[IsolationSession] One bundle builder and one suite runner for ADO, GitHub, and the OS lab - #1359
Dan Legg (danlegg) wants to merge 3 commits into
Conversation
The OS vpack bundle (Azure Pipelines) and the scheduled-validation bundle (GitHub Actions) had separate recipes, and scheduled validation and the Windows OS lab had separate definitions of what each suite runs and what passes. They had already drifted: the OS lab still expects the STA apartment probe to fail, which #1275 changed, so its next vpack would regress. - build-isolation-session-test-bundle.ps1 is now the only recipe. It builds any checkout (-SourceRoot), splits into Build and Validate phases so the pipeline can sign in between, and adopts the pipeline's .NET test-support native library and telemetry-test check. Payloads older sources lack are optional. - tests/scripts/run_isolation_session_suites.ps1 ships in the bundle and owns each suite's invocation and oracle. Scheduled validation calls it with -BackendUnavailable Fail; the OS lab can call it with Skip and enumerate suites with -List. The manifest records the suites. - The Azure Pipelines job runs the script instead of its inline copy. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 4f18230d-7852-4d2f-a862-71e88ae4d1e3
A single-element if-expression unwraps to a string, and splatting a string passes each character as a separate argument. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 4f18230d-7852-4d2f-a862-71e88ae4d1e3
Suites that resolve their own cwd (sdk_helpers' available_tools_policy test) failed when the host started the runner from system32, as the OS lab does after relaunching into the console session. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 4f18230d-7852-4d2f-a862-71e88ae4d1e3
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The cross-system pipeline and external OS-lab integration require final human verification despite no specific defect found.
Review effort: Balanced
Findings: None
What changed in this PR
Centralizes IsolationSession test-bundle construction and suite execution across GitHub Actions, Azure Pipelines, and the OS lab.
Changes:
- Adds a bundled runner owning suite discovery, execution, and pass criteria.
- Extends the bundle builder with source-root and phased build/validation support.
- Replaces duplicated CI orchestration and updates documentation.
| File | Description |
|---|---|
tests/scripts/run_isolation_session_suites.ps1 |
Adds the unified seven-suite runner. |
tests/scripts/README.md |
Documents the runner. |
scripts/ci/run_backend_validation_tests.ps1 |
Delegates validation while retaining account-leak checks. |
scripts/ci/build-isolation-session-test-bundle.ps1 |
Unifies bundle building and validation. |
docs/ci-validation-infrastructure.md |
Documents the shared CI flow. |
.azure-pipelines/templates/IsolationSession.TestBundle.Build.Job.yml |
Replaces duplicated ADO logic with phased builder calls. |
.github/workflows/Package.IsolationSession.TestBundle.Job.yml |
Continues GitHub bundle production through the shared builder. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| @@ -0,0 +1,431 @@ | |||
| <# | |||
There was a problem hiding this comment.
Why is this being added to MXC? Happy to approve it if I can understand why it's needed here.
| | `run_windows_sandbox_state_aware_tests.ps1` | Windows Sandbox state-aware lifecycle E2E (single VM held across provision/start/exec*/stop/deprovision) | Windows Sandbox enabled | | ||
| | `run_isolation_session_tests.ps1` | IsolationSession one-shot E2E suite | Interactive local session; OS-side IsolationSession service | | ||
| | `run_isolation_session_state_aware_tests.ps1` | IsolationSession provision/start/exec/stop/deprovision E2E suite | Interactive local session; OS-side IsolationSession service | | ||
| | `run_isolation_session_suites.ps1` | Runs every suite in an isolation-session test bundle (the two suites above, Node, Rust, .NET, apartment probe) with their pass criteria. Ships in the bundle; scheduled validation and the Windows OS lab both call it. `-List` names the packaged suites | A bundle from `scripts/ci/build-isolation-session-test-bundle.ps1`; interactive local session; OS-side IsolationSession service | |
There was a problem hiding this comment.
This feels incorrect. It's one thing to share azure pipeline and CI build scripts, but we shouldn't be putting in shared test scripts for OS test runs into the "main" repo imo. I'd rather we only share the build script if we can't easily share the "runner" script.
Why
The isolation-session test bundle is built twice, by the ADO job (for the OS vpack) and by
build-isolation-session-test-bundle.ps1(for GitHub nightly). Each consumer also carries its own copy of the suite oracles. The copies have drifted:sta_probe stareturnsCOMPLETEDon main. The OS adapter still expectsFAILED (not hung), so the next main pin bump would fail the lab.What
One builder. ADO and GitHub both call
scripts/ci/build-isolation-session-test-bundle.ps1.-SourceRootbuilds any checkout, so ADO can bundlefeature/isolation-session-internalwith main's script.-Phase Build|Validate|Alllets ADO sign between the two phases.-NodeRuntimePath.mxc_ffiis always the debugdotnetsdk,test-support,isolation_sessionbuild. This works whether or not the csproj supportsMxcTestPrebuiltNativeLibrary, which is what the feature branch needs.suite_runnerandsuites. Validate checks that-Listmatches the manifest.IsolationSession.TestBundle.Build.Job.ymlis now: builder Build → ESRP → builder Validate → publish.One runner. The new
tests/scripts/run_isolation_session_suites.ps1ships inside the bundle and owns every suite's invocation and oracle:-Listprints the suites whose payloads are present.-Suiteruns a subset.-BackendUnavailable Fail|Skip: GitHub uses Fail; the OS lab uses Skip.sdk_helperscwd test failed when the OS lab started it from system32.The runner comes from the source being bundled, so its oracles always match that source's binaries. The feature bundle has no runner until feature takes this change; the OS keeps its static rows for bundles without one.
run_backend_validation_tests.ps1now delegates to the bundled runner and keeps the local-account leak check.The publisher (
Vpack.Package.Job.yml) is unchanged. The bundle layout is a superset of the old one.Validation
isolation-session-bundlepasses on x64 and arm64.linux / x64hit a flakywxc_commontelemetry unit test. It passed on rerun; this PR has no Rust changes.Rollout
This is backward compatible. The OS change (os.2020,
user/dalegg/mxc-suite-runner) uses the runner when a bundle has one and falls back otherwise. It must land before the pin moves to a post-#1275 main, or the apartment row fails on the old oracle.Microsoft Reviewers: Open in CodeFlow