Skip to content

[IsolationSession] One bundle builder and one suite runner for ADO, GitHub, and the OS lab - #1359

Open
Dan Legg (danlegg) wants to merge 3 commits into
mainfrom
user/dalegg/iso-bundle-unify
Open

Dan Legg (danlegg) wants to merge 3 commits into
mainfrom
user/dalegg/iso-bundle-unify

Conversation

@danlegg

@danlegg Dan Legg (danlegg) commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Why

The isolation-session test bundle is built twice, by the ADO job (for the OS vpack) and by build-isolation-session-test-bundle.ps1 (for GitHub nightly). Each consumer also carries its own copy of the suite oracles. The copies have drifted:

  • The ADO job inlines about 300 lines of YAML that duplicate the script.
  • GitHub nightly runs 2 .NET classes; the OS lab runs the whole executable.
  • After [IsolationSession] Admit callers in a single-threaded apartment #1275, sta_probe sta returns COMPLETED on main. The OS adapter still expects FAILED (not hung), so the next main pin bump would fail the lab.

What

One builder. ADO and GitHub both call scripts/ci/build-isolation-session-test-bundle.ps1.

  • New parameters:
    • -SourceRoot builds any checkout, so ADO can bundle feature/isolation-session-internal with main's script.
    • -Phase Build|Validate|All lets ADO sign between the two phases.
    • -NodeRuntimePath.
  • Payloads that older sources lack (SDK-helper tests, the runner) are optional.
  • The .NET mxc_ffi is always the debug dotnetsdk,test-support,isolation_session build. This works whether or not the csproj supports MxcTestPrebuiltNativeLibrary, which is what the feature branch needs.
  • The manifest records suite_runner and suites. Validate checks that -List matches the manifest.
  • IsolationSession.TestBundle.Build.Job.yml is now: builder Build → ESRP → builder Validate → publish.

One runner. The new tests/scripts/run_isolation_session_suites.ps1 ships inside the bundle and owns every suite's invocation and oracle:

  • Suites: one-shot, state-aware, node, rust, rust-sdk-helpers, dotnet, apartment.
  • -List prints the suites whose payloads are present. -Suite runs a subset.
  • -BackendUnavailable Fail|Skip: GitHub uses Fail; the OS lab uses Skip.
  • It runs each suite from the bundle root. The sdk_helpers cwd test failed when the OS lab started it from system32.

The runner comes from the source being bundled, so its oracles always match that source's binaries. The feature bundle has no runner until feature takes this change; the OS keeps its static rows for bundles without one.

run_backend_validation_tests.ps1 now delegates to the bundled runner and keeps the local-account leak check.

The publisher (Vpack.Package.Job.yml) is unchanged. The bundle layout is a superset of the old one.

Validation

  • ADO Iso-Session pipeline, main + feature bundles: 159121073 at 9df267b (full run, including ESRP and SDL), and 159129303 at 12369a2.
    • The main manifest lists all 7 suites and ships the runner.
    • The feature bundle (old csproj, no runner) builds, signs and validates.
  • GitHub Scheduled Validation (nightly) at 9df267b: isolation-session-bundle passes on x64 and arm64.
    • The isolation-session jobs run through the runner on x64 and arm64, 153/153 passed: one-shot 24, state-aware 71, node 13, rust 17, rust-sdk-helpers 15, dotnet 9, apartment 4. No accounts leaked.
    • Re-run at 12369a2: 36775829920: isolation-session x64/arm64 153/153; ADO 159129303 main + feature Build/Sign/Validate/Publish passed.
  • OS lab harness on a 26700 SF2 VM, using the ADO artifacts in the OS test layout: main rows are runner-driven and all 7 suites pass. The feature bundle uses the static rows and all pass.
  • linux / x64 hit a flaky wxc_common telemetry unit test. It passed on rerun; this PR has no Rust changes.

Rollout

This is backward compatible. The OS change (os.2020, user/dalegg/mxc-suite-runner) uses the runner when a bundle has one and falls back otherwise. It must land before the pin moves to a post-#1275 main, or the apartment row fails on the old oracle.

Microsoft Reviewers: Open in CodeFlow

dalegg and others added 3 commits September 30, 2026 12:05
The OS vpack bundle (Azure Pipelines) and the scheduled-validation bundle
(GitHub Actions) had separate recipes, and scheduled validation and the
Windows OS lab had separate definitions of what each suite runs and what
passes. They had already drifted: the OS lab still expects the STA apartment
probe to fail, which #1275 changed, so its next vpack would regress.

- build-isolation-session-test-bundle.ps1 is now the only recipe. It builds
  any checkout (-SourceRoot), splits into Build and Validate phases so the
  pipeline can sign in between, and adopts the pipeline's .NET test-support
  native library and telemetry-test check. Payloads older sources lack are
  optional.
- tests/scripts/run_isolation_session_suites.ps1 ships in the bundle and owns
  each suite's invocation and oracle. Scheduled validation calls it with
  -BackendUnavailable Fail; the OS lab can call it with Skip and enumerate
  suites with -List. The manifest records the suites.
- The Azure Pipelines job runs the script instead of its inline copy.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 4f18230d-7852-4d2f-a862-71e88ae4d1e3
A single-element if-expression unwraps to a string, and splatting a
string passes each character as a separate argument.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 4f18230d-7852-4d2f-a862-71e88ae4d1e3
Suites that resolve their own cwd (sdk_helpers' available_tools_policy
test) failed when the host started the runner from system32, as the OS
lab does after relaunching into the console session.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 4f18230d-7852-4d2f-a862-71e88ae4d1e3
@danlegg
Dan Legg (danlegg) requested a review from a team as a code owner September 30, 2026 21:45
Copilot AI balanced review requested due to automatic review settings September 30, 2026 21:45
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The cross-system pipeline and external OS-lab integration require final human verification despite no specific defect found.

Review effort: Balanced
Findings: None

What changed in this PR

Centralizes IsolationSession test-bundle construction and suite execution across GitHub Actions, Azure Pipelines, and the OS lab.

Changes:

  • Adds a bundled runner owning suite discovery, execution, and pass criteria.
  • Extends the bundle builder with source-root and phased build/validation support.
  • Replaces duplicated CI orchestration and updates documentation.
File Description
tests/​scripts/​run_isolation_session_suites.ps1 Adds the unified seven-suite runner.
tests/​scripts/​README.md Documents the runner.
scripts/​ci/​run_backend_validation_tests.ps1 Delegates validation while retaining account-leak checks.
scripts/​ci/​build-isolation-session-test-bundle.ps1 Unifies bundle building and validation.
docs/​ci-validation-infrastructure.md Documents the shared CI flow.
.azure-pipelines/​templates/​IsolationSession.TestBundle.Build.Job.yml Replaces duplicated ADO logic with phased builder calls.
.github/​workflows/​Package.IsolationSession.TestBundle.Job.yml Continues GitHub bundle production through the shared builder.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@@ -0,0 +1,431 @@
<#

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why is this being added to MXC? Happy to approve it if I can understand why it's needed here.

Comment thread tests/scripts/README.md
| `run_windows_sandbox_state_aware_tests.ps1` | Windows Sandbox state-aware lifecycle E2E (single VM held across provision/start/exec*/stop/deprovision) | Windows Sandbox enabled |
| `run_isolation_session_tests.ps1` | IsolationSession one-shot E2E suite | Interactive local session; OS-side IsolationSession service |
| `run_isolation_session_state_aware_tests.ps1` | IsolationSession provision/start/exec/stop/deprovision E2E suite | Interactive local session; OS-side IsolationSession service |
| `run_isolation_session_suites.ps1` | Runs every suite in an isolation-session test bundle (the two suites above, Node, Rust, .NET, apartment probe) with their pass criteria. Ships in the bundle; scheduled validation and the Windows OS lab both call it. `-List` names the packaged suites | A bundle from `scripts/ci/build-isolation-session-test-bundle.ps1`; interactive local session; OS-side IsolationSession service |

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This feels incorrect. It's one thing to share azure pipeline and CI build scripts, but we shouldn't be putting in shared test scripts for OS test runs into the "main" repo imo. I'd rather we only share the build script if we can't easily share the "runner" script.

@microsoft-github-policy-service microsoft-github-policy-service Bot added the Needs-Author-Feedback Waiting for additional information or action from the issue or pull-request author. label Oct 1, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Needs-Author-Feedback Waiting for additional information or action from the issue or pull-request author.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants