Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Enable TSA tools #47876

Merged
merged 1 commit into from
Mar 26, 2025
Merged

Enable TSA tools #47876

merged 1 commit into from
Mar 26, 2025

Conversation

ericstj
Copy link
Member

@ericstj ericstj commented Mar 25, 2025

@mmitche @ViktorHofer @MichaelSimons

Looks like source-build pipelines still aren't running these. Will try to enable.

@Copilot Copilot bot review requested due to automatic review settings March 25, 2025 19:14
@ericstj ericstj requested review from a team as code owners March 25, 2025 19:14
@dotnet-issue-labeler dotnet-issue-labeler bot added Area-Infrastructure untriaged Request triage from a team member labels Mar 25, 2025
Copy link
Contributor

@Copilot Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR enables additional TSA-related tooling in the source-build pipelines to ensure enhanced analysis is performed during builds.

  • Enabled binskim analysis
  • Enabled policheck verification
  • Enabled TSA tooling

@ericstj
Copy link
Member Author

ericstj commented Mar 25, 2025

Let me know if we should port this over to dotnet/dotnet internally and do a build to make sure things work.

@MichaelSimons
Copy link
Member

Let me know if we should port this over to dotnet/dotnet internally and do a build to make sure things work.

To test this, I would recommend porting these changes to the VMR and pushing your branch to dnceng and then queuing the UB pipeline.

@ericstj
Copy link
Member Author

ericstj commented Mar 25, 2025

@MichaelSimons
Copy link
Member

Should we do the same for source-build and source-build-lite?

It should only be necessary to do source-build-lite. I don't see the value in running across the entire matrix.

@ericstj
Copy link
Member Author

ericstj commented Mar 26, 2025

It should only be necessary to do source-build-lite. I don't see the value in running across the entire matrix.

Done - https://dev.azure.com/dnceng/internal/_build/results?buildId=2672444&view=results

The first build passed most relevant stages, there was an unrelated failure in Pass2 build for one architecture, oddly others passed @ViktorHofer - https://dev.azure.com/dnceng/internal/_build/results?buildId=2671857&view=logs&j=287a7939-eab3-5c36-8f0e-00afcd687924&t=4fb25e12-6d48-5139-7a32-8d5e685a65d1&l=109

    D:\a\_work\1\s\artifacts\source-built-sdks\Microsoft.DotNet.Arcade.Sdk\tools\Build.proj(146,5): error : No projects were found to build. Either the 'Projects' property or 'ProjectToBuild' item group must be specified.
##[error]artifacts\source-built-sdks\Microsoft.DotNet.Arcade.Sdk\tools\Build.proj(146,5): error : No projects were found to build. Either the 'Projects' property or 'ProjectToBuild' item group must be specified.

Looks to me like the tools are running -- however I don't think they are doing so to the full extent.

For example - binskim is only seeing 3 files -
https://dev.azure.com/dnceng/internal/_build/results?buildId=2671857&view=logs&j=9050e078-31bf-5111-d8ec-8b6fa95caf9c&t=13fed60c-a588-5d3e-9328-82bd431be2c4&l=78
Likely due to the size-on-disk savings techniques used by UB to delete intermediates. Do we need to do this for final outputs?

I don't see Policheck running but I don't see that for runtime either. Going to see if I can find evidence of it running elsewhere.

@ViktorHofer
Copy link
Member

ViktorHofer commented Mar 26, 2025

Likely due to the size-on-disk savings techniques used by UB to delete intermediates

dotnet/source-build#4901 - Ideally we wouldn't need to use --clean-while-building in CI but if we must (because of CI disk space limitations) we need to come up with the list of intermediates that should be preserved.

@ViktorHofer
Copy link
Member

##[error]artifacts\source-built-sdks\Microsoft.DotNet.Arcade.Sdk\tools\Build.proj(146,5): error : No projects were found to build. Either the 'Projects' property or 'ProjectToBuild' item group must be specified.

I think @wtgodbe fixed this recently.

@ericstj ericstj enabled auto-merge (squash) March 26, 2025 16:54
@ericstj ericstj merged commit 80b6017 into main Mar 26, 2025
38 of 41 checks passed
@ericstj ericstj deleted the ericstj-tsa-tools branch March 26, 2025 16:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Area-Infrastructure untriaged Request triage from a team member
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants