in the internal template rather than the shared pins.

Validation

  • Parsed the modified YAML, JSON, and XML; git diff --check passed.
  • Executed the actual internal selection step twice on isolated checkout configuration copies. Both invocations produced SDK/property/dependency version 11.0.100-rc.2.26478.115, source commit 491b6df29d9d56266c00cfe7552f59c4f6da43e5, and no public compatibility feed. MSBuild property evaluation confirmed the selected SDK.
  • Confirmed the shared checkout retains the public .137 SDK, public source provenance, and compatibility feed.
  • Public .137 Linux and Windows SDK archive URLs return HTTP 200; the corresponding internal .115 URLs return HTTP 404. The public compatibility feed is reachable.
  • No pipeline tests added. Full public CI and authenticated internal-build validation remain pending; public CI does not validate the internal .115 SDK itself.

Keep the public RC2 SDK and package feed as the checkout default so device-test and other public jobs never bootstrap an internal-only SDK. Select the newer internal SDK and its provenance only under the existing trusted pipeline gates.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings September 30, 2026 17:46
@kubaflo
kubaflo deployed to copilot-pat-pool September 30, 2026 17:47 — with GitHub Actions Active
@github-actions

Copy link
Copy Markdown
Contributor

🚀 Dogfood this PR with:

⚠️ WARNING: Do not do this without first carefully reviewing the code of this PR to satisfy yourself it is safe.

curl -fsSL https://raw.githubusercontent.com/dotnet/maui/main/eng/scripts/get-maui-pr.sh | bash -s -- 39030

Or

  • Run remotely in PowerShell:
iex "& { $(irm https://raw.githubusercontent.com/dotnet/maui/main/eng/scripts/get-maui-pr.ps1) } 39030"

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
There may be pipelines that require an authorized user to comment /azp run to run.

@kubaflo

kubaflo commented Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

/azp run maui-pr-devicetests, maui-pr-uitests

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 2 pipeline(s).

@kubaflo
kubaflo deployed to copilot-pat-pool September 30, 2026 17:50 — with GitHub Actions Active
@kubaflo
kubaflo deployed to copilot-pat-pool September 30, 2026 17:51 — with GitHub Actions Active
@github-actions github-actions Bot added the area-infrastructure CI, Maestro / Coherency, upstream dependencies/versions label Sep 30, 2026
@kubaflo
kubaflo deployed to copilot-pat-pool September 30, 2026 17:52 — with GitHub Actions Active
@kubaflo

kubaflo commented Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

/azp run

@kubaflo kubaflo closed this Sep 30, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The security-sensitive internal SDK and feed rewrite lacks automated coverage and cannot be exercised by public CI.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Makes the public RC2 SDK the repository default while restricting the private SDK to trusted internal builds.

Changes:

  • Pins public SDK .137 and its provenance by default.
  • Adds a trusted-build template selecting internal SDK .115.
  • Removes the previous public fallback mechanism.
File Description
NuGet.config Adds the public .NET 10 compatibility feed.
global.json Selects public SDK .137.
eng/​Versions.props Aligns the SDK package version.
eng/​Version.Details.xml Records public SDK provenance.
eng/​pipelines/​common/​public-sdk-fallback.yml Removes runtime fallback rewriting.
eng/​pipelines/​common/​provision.yml Runs internal selection behind trusted-build gates.
eng/​pipelines/​common/​internal-sdk.yml Rewrites trusted builds to internal SDK .115.
eng/​pipelines/​arcade/​stage-helix-tests.yml Applies internal selection to the trusted Helix monitor.

Comment on lines +20 to +23
$replacements = @(
@{ Path = $globalJsonPath; Pattern = '("dotnet"\s*:\s*")' + [regex]::Escape($publicSdk) + '"'; Replacement = '${1}' + $internalSdk + '"' }
@{ Path = $versionsPropsPath; Pattern = '<MicrosoftNETSdkPackageVersion>' + [regex]::Escape($publicSdk) + '</MicrosoftNETSdkPackageVersion>'; Replacement = "<MicrosoftNETSdkPackageVersion>$internalSdk</MicrosoftNETSdkPackageVersion>" }
)

This branch was successfully deployed

1 active deployment
copilot-pat-pool — 10fdfa1e Deployed Sep 30, 2026 by kubaflo via conclusion #2156
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-infrastructure CI, Maestro / Coherency, upstream dependencies/versions

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants