Null-guard feedKeys/feedOverrides in SetupTargetFeedConfigV3 (fixes NRE on keyless Entra publish)#17188
Open
missymessa wants to merge 1 commit into
Open
Null-guard feedKeys/feedOverrides in SetupTargetFeedConfigV3 (fixes NRE on keyless Entra publish)#17188missymessa wants to merge 1 commit into
missymessa wants to merge 1 commit into
Conversation
…RE on keyless Entra publish)
Contributor
There was a problem hiding this comment.
Pull request overview
This PR fixes a null-reference crash in the Microsoft.DotNet.Build.Tasks.Feed publishing task by making SetupTargetFeedConfigV3 tolerate null feedKeys/feedOverrides inputs (which can occur when the corresponding MSBuild ItemGroup is empty), aligning its behavior with SetupTargetFeedConfigV4 for keyless Entra/WIF publishing scenarios.
Changes:
- Null-guard
feedKeysandfeedOverridesbefore converting them to immutable dictionaries inSetupTargetFeedConfigV3. - Add explanatory comments documenting why these parameters can be null in MSBuild task binding.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Comment on lines
+74
to
+77
| // feedKeys/feedOverrides may be null when the corresponding MSBuild ItemGroup is empty | ||
| // (e.g. when publishing with Entra/WIF auth and no feed key is supplied). | ||
| FeedKeys = (feedKeys ?? Array.Empty<ITaskItem>()).ToImmutableDictionary(i => i.ItemSpec, i => i.GetMetadata("Key")); | ||
| FeedOverrides = (feedOverrides ?? Array.Empty<ITaskItem>()).ToImmutableDictionary(i => i.ItemSpec, i => i.GetMetadata("Replacement")); |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Null-guard
feedKeys/feedOverridesinSetupTargetFeedConfigV3SetupTargetFeedConfigV4already guards these parameters against null, butSetupTargetFeedConfigV3does not. When Build Promotion publishes with Entra/WIF auth and no feed key, theFeedKeyMSBuild item is empty, so the task'sFeedKeysparameter arrives null and.ToImmutableDictionary()throws before auth runs:This change makes V3 match V4: a null
feedKeys/feedOverridesyields an empty dictionary and the publisher falls back to Entra auth as intended. It does not change any current publishing behavior on its own — the key-based path is unaffected.Why now
Keyless Build Promotion (#17185) hit this exact crash in production (roslyn 3030919, dnceng-shared 3030947) and was reverted by #17186. This is the task-level fix that makes keyless safe.
Rollout
This is step 2 of the durable rollout:
global.jsonbump flows it into Build Promotion.publish.yml(follow-up PR) once the fixed task is live.