mirror of
https://github.com/microsoft/PowerToys.git
synced 2026-08-29 01:59:34 +02:00
## Summary of the Pull Request Replaces the retired GitHub Models-based automatic issue triage and deduplication flows with the GitHub Agentic Workflow proven in the `niels9001/powertoys-ai-triage-sandbox`. This PR also: - aligns `Needs-Author-Feedback` closure to 7 days for issues and PRs; - removes the automatic GitHub Models issue/PR labeler; - removes the automatic GitHub Models new-issue deduplicator; - removes the Azure Pipelines XAML Styler verification step while retaining the local styling script. This is a draft because production rollout still requires the appropriate privacy and Responsible AI reviews. ## Issue triage rules ### Triggers and refresh behavior - Runs when an issue is opened, edited, or reopened. - Runs when the issue author attaches a `PowerToysReport_*.zip` in a comment. - Maintainers can force regeneration with `/triage refresh`. - Ignores unrelated comments, unchanged issue edits, PR comments, and bot-initiated reopens. - Uses per-issue concurrency so a newer run supersedes an older run. - Maintains one canonical triage comment instead of adding repeated bot comments. ### Comment format - Separates **For the issue author** from **For the PowerToys team**. - Mentions the author once and lists each requested action as a bullet. - Distinguishes blocking **Needed** actions from non-blocking **Recommended** actions. - Shows the product, issue kind, reported PowerToys version, concise summary, diagnostic findings, possible duplicates, and collapsed investigation checks. - Ends with a short disclosure that triage is AI-assisted and maintainers make final decisions. ### Classification and labels - Detects PowerToys bug-template issues deterministically. - Reads the selected product area and adds a matching primary `Product-*` label. - Handles production aliases such as FancyZones Editor and File Explorer preview/thumbnail areas. - Product labeling is additive: existing product and maintainer labels are never removed. - Normalizes the reported PowerToys version and adds a matching version label when one exists. - Applies `Needs-Author-Feedback` only when blocking information or an English translation is required. - Removes `Needs-Author-Feedback` when the issue becomes actionable. ### PowerToys version rule - Compares the reported version with the latest stable PowerToys GitHub release. - Older versions receive a recommended update-and-retest action. - Current versions, newer preview/dev versions, missing versions, and release lookup failures are not flagged as outdated. - Updating is advisory and does not block triage by itself. ### Reproduction rule - Concrete actions plus an observed result are sufficient. - Concise steps can use the separate Actual Behavior section as the observed result. - Passive or intermittent failures are sufficient when the timing/trigger and observed failure are clear. - Vague statements without an actionable scenario remain insufficient. - Clearly non-English steps are not treated as missing; reproduction is reassessed after the author translates the issue. ### Language rule - Classifies author-written prose as English, non-English, or uncertain. - Ignores template headings, code, logs, filenames, URLs, hidden comments, and quoted text. - Clearly non-English issues ask the author to translate the title and description to English. - Short, mixed, code-heavy, or uncertain text is not flagged. ### Diagnostic report rule - A report is **required** for diagnostic-heavy failures: crashes, hangs, startup/load failures, installation/update failures, performance failures, and service/driver/shell-integration failures. - A report is **optional** for clear reproducible UI/visual defects. - A report is **recommended**, but not blocking, for other actionable bugs. - Missing or rejected reports block only when the deterministic requirement is `REQUIRED`. ### Diagnostic report privacy and safety - Accepts only PowerToys report attachment URLs matching the expected pattern. - Enforces archive size, decompressed size, file-count, per-file, path traversal, and encryption limits. - Selects only bounded relevant metadata and product-log evidence. - Redacts email addresses, IP addresses, user paths, URLs, GUIDs, SIDs, identity fields, tokens, secrets, and passwords. - Sends only the sanitized evidence to Copilot. - Never sends the raw ZIP or extracted files to Copilot, logs, artifacts, or repository storage. - Deletes the temporary archive after processing. ### Duplicate rule - Searches only older issues using focused product, title/body, and exact technical-signal queries. - Ranks candidates deterministically before Copilot runs. - Copilot judges only the supplied candidates and returns at most five high-confidence matches. - Similar product area alone is not enough; the underlying request or failure must match. - The model never closes an issue directly. - The workflow submits the strongest match as a native GitHub duplicate-close suggestion. - **When a maintainer accepts the suggestion, GitHub automatically closes the issue as a duplicate and links it to the selected canonical issue.** - Declining the suggestion leaves the issue open. - A defensive safeguard reopens the issue and fails the run if GitHub applies the close without holding it for review. ### AI cost and permission controls - Uses the `small` model alias. - Maximum 5 turns and 10 AI credits per run. - Maximum 300 AI credits per day. - Maximum 5 runs per user per 60-minute window. - Content hashing skips unchanged work before inference. - The agent receives only `contents: read`, `issues: read`, and `copilot-requests: write`. - A separate validated safe-output job receives `issues: write`. ## Seven-day author-feedback lifecycle The existing Microsoft GitHub Policy Service configuration remains responsible for stale closure: - Open issues with `Needs-Author-Feedback` and no activity for 7 days are closed with an explanatory comment. - Open PRs with `Needs-Author-Feedback` and no activity for 7 days are closed with an explanatory comment. - An author comment removes `Needs-Author-Feedback` and returns the issue/PR to team triage. - An author push removes `Needs-Author-Feedback` from a PR. - Manually removing the label immediately makes the issue or PR ineligible for scheduled closure. ## Deprecated automation - Deletes `.github/workflows/automatic-issue-deduplication.yml`. - Deletes `.github/workflows/auto-labeler.yml`. - Automatic PR product labeling from the old Models workflow is intentionally not replaced in this PR; a production PR ownership/path map should be agreed separately. - Keeps the manual batch deduplication workflow unchanged. - Removes the passive XAML Styler verification step from `.pipelines/v2/templates/job-build-project.yml`. - Keeps `.pipelines/applyXamlStyling.ps1` available for local developer use. ## Validation Steps Performed - Compiled `.github/workflows/issue-triage.md` with `gh aw compile`. - Ran 32 focused Python tests for issue parsing, duplicate retrieval, version checks, reproduction rules, language signals, archive validation, report selection, redaction, and output privacy. - Parsed the changed workflow and resource-management YAML. - Verified the required production labels exist. - Tested the workflow against the latest 20 PowerToys issues in the sandbox; all 20 produced one canonical comment. - Verified live variants for outdated versions, intermittent/passive reproduction, non-English issues, rejected and analyzed reports, optional UI reports, and title-only issues. ## PR Checklist - [ ] **Communication:** Discussed with core contributors. - [x] **Tests:** Added/updated and all focused tests pass. - [ ] **Privacy / Responsible AI:** Complete required production reviews before enabling. - [x] **Localization:** No product UI strings are added. - [x] **Dev docs:** Updated repository automation documentation. - [x] **New binaries:** None. --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 18a9b8ad-fd7e-4b9d-a06c-5e350bcde9d7 Copilot-Session: fd512b9b-db6f-4004-a65b-aa49404d568d
708 lines
28 KiB
YAML
708 lines
28 KiB
YAML
parameters:
|
|
- name: additionalBuildOptions
|
|
type: string
|
|
default: ''
|
|
- name: buildConfigurations
|
|
type: object
|
|
default:
|
|
- Release
|
|
- name: buildPlatforms
|
|
type: object
|
|
default:
|
|
- x64
|
|
- arm64
|
|
- name: official
|
|
type: boolean
|
|
default: false
|
|
- name: codeSign
|
|
type: boolean
|
|
default: false
|
|
- name: artifactStem
|
|
type: string
|
|
default: ''
|
|
- name: jobName
|
|
type: string
|
|
default: 'Build'
|
|
- name: condition
|
|
type: string
|
|
default: ''
|
|
- name: dependsOn
|
|
type: object
|
|
default: []
|
|
- name: pool
|
|
type: object
|
|
default: []
|
|
- name: beforeBuildSteps
|
|
type: stepList
|
|
default: []
|
|
- name: variables
|
|
type: object
|
|
default: {}
|
|
- name: publishArtifacts
|
|
type: boolean
|
|
default: true
|
|
- name: signingIdentity
|
|
type: object
|
|
default: {}
|
|
- name: enablePackageCaching
|
|
type: boolean
|
|
default: false
|
|
- name: enableMsBuildCaching
|
|
type: boolean
|
|
default: false
|
|
- name: msBuildCacheIsReadOnly
|
|
type: boolean
|
|
default: true
|
|
- name: runTests
|
|
type: boolean
|
|
default: true
|
|
- name: buildTests
|
|
type: boolean
|
|
default: true
|
|
- name: useVSPreview
|
|
type: boolean
|
|
default: false
|
|
- name: versionNumber
|
|
type: string
|
|
default: '0.0.1'
|
|
- name: resolvedVersionNumber
|
|
type: string
|
|
default: ''
|
|
- name: useLatestWinAppSDK
|
|
type: boolean
|
|
default: false
|
|
- name: winAppSDKVersionNumber
|
|
type: string
|
|
default: '2.0'
|
|
- name: useExperimentalVersion
|
|
type: boolean
|
|
default: false
|
|
# Artifact mode parameters
|
|
- name: useArtifactSource
|
|
type: boolean
|
|
default: false
|
|
- name: azureDevOpsOrg
|
|
type: string
|
|
default: 'https://dev.azure.com/microsoft'
|
|
- name: azureDevOpsProject
|
|
type: string
|
|
default: 'ProjectReunion'
|
|
- name: buildId
|
|
type: string
|
|
default: ''
|
|
- name: artifactName
|
|
type: string
|
|
default: 'WindowsAppSDK_Nuget_And_MSIX'
|
|
- name: metaPackageName
|
|
type: string
|
|
default: 'Microsoft.WindowsAppSDK'
|
|
- name: csProjectsToPublish
|
|
type: object
|
|
default:
|
|
- 'src/settings-ui/Settings.UI/PowerToys.Settings.csproj'
|
|
- 'src/modules/launcher/PowerLauncher/PowerLauncher.csproj'
|
|
- 'src/modules/previewpane/MonacoPreviewHandler/MonacoPreviewHandler.csproj'
|
|
- 'src/modules/previewpane/MarkdownPreviewHandler/MarkdownPreviewHandler.csproj'
|
|
- 'src/modules/previewpane/SvgPreviewHandler/SvgPreviewHandler.csproj'
|
|
- 'src/modules/previewpane/SvgThumbnailProvider/SvgThumbnailProvider.csproj'
|
|
- 'src/modules/FileLocksmith/FileLocksmithUI/FileLocksmithUI.csproj'
|
|
- name: timeoutInMinutes
|
|
type: number
|
|
default: 240
|
|
- name: cancelTimeoutInMinutes
|
|
type: number
|
|
default: 1
|
|
|
|
jobs:
|
|
- job: ${{ parameters.jobName }}
|
|
${{ if ne(length(parameters.pool), 0) }}:
|
|
pool: ${{ parameters.pool }}
|
|
dependsOn: ${{ parameters.dependsOn }}
|
|
condition: ${{ parameters.condition }}
|
|
strategy:
|
|
matrix:
|
|
${{ each config in parameters.buildConfigurations }}:
|
|
${{ each platform in parameters.buildPlatforms }}:
|
|
${{ config }}_${{ platform }}:
|
|
BuildConfiguration: ${{ config }}
|
|
BuildPlatform: ${{ platform }}
|
|
${{ if eq(platform, 'x86') }}:
|
|
OutputBuildPlatform: Win32
|
|
${{ elseif eq(platform, 'Any CPU') }}:
|
|
OutputBuildPlatform: AnyCPU
|
|
${{ else }}:
|
|
OutputBuildPlatform: ${{ platform }}
|
|
variables:
|
|
NUGET_PACKAGES: 'C:\NuGetPackages' # Some of our build steps cache these here... and it was apparently part of the global environment
|
|
MakeAppxPath: 'C:\Program Files (x86)\Windows Kits\10\bin\10.0.26100.0\x86\MakeAppx.exe'
|
|
# Azure DevOps abhors a vacuum
|
|
# If these are blank, expansion will fail later on... which will result in direct substitution of the variable *names*
|
|
# later on. We'll just... set them to a single space and if we need to, check IsNullOrWhiteSpace.
|
|
# Yup.
|
|
MSBuildCacheParameters: ' '
|
|
JobOutputDirectory: $(Build.ArtifactStagingDirectory)
|
|
LogOutputDirectory: $(Build.ArtifactStagingDirectory)\logs
|
|
JobOutputArtifactName: build-$(BuildPlatform)-$(BuildConfiguration)${{ parameters.artifactStem }}
|
|
${{ if eq(parameters.resolvedVersionNumber, '') }}:
|
|
EffectiveVersionNumber: ${{ parameters.versionNumber }}
|
|
${{ if ne(parameters.resolvedVersionNumber, '') }}:
|
|
EffectiveVersionNumber: ${{ parameters.resolvedVersionNumber }}
|
|
NUGET_RESTORE_MSBUILD_ARGS: /p:Platform=$(BuildPlatform) # Required for nuget to work due to self contained
|
|
NODE_OPTIONS: --max_old_space_size=16384
|
|
${{ if or(eq(parameters.runTests, true), eq(parameters.buildTests, true)) }}:
|
|
MSBuildMainBuildTargets: Build;Test
|
|
${{ else }}:
|
|
MSBuildMainBuildTargets: Build
|
|
${{ insert }}: ${{ parameters.variables }}
|
|
${{ if eq(parameters.useLatestWinAppSDK, true) }}:
|
|
RestoreAdditionalProjectSourcesArg: '/p:RestoreAdditionalProjectSources="$(Build.SourcesDirectory)\localpackages\NugetPackages" /p:IgnoreExperimentalWarnings=true'
|
|
${{ else }}:
|
|
RestoreAdditionalProjectSourcesArg: ''
|
|
displayName: Build
|
|
timeoutInMinutes: ${{ parameters.timeoutInMinutes }}
|
|
cancelTimeoutInMinutes: ${{ parameters.cancelTimeoutInMinutes }}
|
|
templateContext: # Required when this template is hosted in 1ES PT
|
|
outputs:
|
|
- output: pipelineArtifact
|
|
artifactName: $(JobOutputArtifactName)
|
|
targetPath: $(Build.ArtifactStagingDirectory)
|
|
- output: pipelineArtifact
|
|
artifactName: $(JobOutputArtifactName)-failure-$(System.JobAttempt)
|
|
targetPath: $(LogOutputDirectory)
|
|
condition: or(failed(), canceled())
|
|
steps:
|
|
- checkout: self
|
|
clean: true
|
|
submodules: true
|
|
persistCredentials: True
|
|
fetchTags: false
|
|
fetchDepth: 1
|
|
|
|
# Checkout to surface a missing import before full build.
|
|
- pwsh: |-
|
|
& '.pipelines/verifyCommonProps.ps1' -sourceDir '$(build.sourcesdirectory)\src'
|
|
displayName: Audit shared common props for CSharp projects in src sub-folder
|
|
|
|
- ${{ if eq(parameters.enableMsBuildCaching, true) }}:
|
|
- pwsh: |-
|
|
$MSBuildCacheParameters = ""
|
|
$MSBuildCacheParameters += " -graph"
|
|
$MSBuildCacheParameters += " -reportfileaccesses"
|
|
$MSBuildCacheParameters += " -p:MSBuildCacheEnabled=true"
|
|
$MSBuildCacheParameters += " -p:MSBuildCacheLogDirectory=$(LogOutputDirectory)\MSBuildCacheLogs"
|
|
# Cache read-only policy controlled by parameter
|
|
$cacheIsReadOnly = "${{ parameters.msBuildCacheIsReadOnly }}"
|
|
if ($cacheIsReadOnly -eq "True") {
|
|
$MSBuildCacheParameters += " /p:MSBuildCacheRemoteCacheIsReadOnly=true"
|
|
}
|
|
Write-Host "MSBuildCacheParameters: $MSBuildCacheParameters"
|
|
Write-Host "##vso[task.setvariable variable=MSBuildCacheParameters]$MSBuildCacheParameters"
|
|
displayName: Prepare MSBuildCache variables
|
|
|
|
- template: steps-ensure-dotnet-version.yml
|
|
parameters:
|
|
sdk: true
|
|
version: '6.0' # .NET 6.0 is required in CI for ESRP code signing tasks. Please do not remove.
|
|
|
|
- template: steps-ensure-dotnet-version.yml
|
|
parameters:
|
|
sdk: true
|
|
version: '8.0'
|
|
|
|
- template: steps-ensure-dotnet-version.yml
|
|
parameters:
|
|
sdk: true
|
|
version: '10.0'
|
|
# SDK 10.0.303 contains runtime 10.0.11. Keep this aligned with DotNetRuntimePackageVersion in Directory.Packages.props.
|
|
exactVersion: '10.0.303'
|
|
|
|
- ${{ if eq(parameters.runTests, true) }}:
|
|
- task: VisualStudioTestPlatformInstaller@1
|
|
displayName: Ensure VSTest Platform
|
|
|
|
- task: NuGetAuthenticate@1
|
|
displayName: Authenticate NuGet feeds for verification
|
|
|
|
- pwsh: |-
|
|
& '.pipelines/verifyNugetPackages.ps1' -solution '$(build.sourcesdirectory)\PowerToys.slnx'
|
|
displayName: Verify Nuget package versions for PowerToys.slnx
|
|
|
|
- pwsh: |-
|
|
& '.pipelines/verifyArm64Configuration.ps1' -solution '$(build.sourcesdirectory)\PowerToys.slnx'
|
|
& '.pipelines/verifyArm64Configuration.ps1' -solution '$(build.sourcesdirectory)\tools\BugReportTool\BugReportTool.sln'
|
|
& '.pipelines/verifyArm64Configuration.ps1' -solution '$(build.sourcesdirectory)\tools\StylesReportTool\StylesReportTool.sln'
|
|
& '.pipelines/verifyArm64Configuration.ps1' -solution '$(build.sourcesdirectory)\installer\PowerToysSetup.slnx'
|
|
displayName: Verify ARM64 configurations
|
|
|
|
- ${{ if eq(parameters.enablePackageCaching, true) }}:
|
|
- task: Cache@2
|
|
displayName: 'Cache nuget packages (PackageReference)'
|
|
inputs:
|
|
key: '"PackageReference" | "$(Agent.OS)" | Directory.Packages.props'
|
|
restoreKeys: |
|
|
"PackageReference" | "$(Agent.OS)"
|
|
"PackageReference"
|
|
path: $(NUGET_PACKAGES)
|
|
|
|
- task: Cache@2
|
|
displayName: 'Cache nuget packages (packages.config)'
|
|
inputs:
|
|
key: '"packages.config" | "$(Agent.OS)" | **/packages.config'
|
|
restoreKeys: |
|
|
"packages.config" | "$(Agent.OS)"
|
|
"packages.config"
|
|
path: packages
|
|
|
|
- ${{ if eq(parameters.useLatestWinAppSDK, true)}}:
|
|
- template: .\steps-update-winappsdk-and-restore-nuget.yml
|
|
parameters:
|
|
versionNumber: ${{ parameters.winAppSDKVersionNumber }}
|
|
useExperimentalVersion: ${{ parameters.useExperimentalVersion }}
|
|
useArtifactSource: ${{ parameters.useArtifactSource }}
|
|
azureDevOpsOrg: ${{ parameters.azureDevOpsOrg }}
|
|
azureDevOpsProject: ${{ parameters.azureDevOpsProject }}
|
|
buildId: ${{ parameters.buildId }}
|
|
artifactName: ${{ parameters.artifactName }}
|
|
metaPackageName: ${{ parameters.metaPackageName }}
|
|
|
|
- ${{ if eq(parameters.useLatestWinAppSDK, false)}}:
|
|
- template: .\steps-restore-nuget.yml
|
|
|
|
- pwsh: |-
|
|
& "$(build.sourcesdirectory)\.pipelines\verifyAndSetLatestVCToolsVersion.ps1"
|
|
displayName: Work around DD-1541167 (VCToolsVersion)
|
|
${{ if eq(parameters.useVSPreview, true) }}:
|
|
env:
|
|
VCWhereExtraVersionTarget: '-prerelease'
|
|
|
|
- ${{ if eq(parameters.official, true) }}:
|
|
# M.W.T.V Setup.ps1 sets the pipeline-level XES_APPXMANIFESTVERSION env var
|
|
# from the supplied -ProjectDirectory's custom.props. Whichever invocation
|
|
# runs last wins. cmdpal MUST run last because $(CmdPalVersion) (used by the
|
|
# VNext installer and CmdPal's AppxPackageTestDir) falls back to that env
|
|
# var; if AP wins, CmdPal's folder name and MSIX filename disagree on
|
|
# VersionMinor and the installer fails with WIX0103. Each project's own
|
|
# custom.props is still applied at MSBuild time, so AP versioning is
|
|
# unaffected by the order.
|
|
- template: .\steps-setup-versioning.yml
|
|
parameters:
|
|
directory: $(build.sourcesdirectory)\src\modules\AdvancedPaste
|
|
- template: .\steps-setup-versioning.yml
|
|
parameters:
|
|
directory: $(build.sourcesdirectory)\src\modules\cmdpal
|
|
|
|
# --- vcpkg detection + binary cache --------------------------------------
|
|
# PowerToys consumes spdlog (and, over time, other native deps) via vcpkg in
|
|
# manifest mode. steps-install-vcpkg.yml prefers the vcpkg shipped with
|
|
# Visual Studio (Microsoft.VisualStudio.Component.Vcpkg) and falls back to a
|
|
# fresh clone of microsoft/vcpkg into deps/vcpkg if VS doesn't have it.
|
|
# Either way it sets the VCPKG_ROOT pipeline variable; MSBuild integration
|
|
# is wired globally from Cpp.Build.props (with vcpkg.targets in
|
|
# Cpp.Build.targets) using the three-tier VcpkgRoot fallback
|
|
# (env var > VS-shipped > deps/vcpkg runtime clone).
|
|
#
|
|
# Vcpkg's MSBuild integration runs `vcpkg install` once per project, so the
|
|
# binary cache below saves ~3-5 minutes per triplet on cache hits.
|
|
- template: .\steps-install-vcpkg.yml
|
|
parameters:
|
|
useVSPreview: ${{ parameters.useVSPreview }}
|
|
|
|
- ${{ if eq(parameters.enablePackageCaching, true) }}:
|
|
- task: Cache@2
|
|
displayName: 'Cache vcpkg binary archives'
|
|
inputs:
|
|
# Key on the inputs vcpkg uses to compute its package ABI: the manifest,
|
|
# configuration, every overlay-port file, and the agent OS.
|
|
key: '"vcpkg" | "$(Agent.OS)" | vcpkg.json | vcpkg-configuration.json | deps/vcpkg-overlays/**'
|
|
restoreKeys: |
|
|
"vcpkg" | "$(Agent.OS)"
|
|
"vcpkg"
|
|
path: $(LOCALAPPDATA)\vcpkg\archives
|
|
|
|
|
|
|
|
- ${{ parameters.beforeBuildSteps }}
|
|
|
|
- task: VSBuild@1
|
|
${{ if eq(parameters.runTests, true) }}:
|
|
displayName: Build and Test PowerToys main project
|
|
${{ else }}:
|
|
displayName: Build PowerToys main project
|
|
inputs:
|
|
solution: 'PowerToys.slnx'
|
|
vsVersion: 18.0
|
|
msbuildArgs: >-
|
|
-restore -graph
|
|
/p:RestorePackagesConfig=true
|
|
/p:CIBuild=true
|
|
/p:BuildTests=${{ parameters.buildTests }}
|
|
/bl:$(LogOutputDirectory)\build-0-main.binlog
|
|
${{ parameters.additionalBuildOptions }}
|
|
$(MSBuildCacheParameters)
|
|
/t:$(MSBuildMainBuildTargets)
|
|
$(RestoreAdditionalProjectSourcesArg)
|
|
platform: $(BuildPlatform)
|
|
configuration: $(BuildConfiguration)
|
|
msbuildArchitecture: x64
|
|
maximumCpuCount: true
|
|
${{ if eq(parameters.enableMsBuildCaching, true) }}:
|
|
env:
|
|
SYSTEM_ACCESSTOKEN: $(System.AccessToken)
|
|
|
|
- task: VSBuild@1
|
|
displayName: Generate DSC artifacts for ARM64
|
|
condition: and(succeeded(), eq(variables['BuildPlatform'], 'arm64'))
|
|
inputs:
|
|
solution: PowerToys.slnx
|
|
vsVersion: 18.0
|
|
msbuildArgs: >-
|
|
-restore
|
|
/p:Configuration=$(BuildConfiguration)
|
|
/p:Platform=x64
|
|
/t:DSC\PowerToys_Settings_DSC_Schema_Generator
|
|
/bl:$(LogOutputDirectory)\build-dsc-generator.binlog
|
|
${{ parameters.additionalBuildOptions }}
|
|
$(MSBuildCacheParameters)
|
|
$(RestoreAdditionalProjectSourcesArg)
|
|
platform: x64
|
|
configuration: $(BuildConfiguration)
|
|
msbuildArchitecture: x64
|
|
maximumCpuCount: true
|
|
|
|
# Build PowerToys.DSC.exe for ARM64 (x64 uses existing binary from previous build)
|
|
- task: VSBuild@1
|
|
displayName: Build PowerToys.DSC.exe (x64 for generating manifests)
|
|
condition: and(succeeded(), ne(variables['BuildPlatform'], 'x64'))
|
|
inputs:
|
|
solution: src/dsc/v3/PowerToys.DSC/PowerToys.DSC.csproj
|
|
msbuildArgs: /t:Build /m /restore
|
|
platform: x64
|
|
configuration: $(BuildConfiguration)
|
|
msbuildArchitecture: x64
|
|
maximumCpuCount: true
|
|
|
|
# Generate DSC manifests using PowerToys.DSC.exe
|
|
- pwsh: |-
|
|
& '.pipelines/generateDscManifests.ps1' -BuildPlatform '$(BuildPlatform)' -BuildConfiguration '$(BuildConfiguration)' -RepoRoot '$(Build.SourcesDirectory)'
|
|
displayName: Generate DSC manifests
|
|
|
|
- task: CopyFiles@2
|
|
displayName: Stage SDK/build
|
|
inputs:
|
|
contents: |-
|
|
"**/cmdpal/extensionsdk/nuget/Microsoft.CommandPalette.Extensions.SDK.props"
|
|
"**/cmdpal/extensionsdk/nuget/Microsoft.CommandPalette.Extensions.SDK.targets"
|
|
flattenFolders: True
|
|
targetFolder: $(JobOutputDirectory)/sdk/build
|
|
|
|
- task: CopyFiles@2
|
|
displayName: Stage SDK/lib
|
|
inputs:
|
|
contents: |-
|
|
"**/Microsoft.CommandPalette.Extensions.Toolkit/$(BuildPlatform)/release/WinUI3Apps/CmdPal/Microsoft.CommandPalette.Extensions.Toolkit.dll"
|
|
"**/Microsoft.CommandPalette.Extensions.Toolkit/$(BuildPlatform)/release/WinUI3Apps/CmdPal/Microsoft.CommandPalette.Extensions.Toolkit.deps.json"
|
|
flattenFolders: True
|
|
targetFolder: $(JobOutputDirectory)/sdk/lib/net8.0-windows10.0.19041.0
|
|
|
|
- task: CopyFiles@2
|
|
displayName: Stage SDK/winmd
|
|
inputs:
|
|
contents: |-
|
|
"**/Microsoft.CommandPalette.Extensions/$(BuildPlatform)/release/Microsoft.CommandPalette.Extensions/Microsoft.CommandPalette.Extensions.winmd"
|
|
flattenFolders: True
|
|
targetFolder: $(JobOutputDirectory)/sdk/winmd
|
|
|
|
- task: VSBuild@1
|
|
displayName: Build BugReportTool
|
|
inputs:
|
|
solution: '**/tools/BugReportTool/BugReportTool.sln'
|
|
vsVersion: 18.0
|
|
msbuildArgs: >-
|
|
-restore -graph
|
|
/p:RestorePackagesConfig=true
|
|
/p:CIBuild=true
|
|
/bl:$(LogOutputDirectory)\build-bug-report.binlog
|
|
${{ parameters.additionalBuildOptions }}
|
|
$(MSBuildCacheParameters)
|
|
$(RestoreAdditionalProjectSourcesArg)
|
|
platform: $(BuildPlatform)
|
|
configuration: $(BuildConfiguration)
|
|
msbuildArchitecture: x64
|
|
maximumCpuCount: true
|
|
${{ if eq(parameters.enableMsBuildCaching, true) }}:
|
|
env:
|
|
SYSTEM_ACCESSTOKEN: $(System.AccessToken)
|
|
|
|
- task: VSBuild@1
|
|
displayName: Build StylesReportTool
|
|
inputs:
|
|
solution: '**/tools/StylesReportTool/StylesReportTool.sln'
|
|
vsVersion: 18.0
|
|
msbuildArgs: >-
|
|
-restore -graph
|
|
/p:RestorePackagesConfig=true
|
|
/p:CIBuild=true
|
|
/bl:$(LogOutputDirectory)\build-styles-report.binlog
|
|
${{ parameters.additionalBuildOptions }}
|
|
$(MSBuildCacheParameters)
|
|
$(RestoreAdditionalProjectSourcesArg)
|
|
platform: $(BuildPlatform)
|
|
configuration: $(BuildConfiguration)
|
|
msbuildArchitecture: x64
|
|
maximumCpuCount: true
|
|
${{ if eq(parameters.enableMsBuildCaching, true) }}:
|
|
env:
|
|
SYSTEM_ACCESSTOKEN: $(System.AccessToken)
|
|
|
|
- ${{ each project in parameters.csProjectsToPublish }}:
|
|
- task: VSBuild@1
|
|
displayName: Publish ${{ project }} for Packaging
|
|
inputs:
|
|
solution: ${{ project }}
|
|
vsVersion: 18.0
|
|
msbuildArgs: >-
|
|
/target:Publish
|
|
/graph
|
|
/p:Configuration=$(BuildConfiguration);Platform=$(BuildPlatform);AppxBundle=Never
|
|
/p:VCRTForwarders-IncludeDebugCRT=false
|
|
/p:PowerToysRoot=$(Build.SourcesDirectory)
|
|
/p:PublishProfile=InstallationPublishProfile.pubxml
|
|
/p:TargetFramework=net10.0-windows10.0.26100.0
|
|
/bl:$(LogOutputDirectory)\publish-${{ join('_',split(project, '/')) }}.binlog
|
|
$(RestoreAdditionalProjectSourcesArg)
|
|
platform: $(BuildPlatform)
|
|
configuration: $(BuildConfiguration)
|
|
msbuildArchitecture: x64
|
|
maximumCpuCount: true
|
|
|
|
### HACK: On ARM64 builds, building an app with Windows App SDK copies the x64 WebView2 dll instead of the ARM64 one. This task makes sure the right dll is used.
|
|
- task: CopyFiles@2
|
|
displayName: HACK Copy core WebView2 ARM64 dll to output directory
|
|
condition: and(succeeded(), eq(variables['BuildPlatform'], 'arm64'))
|
|
inputs:
|
|
contents: packages/Microsoft.Web.WebView2.1.0.2903.40/runtimes/win-ARM64/native_uap/Microsoft.Web.WebView2.Core.dll
|
|
targetFolder: $(Build.SourcesDirectory)/ARM64/Release/WinUI3Apps/
|
|
flattenFolders: True
|
|
OverWrite: True
|
|
|
|
# Check if deps.json files don't reference different dll versions.
|
|
- pwsh: |-
|
|
& '.pipelines/verifyDepsJsonLibraryVersions.ps1' -targetDir '$(build.sourcesdirectory)\$(BuildPlatform)\$(BuildConfiguration)'
|
|
displayName: Audit deps.json files for all applications
|
|
|
|
# Check if asset files on the main application paths are playing nice and avoiding basic conflicts.
|
|
- pwsh: |-
|
|
& '.pipelines/verifyPossibleAssetConflicts.ps1' -targetDir '$(build.sourcesdirectory)\$(BuildPlatform)\$(BuildConfiguration)'
|
|
displayName: Audit base applications path asset conflicts
|
|
|
|
- pwsh: |-
|
|
& '.pipelines/verifyPossibleAssetConflicts.ps1' -targetDir '$(build.sourcesdirectory)\$(BuildPlatform)\$(BuildConfiguration)\WinUI3Apps'
|
|
displayName: Audit WinAppSDK applications path asset conflicts
|
|
|
|
# To streamline the pipeline and prevent errors, skip this step during compatibility tests with the latest WinAppSDK.
|
|
- ${{ if eq(parameters.useLatestWinAppSDK, false) }}:
|
|
- pwsh: |-
|
|
& '.pipelines/verifyNoticeMdAgainstNugetPackages.ps1' -path '$(build.sourcesdirectory)\'
|
|
displayName: Verify NOTICE.md and NuGet packages match
|
|
|
|
- ${{ if eq(parameters.runTests, true) }}:
|
|
# Publish test results which ran in MSBuild
|
|
- task: PublishTestResults@2
|
|
displayName: 'Publish Test Results'
|
|
inputs:
|
|
testResultsFormat: VSTest
|
|
testResultsFiles: '**/*.trx'
|
|
condition: and(succeeded(), ne(variables['BuildPlatform'], 'arm64'))
|
|
|
|
# Native dlls
|
|
- task: VSTest@2
|
|
condition: and(succeeded(), ne(variables['BuildPlatform'], 'arm64')) # No arm64 agents to run the tests.
|
|
displayName: 'Native Tests'
|
|
inputs:
|
|
platform: '$(BuildPlatform)'
|
|
configuration: '$(BuildConfiguration)'
|
|
testSelector: 'testAssemblies'
|
|
testAssemblyVer2: |
|
|
**\KeyboardManagerEngineTest.dll
|
|
**\KeyboardManagerEditorTest.dll
|
|
**\*UnitTest*.dll
|
|
!**\obj\**
|
|
|
|
- pwsh: |-
|
|
$Packages = Get-ChildItem -Recurse -Filter "Microsoft.CmdPal.UI_*.msix"
|
|
Write-Host "Found $($Packages.Count) CmdPal MSIX package(s):"
|
|
foreach ($pkg in $Packages) {
|
|
Write-Host " - $($pkg.FullName)"
|
|
}
|
|
|
|
if ($Packages.Count -gt 0) {
|
|
# Priority: Look for platform-specific MSIX (x64/arm64) first, then fall back to any
|
|
$PlatformPackage = $Packages | Where-Object { $_.Name -match "Microsoft\.CmdPal\.UI_.*_(x64|arm64)\.msix$" } | Select-Object -First 1
|
|
if ($PlatformPackage) {
|
|
$Package = $PlatformPackage
|
|
Write-Host "Using platform-specific package: $($Package.FullName)"
|
|
} else {
|
|
$Package = $Packages | Select-Object -First 1
|
|
Write-Host "Using first available package: $($Package.FullName)"
|
|
}
|
|
|
|
$PackageFilename = $Package.FullName
|
|
Write-Host "##vso[task.setvariable variable=CmdPalPackagePath]${PackageFilename}"
|
|
} else {
|
|
Write-Warning "No CmdPal MSIX packages found!"
|
|
}
|
|
displayName: Locate the CmdPal MSIX
|
|
|
|
- ${{ if eq(parameters.codeSign, true) }}:
|
|
- pwsh: |-
|
|
& "$(MakeAppxPath)" unpack /p "$(CmdPalPackagePath)" /d "$(JobOutputDirectory)/CmdPalPackageContents"
|
|
displayName: Unpack the MSIX for signing
|
|
|
|
- template: steps-esrp-signing.yml
|
|
parameters:
|
|
displayName: Sign CmdPal MSIX content
|
|
signingIdentity: ${{ parameters.signingIdentity }}
|
|
inputs:
|
|
FolderPath: '$(JobOutputDirectory)/CmdPalPackageContents'
|
|
signType: batchSigning
|
|
batchSignPolicyFile: '$(build.sourcesdirectory)\.pipelines\ESRPSigning_cmdpal_msix_content.json'
|
|
ciPolicyFile: '$(build.sourcesdirectory)\.pipelines\CIPolicy.xml'
|
|
|
|
- pwsh: |-
|
|
$outDir = New-Item -Type Directory "$(JobOutputDirectory)/_appx" -ErrorAction:Ignore
|
|
$PackageFilename = Join-Path $outDir.FullName (Split-Path -Leaf "$(CmdPalPackagePath)")
|
|
& "$(MakeAppxPath)" pack /h SHA256 /o /p $PackageFilename /d "$(JobOutputDirectory)/CmdPalPackageContents"
|
|
Copy-Item -Force $PackageFilename "$(CmdPalPackagePath)"
|
|
Remove-Item -Force -Recurse "$(JobOutputDirectory)/CmdPalPackageContents" -ErrorAction:Ignore
|
|
Remove-Item -Force -Recurse "$(JobOutputDirectory)/_appx" -ErrorAction:Ignore
|
|
displayName: Re-pack the new CmdPal package after signing
|
|
|
|
- pwsh: |
|
|
$testsPath = "$(Build.SourcesDirectory)/$(BuildPlatform)/$(BuildConfiguration)/tests"
|
|
if (Test-Path $testsPath) {
|
|
Remove-Item -Path $testsPath -Recurse -Force
|
|
Write-Host "Removed tests folder to reduce signing workload: $testsPath"
|
|
}
|
|
displayName: Remove tests folder before signing
|
|
|
|
- template: steps-esrp-signing.yml
|
|
parameters:
|
|
displayName: Sign Core PowerToys
|
|
signingIdentity: ${{ parameters.signingIdentity }}
|
|
inputs:
|
|
FolderPath: '$(BuildPlatform)/$(BuildConfiguration)'
|
|
signType: batchSigning
|
|
batchSignPolicyFile: '$(build.sourcesdirectory)\.pipelines\ESRPSigning_core.json'
|
|
ciPolicyFile: '$(build.sourcesdirectory)\.pipelines\CIPolicy.xml'
|
|
|
|
- template: steps-esrp-signing.yml
|
|
parameters:
|
|
displayName: Sign DSC files
|
|
signingIdentity: ${{ parameters.signingIdentity }}
|
|
inputs:
|
|
FolderPath: 'src/dsc/Microsoft.PowerToys.Configure'
|
|
signType: batchSigning
|
|
batchSignPolicyFile: '$(build.sourcesdirectory)\.pipelines\ESRPSigning_DSC.json'
|
|
ciPolicyFile: '$(build.sourcesdirectory)\.pipelines\CIPolicy.xml'
|
|
|
|
- pwsh: |-
|
|
Copy-Item -Verbose -Force "$(CmdPalPackagePath)" "$(JobOutputDirectory)"
|
|
displayName: Stage the final CmdPal package
|
|
|
|
|
|
|
|
- template: steps-build-installer-vnext.yml
|
|
parameters:
|
|
codeSign: ${{ parameters.codeSign }}
|
|
signingIdentity: ${{ parameters.signingIdentity }}
|
|
versionNumber: $(EffectiveVersionNumber)
|
|
additionalBuildOptions: ${{ parameters.additionalBuildOptions }}
|
|
|
|
# This saves ~1GiB per architecture. We won't need these later.
|
|
# Removes:
|
|
# - All .pdb files from any static libs .libs (which were only used during linking)
|
|
- pwsh: |-
|
|
$binDir = '$(Build.SourcesDirectory)'
|
|
$ImportLibs = Get-ChildItem $binDir -Recurse -File -Filter '*.exp' | ForEach-Object { $_.FullName -Replace "exp$","lib" }
|
|
$StaticLibs = Get-ChildItem $binDir -Recurse -File -Filter '*.lib' | Where-Object FullName -NotIn $ImportLibs
|
|
|
|
$Items = @()
|
|
$Items += Get-Item ($StaticLibs.FullName -Replace "lib$","pdb") -ErrorAction:Ignore
|
|
|
|
$Items | Remove-Item -Recurse -Force -Verbose -ErrorAction:Ignore
|
|
displayName: Clean up static libs PDBs
|
|
errorActionPreference: silentlyContinue # It's OK if this silently fails
|
|
|
|
- task: CopyFiles@2
|
|
displayName: Stage Installers
|
|
inputs:
|
|
contents: |-
|
|
**/PowerToys*Setup-*.exe
|
|
!**/PowerToysSetupVNext/obj/**
|
|
flattenFolders: True
|
|
targetFolder: $(JobOutputDirectory)
|
|
|
|
- pwsh: |-
|
|
$Symbols = Get-ChildItem "$(BuildPlatform)" -Recurse -Filter *.pdb -Exclude "vc143.pdb","*test*.pdb" |
|
|
Group-Object Name | ForEach-Object { $_.Group[0] }
|
|
$OutDir = "$(JobOutputDirectory)/symbols-$(BuildPlatform)"
|
|
New-Item -Type Directory $OutDir -EA:Ignore
|
|
Write-Host "Linking $($Symbols.Length) symbols into place at $OutDir"
|
|
ForEach($s in $Symbols) {
|
|
New-Item -Type HardLink -Target $s.FullName (Join-Path $OutDir $s.Name)
|
|
}
|
|
displayName: Stage Unique Symbols (as hard links)
|
|
|
|
- pwsh: |-
|
|
$p = "$(JobOutputDirectory)\"
|
|
|
|
# Calculate hashes for installers
|
|
$userSetupFiles = Get-ChildItem -Path $p -Filter "PowerToysUserSetup*.exe"
|
|
$machineSetupFiles = Get-ChildItem -Path $p -Filter "PowerToysSetup*.exe" | Where-Object { $_.Name -notmatch "PowerToysUserSetup" }
|
|
|
|
if ($userSetupFiles.Count -gt 0) {
|
|
$userHash = ($userSetupFiles[0] | Get-FileHash).Hash;
|
|
$userPlat = "hash_user_$(BuildPlatform).txt";
|
|
$combinedUserPath = $p + $userPlat;
|
|
echo "User: $userHash"
|
|
$userHash | out-file -filepath $combinedUserPath
|
|
}
|
|
|
|
if ($machineSetupFiles.Count -gt 0) {
|
|
$machineHash = ($machineSetupFiles[0] | Get-FileHash).Hash;
|
|
$machinePlat = "hash_machine_$(BuildPlatform).txt";
|
|
$combinedMachinePath = $p + $machinePlat;
|
|
echo "Machine: $machineHash"
|
|
$machineHash | out-file -filepath $combinedMachinePath
|
|
}
|
|
displayName: Calculate file hashes for all installers
|
|
|
|
# Publishing the GPO files
|
|
- pwsh: |-
|
|
$GpoArchive = "$(JobOutputDirectory)\GroupPolicyObjectFiles-$(EffectiveVersionNumber).zip"
|
|
tar -c -v --format=zip -C .\src\gpo\assets -f $GpoArchive *
|
|
displayName: Stage GPO files
|
|
|
|
- ${{ if or(eq(parameters.runTests, true), eq(parameters.buildTests, true)) }}:
|
|
# Running the tests may result in future jobs consuming artifacts out of this build
|
|
# Instead of running an expensive file copy step, move everything over since the build is totally done.
|
|
- pwsh: |-
|
|
# It seems weird, but this is for compatibility. Our artifacts historically contained the folder x64/Release/x64/Release (for example).
|
|
$FinalOutputRoot = "$(JobOutputDirectory)\$(BuildPlatform)\$(BuildConfiguration)\$(BuildPlatform)"
|
|
$ProjectBuildRoot = "$(Build.SourcesDirectory)\$(BuildPlatform)"
|
|
$ProjectBuildDirectory = "$ProjectBuildRoot\$(BuildConfiguration)"
|
|
|
|
New-Item -Type Directory $FinalOutputRoot -EA:Ignore
|
|
Move-Item $ProjectBuildDirectory $FinalOutputRoot
|
|
displayName: Move entire output directory into artifacts
|
|
|
|
- ${{ if eq(parameters.publishArtifacts, true) }}:
|
|
- publish: $(JobOutputDirectory)
|
|
artifact: $(JobOutputArtifactName)
|
|
displayName: Publish all outputs
|
|
condition: succeeded()
|
|
|
|
- publish: $(JobOutputDirectory)
|
|
artifact: $(JobOutputArtifactName)-failure-$(System.JobAttempt)
|
|
displayName: Publish failure logs
|
|
condition: or(failed(), canceled()) |