Skip to content

fix(953): sweep stale Fizzler binding redirects and add a redirect verification gate - #974

Merged
drmoisan merged 15 commits into
mainfrom
bug/stale-fizzler-and-unsafe-binding-redirects-953
Oct 2, 2026
Merged

drmoisan merged 15 commits into
mainfrom
bug/stale-fizzler-and-unsafe-binding-redirects-953

Conversation

@drmoisan

@drmoisan drmoisan commented Oct 2, 2026

Copy link
Copy Markdown
Owner

Suggested title

fix(953): sweep stale Fizzler binding redirects and add a redirect verification gate

Summary

  • Moves the 11 stale Fizzler bindingRedirect entries from 1.3.0.0 to oldVersion="0.0.0.0-1.3.1.0" newVersion="1.3.1.0" across the app.config files, matching the two files that were already correct (SVGControl, UtilitiesCS). Each edit changes one line; CRLF line endings and the UTF-8 BOM are preserved.
  • Adds scripts/dependencies/BindingRedirectVerification.psm1 with ConvertTo-ReferenceVersionMap and Find-StaleBindingRedirect. A redirect newVersion must equal a version that some project file declares in a Reference Include for the same assembly name.
  • Adds tests/scripts/dependencies/BindingRedirectVerification.Tests.ps1 (14 tests). It fails on a new mismatch, on any Fizzler regression, and on a known-debt pair that has been fixed but is still listed.
  • The System.Runtime.CompilerServices.Unsafe half of the issue was delivered earlier (issue 929, PR 949). It is verified here and not edited: all 17 Unsafe redirects remain at 6.0.3.0.
  • The 15 other stale pairs are recorded as known debt and allowed by the ratchet test. Correcting them is out of scope (see Follow-ups).

Why

Package updates advanced deployed assembly versions without a matching sweep of bindingRedirect values (issue 953; the earlier designer failure in issue 418 had the same cause). The review of issue 929 reported that eleven app.config files still redirected Fizzler to 1.3.0.0 while the csproj Reference is 1.3.1.0. Nothing detected this class of drift, so a new redirect mismatch could merge silently.

What Changed

  • Config edits (11 files): QuickFiler, QuickFiler.Test, SVGControl.Test, Tags, TaskMaster, TaskTree, TaskVisualization, TaskVisualization.Test, ToDoModel, ToDoModel.Test, UtilitiesCS.Test. The System.ClientModel redirects that share the same text in six of these files are untouched.
  • New detector module (139 lines) and new Pester file (335 lines, no temporary files).
  • Feature folder under docs/features/active/2026-08-04-stale-fizzler-and-unsafe-binding-redirects-953/: plan, research, evidence, issue acceptance-criteria check-offs, and the reduced-audit artifacts. Four planner agent-memory notes from the preparation passes are committed separately.

Architecture / How It Fits Together

BindingRedirectVerification.psm1 imports PackageGraph.psm1 for parsing and is pure over text. The deployed-version source is an injected scriptblock, so unit tests run on in-memory fixtures. The repository-level tests build the version map from every csproj Reference Include value. Membership is by assembly name across all projects, not per project. An assembly with no csproj Reference anywhere is reported as unverifiable and is not a finding. The ratchet test pins the sorted set of AssemblyName|NewVersion findings (15 pairs) and the sorted unverifiable names (3) and compares the detector's examined count with an independent count of <bindingRedirect elements (1176).

Verification

Completed (local, through the PoshQC tools; evidence under the feature folder):

  • Fail-before: with the tests present and the configs unedited, the suite showed 151 tests and 2 failures (tests 13 and 14; test 13 reported but got 11).
  • Pass-after: 151 tests, 0 failures, 0 errors across 9 suites; the 8 pre-existing suites match their baseline counts.
  • PoshQC format: terminal iteration shows no rewrite (iteration 1 reformatted indentation in the two new files, which was then committed). PoshQC analyze: pass (0 findings); tool reports no count.
  • Each config edit: git diff --numstat reads 1 1, line endings read w/crlf, BOM bytes 239,187,191.
  • Reduced audit (code review, policy audit, feature audit): PASS, 0 blocking findings.

Pester line coverage for scripts/dependencies is not measured locally. It comes from the CI Pester job on this pull request and is reported in the PR conversation, not in this body: Not verified in this PR at the time of writing.

Recommended: review the CI Pester job result and its coverage figure for BindingRedirectVerification.psm1.

Backward Compatibility / Migration Notes

No public API changes and no C# source, project, solution or manifest change. The app.config edits raise the Fizzler redirect upper bound and target from 1.3.0.0 to 1.3.1.0, which is the version the two Fizzler-referencing projects already deploy.

Risks and Mitigations

  • Risk: the new ratchet test fails on future legitimate dependency updates. Mitigation: that is its purpose; its failure message lists each observed pair, so the developer either fixes the redirect or updates the pinned set deliberately.
  • Risk: line-ending or BOM changes to the configs. Mitigation: verified per file (above).
  • Rollback: revert the commit; no data or runtime state is involved.

Review Guide

  1. scripts/dependencies/BindingRedirectVerification.psm1
  2. tests/scripts/dependencies/BindingRedirectVerification.Tests.ps1 (tests 13 and 14 are the repository-level ones)
  3. The 11 one-line app.config diffs (mechanical)
  4. Feature-folder documents and evidence (noisy; skim the audit artifacts first)

Follow-ups

The following are not filed from this branch; the coordinator promotes them.

  • Correct the 15 known-debt redirect pairs (137 redirect entries, all csproj References newer than the config values): Azure.Core, Microsoft.Bcl.Memory, Microsoft.Bcl.Numerics, Microsoft.Extensions.Diagnostics.Abstractions, Microsoft.Identity.Client, Microsoft.Identity.Client.Extensions.Msal, Microsoft.IdentityModel.Abstractions, ...JsonWebTokens, ...Logging, ...Protocols, ...Protocols.OpenIdConnect, ...Tokens, ...Validators, System.IdentityModel.Tokens.Jwt, and System.ClientModel (six configs at 1.3.0.0 against Reference 1.16.0.0). Detail: evidence/other/p2-t16-known-debt-followup.2026-10-02T03-54.md in the feature folder.
  • Three assembly names have redirects but no csproj Reference (System.Linq.AsyncEnumerable, Microsoft.IdentityModel.Clients.ActiveDirectory, netstandard); the detector lists them as unverifiable.
  • Non-blocking review observations: the non-configuration-text test uses a bare Should -Throw; whitespace-only and empty ProjectText inputs are documented but untested; the known-debt test bundles five assertions in one It.

GitHub Auto-close

drmoisan and others added 15 commits October 2, 2026 00:17
…sses

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…direct verification gate

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…or the redirect gate

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…dule

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@drmoisan
drmoisan merged commit 9428736 into main Oct 2, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bug: stale-fizzler-and-unsafe-binding-redirects

1 participant