Repository navigation
Conversation
Replace throwing numeric conversions and payload allocation with explicit failure paths, guard exception-only handlers, and build the full SDK with GCC and Clang in CI so blockers outside Curl cannot remain hidden. Initialize submodules and pin the companion module fixes without dropping the existing SDK module baseline. Files changed: .github/workflows/build-posix-latest.yml; docs/linux-setup-build.md; lib/api/CorrelationVector.cpp; lib/api/capi.cpp; lib/decoder/PayloadDecoder.cpp; lib/include/public/ctmacros.hpp; lib/modules; lib/offline/KillSwitchManager.hpp; lib/offline/OfflineStorage_SQLite.cpp; lib/offline/SQLiteWrapper.hpp; lib/packager/Packager.cpp; lib/pal/InformationProviderImpl.cpp; lib/tpm/TransmitProfiles.cpp; tests/unittests/CorrelationVectorTests.cpp; tests/unittests/KillSwitchManagerTests.cpp; tests/unittests/OfflineStorageTests_SQLite.cpp; tests/unittests/PayloadDecoderTests.cpp Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 133d63e0-e402-4d40-bcc8-e801d9f5c438
Remove submodule cloning from the public GCC/Clang build gate because the optional modules repository is private. Keep building the complete public mat target, document that boundary, pin the reviewed module schema fixes, and include their regression tests only when those modules are already available locally. Files changed: .github/workflows/build-posix-latest.yml; docs/linux-setup-build.md; tests/unittests/CMakeLists.txt; lib/modules Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 133d63e0-e402-4d40-bcc8-e801d9f5c438
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Malformed transmission-profile JSON can abort no-exception builds instead of failing gracefully.
Review effort: Balanced
Findings: 1
What changed in this PR
Enables full GCC/Clang SDK builds with C++ exceptions disabled.
Changes:
- Adds non-throwing numeric parsing and payload allocation handling.
- Conditionally excludes exception handlers while preserving exception-enabled behavior.
- Expands regression tests, CI coverage, and build documentation.
| File | Description |
|---|---|
.github/workflows/build-posix-latest.yml |
Builds the complete SDK with GCC and Clang without exceptions. |
docs/linux-setup-build.md |
Documents no-exception builds and allocation limitations. |
lib/api/CorrelationVector.cpp |
Replaces throwing numeric conversion. |
lib/api/capi.cpp |
Conditionally compiles C API exception handlers. |
lib/decoder/PayloadDecoder.cpp |
Uses non-throwing decompression-buffer allocation. |
lib/include/public/ctmacros.hpp |
Provides std::abort declaration for exception macros. |
lib/offline/KillSwitchManager.hpp |
Adds checked duration parsing. |
lib/offline/OfflineStorage_SQLite.cpp |
Uses non-throwing SQLite filter conversion. |
lib/offline/SQLiteWrapper.hpp |
Conditionally compiles callback exception handling. |
lib/packager/Packager.cpp |
Conditionally compiles allocation handling. |
lib/pal/InformationProviderImpl.cpp |
Conditionally compiles callback exception handling. |
lib/tpm/TransmitProfiles.cpp |
Conditionally compiles JSON parsing handler. |
tests/unittests/CMakeLists.txt |
Includes optional Azure Monitor tests. |
tests/unittests/CorrelationVectorTests.cpp |
Covers decimal limits and leading zeros. |
tests/unittests/KillSwitchManagerTests.cpp |
Covers signed 64-bit duration boundaries. |
tests/unittests/OfflineStorageTests_SQLite.cpp |
Covers malformed numeric filters. |
tests/unittests/PayloadDecoderTests.cpp |
Covers allocation failure behavior. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Address Copilot comment 4152647239: parse customer JSON with allow_exceptions=false, check member/container types before conversion, and bounds-check signed, unsigned, and floating timer values so malformed configuration cannot abort a no-exceptions host. Verified at lib/tpm/TransmitProfiles.cpp:198-309. Preserve existing permissive optional-field handling, ignored nonnumeric timers, valid fractional timer conversion, and valid-prefix loading; keep all legacy pinning tests. All 62 profile tests passed on VS 2026 and against full module-free GCC and Clang SDK builds with -fno-exceptions. Files changed: lib/tpm/TransmitProfiles.cpp; tests/unittests/TransmitProfilesTests.cpp Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 133d63e0-e402-4d40-bcc8-e801d9f5c438
Keep Android JNI/Room and Apple wrappers buildable when native consumers disable C++ exceptions. Preserve enabled handlers and Room ID error reporting, detect MSVC unwind support, and gate native platforms in CI, including fix branches. Files changed: - .github/workflows/build-android.yml - .github/workflows/build-ios-mac.yml - .github/workflows/build-posix-latest.yml - .github/workflows/build-windows-vs2022.yaml - docs/linux-setup-build.md - lib/include/public/ctmacros.hpp - lib/jni/LogManager_jni.cpp - lib/offline/OfflineStorage_Room.cpp - tests/headers/check_public_headers.cmd - tests/headers/check_public_headers.sh - tests/headers/exception-macros.cpp - wrappers/obj-c/ODWDiagnosticDataViewer.mm - wrappers/obj-c/ODWLogManager.mm - wrappers/obj-c/ODWLogger.mm Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Replace the request polling loop with notifications under the request mutex, a steady-clock deadline, and one-time counting of each batch. Preserve the five-second timeout and existing HTTP/error assertions; add a split-batch regression that rejects duplicate counting. Disable host network discovery for loopback tests after a VS 2026 stress run blocked in WinRT activation before HTTP initialization. Include AISendTests in CMake when Azure Monitor is enabled so both Windows and Linux exercise the same functional coverage. Files changed: tests/functests/AISendTests.cpp; tests/functests/CMakeLists.txt; docs/linux-setup-build.md Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Use Clang C++ feature detection so Objective-C exceptions cannot enable C++ try/catch in exception-free wrappers. Preserve dynamically resolved Windows API signatures without incompatible casts, and fully initialize the certificate-chain parameters for strict clang-cl builds. Check SQLite page allocation before opt-in trimming so page and index overhead cannot exceed the configured limit between throttled notifications. Add Objective-C++ macro coverage on Apple CI and a deterministic storage boundary regression without relaxing the existing functional assertion. Files changed: .github/workflows/build-posix-latest.yml; docs/Offline-storage-settings.md; docs/linux-setup-build.md; lib/http/HttpClient_WinHttp.cpp; lib/include/public/ctmacros.hpp; lib/offline/OfflineStorage_SQLite.cpp; lib/utils/Utils.cpp; tests/headers/check_public_headers.sh; tests/unittests/OfflineStorageTests_SQLite.cpp Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Clang 19 in CI diagnoses the precise-clock loader after the temporary-directory cast is fixed. Use a shared typed procedure loader for every SDK Windows API lookup so size-checked pointer copies retain each export signature without suppressing the diagnostic. Preserve missing-export fallbacks and correct the packaged-app API calling convention on 32-bit Windows. Add regression coverage that calls both DWORD-returning and void-returning exports and verifies a missing export remains null. Validate both HTTP transports with the cast diagnostic explicitly enabled, since newer local Clang does not enable it by default. Files changed: lib/utils/WindowsUtils.hpp; lib/utils/Utils.cpp; lib/pal/PAL.cpp; lib/pal/desktop/WindowsDesktopSystemInformationImpl.cpp; tests/unittests/UtilsTests.cpp Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Update the module pin to the latest master HEAD so the no-exceptions SDK PR uses the merged companion module changes rather than the development branch snapshot. Files changed: lib/modules Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Baiju Meswani (baijumeswani)
left a comment
There was a problem hiding this comment.
Thanks for the broad no-exceptions work. The checked parsing, platform exception detection, and added build coverage are useful. I do not think this is ready for approval yet. Malformed JSON passed through FromJSON can abort the process, and a malformed collector response with a non-object efi field can do the same in no-exception builds. The clang-cl matrix also currently fails. Please fix these runtime and build issues, add a small runtime no-exceptions test, and rerun the full platform matrix.
Resolve the decoder-test includes without dropping either branch's regressions. Brace the compact-SKU logging conditional so disabling logging does not trigger C4390. Aggregate completed Dr. Memory process reports so forked Linux tests retain leak accounting instead of failing report discovery. Files updated beyond the main merge: tests/unittests/PayloadDecoderTests.cpp; lib/pal/desktop/WindowsDesktopSystemInformationImpl.cpp; .github/scripts/run-drmemory.ps1; .github/workflows/memory-leak-analysis.yml; tests/memory-leak-analysis/run-drmemory-tests.ps1; docs/maintainer-onboarding.md. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: f81706eb-e23d-4739-a41b-8851e2c3653a
…ures 4191920933: resolve both IP Helper functions through GetWindowsProcAddress instead of incompatible FARPROC casts (lib/pal/desktop/NetworkDetector.cpp). 4191920942: disable Android fail-fast so each ABI and Room combination runs. 4191920945: link a standalone runtime smoke test against the full exception-disabled SDK and run it on POSIX and all four Windows compiler/transport entries. 4191920951: document the existing valid-prefix profile-loading contract without breaking its pinning tests. Also address the review summary: guard null/non-object FromJSON input and disable throwing JSON parse errors only in no-exceptions builds; validate collector response objects, efi types, and numeric counts before conversion. Reject unrepresentable expansion lengths before allocation so the SIZE_MAX regression does not enter an instrumented allocator. Files changed: .github/workflows/build-android.yml; .github/workflows/build-posix-latest.yml; .github/workflows/build-windows-vs2022.yaml; lib/api/LogConfiguration.cpp; lib/decoder/PayloadDecoder.cpp; lib/http/HttpResponseDecoder.cpp; lib/include/public/LogConfiguration.hpp; lib/include/public/TransmitProfiles.hpp; lib/pal/desktop/NetworkDetector.cpp; tests/no-exceptions/CMakeLists.txt; tests/no-exceptions/README.md; tests/no-exceptions/no-exceptions-smoke.cpp; tests/unittests/CMakeLists.txt; tests/unittests/HttpResponseDecoderTests.cpp; tests/unittests/LogConfigurationTests.cpp; tests/unittests/PayloadDecoderTests.cpp; tests/unittests/UnitTests.vcxproj. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: f81706eb-e23d-4739-a41b-8851e2c3653a
Address Copilot comment 4193506718. Keep the normal Expand entry point and std::nothrow allocation unchanged, but route it through an internal overload with a per-call allocator. Inject failure for a representable 32-byte request and assert the allocator ran, false was returned, a previously non-null output was cleared, and the length became zero. Cover exception-enabled unit tests and exception-disabled runtime smoke tests without process-global injection controls. Files changed: lib/decoder/PayloadDecoder.cpp; tests/unittests/PayloadDecoderTests.cpp; tests/no-exceptions/no-exceptions-smoke.cpp; tests/no-exceptions/README.md. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: f81706eb-e23d-4739-a41b-8851e2c3653a
Add opt-in exception-free, diagnostic-free, and Android C API HTTP callback features while preserving package defaults and private compiler policy. Exercise real package builds and remove diagnostic-only code that breaks strict logging-disabled builds. Files changed: - .github/workflows/build-posix-latest.yml - .github/workflows/test-vcpkg.yml - CMakeLists.txt - cmake/MatsdkOptions.cmake - docs/building-with-vcpkg.md - docs/linux-setup-build.md - lib/http/HttpClient_WinInet.cpp - lib/offline/SQLiteWrapper.hpp - lib/pal/WorkerThread.cpp - lib/stats/MetaStats.hpp - tests/no-exceptions/README.md - tests/vcpkg/CMakeLists.txt - tests/vcpkg/test-release-port.py - tests/vcpkg/test-vcpkg-android.sh - tests/vcpkg/test-vcpkg-linux.sh - tests/vcpkg/test-vcpkg-windows.ps1 - tests/vcpkg/vcpkg.json - tools/ports/cpp-client-telemetry/portfile.cmake - tools/ports/cpp-client-telemetry/vcpkg.json - tests/vcpkg/native-feature-tests.cmake Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: ae9709f0-338e-457b-9554-6be83625f8f3
Read SDK option sources once and derive legacy build aliases from the canonical recipe only when the source needs them. Preserve native feature behavior and cover modern, legacy, and partially migrated sources. Files changed: - tools/ports/cpp-client-telemetry/portfile.cmake - tests/vcpkg/native-feature-tests.cmake Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: ae9709f0-338e-457b-9554-6be83625f8f3
Use automatic vcpkg detection and MATSDK_SQLITE_PROVIDER instead of the obsolete dependency toggles. Reject minimal SQLite requests against SDK sources without the provider option rather than silently losing the selected behavior. Retain the older BUILD_* compatibility names. Files changed: - tools/ports/cpp-client-telemetry/portfile.cmake - tests/vcpkg/native-feature-tests.cmake Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: ae9709f0-338e-457b-9554-6be83625f8f3
Exercise the supported exception option consistently in CI without changing dependency compiler policy. Use CTest registration for native consumers, restore C API coverage, and propagate build and concurrent-process failures instead of accepting stale or incomplete runs. Add deterministic runner contracts to Ubuntu and macOS CI. Files changed: - .github/workflows/build-android.yml - .github/workflows/build-ios-mac.yml - .github/workflows/build-posix-latest.yml - .github/workflows/build-windows-vs2022.yaml - .github/workflows/test-embedding.yml - CMakeLists.txt - build-tests.sh - cmake/MatsdkCompilerOptions.cmake - docs/maintainer-onboarding.md - tests/build-runner-tests.py - tests/embedding/CMakeLists.txt - tests/functests/CMakeLists.txt - tests/no-exceptions/CMakeLists.txt - tests/unittests/CMakeLists.txt - tests/vcpkg/test-vcpkg-linux.sh - tests/vcpkg/test-vcpkg-macos.sh - tests/vcpkg/test-vcpkg-windows.ps1 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: ae9709f0-338e-457b-9554-6be83625f8f3


Summary
-fno-exceptionscompilation, not just the Curl transport object.falsewith null output and zero length on allocation failure.mattarget with GCC and Clang without cloning the private optional-modules repository.Dependency
Depends on microsoft/cpp_client_telemetry_modules#361. The submodule is pinned to
b2718c982, which preserves the previously pinned SDK module baseline and adds the Azure Monitor/sanitizer no-exceptions fixes. Merge the companion modules PR first; if its merge method changes the resulting commit, update this pin to the merged equivalent before merging this PR.This PR is based on
mainand does not include the separate Curl changes in #1541.Validation
Built the complete SDK with GCC and Clang using
-fno-exceptions, including the locally checked-out optional modules.Passed 153 targeted regression tests on Windows using Visual Studio 2026.
Passed 36 Linux regression tests linked against the no-exceptions SDK.
Passed standalone public-header checks for GCC/Clang C++11/C++17 and the C API header under C11.
Passed repository-pinned misspell checks on changed files, whitespace checks, and YAML/compiler-matrix validation before pushing.
Fresh module-free public SDK builds passed with GCC and Clang using
-fno-exceptions.Seven malformed-response/schema regression tests passed on Visual Studio 2026 and with both the handler and test driver compiled using Clang
-fno-exceptions. These private-module tests are included only when their sources are already present locally.Profile JSON parsing now validates syntax, member types, and numeric ranges without throwing; all 62 profile tests, including legacy pinning cases, passed on VS 2026 and GCC/Clang
-fno-exceptionsbuilds.