fix(953): sweep stale Fizzler binding redirects and add a redirect verification gate - #974
Merged
drmoisan merged 15 commits intoOct 2, 2026
Merged
Conversation
…sses Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…direct verification gate Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…or the redirect gate Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…dule Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
1 of 5 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Suggested title
fix(953): sweep stale Fizzler binding redirects and add a redirect verification gate
Summary
bindingRedirectentries from1.3.0.0tooldVersion="0.0.0.0-1.3.1.0" newVersion="1.3.1.0"across theapp.configfiles, matching the two files that were already correct (SVGControl,UtilitiesCS). Each edit changes one line; CRLF line endings and the UTF-8 BOM are preserved.scripts/dependencies/BindingRedirectVerification.psm1withConvertTo-ReferenceVersionMapandFind-StaleBindingRedirect. A redirectnewVersionmust equal a version that some project file declares in aReference Includefor the same assembly name.tests/scripts/dependencies/BindingRedirectVerification.Tests.ps1(14 tests). It fails on a new mismatch, on any Fizzler regression, and on a known-debt pair that has been fixed but is still listed.System.Runtime.CompilerServices.Unsafehalf of the issue was delivered earlier (issue 929, PR 949). It is verified here and not edited: all 17 Unsafe redirects remain at6.0.3.0.Why
Package updates advanced deployed assembly versions without a matching sweep of
bindingRedirectvalues (issue 953; the earlier designer failure in issue 418 had the same cause). The review of issue 929 reported that elevenapp.configfiles still redirected Fizzler to1.3.0.0while the csprojReferenceis1.3.1.0. Nothing detected this class of drift, so a new redirect mismatch could merge silently.What Changed
QuickFiler,QuickFiler.Test,SVGControl.Test,Tags,TaskMaster,TaskTree,TaskVisualization,TaskVisualization.Test,ToDoModel,ToDoModel.Test,UtilitiesCS.Test. TheSystem.ClientModelredirects that share the same text in six of these files are untouched.docs/features/active/2026-08-04-stale-fizzler-and-unsafe-binding-redirects-953/: plan, research, evidence, issue acceptance-criteria check-offs, and the reduced-audit artifacts. Four planner agent-memory notes from the preparation passes are committed separately.Architecture / How It Fits Together
BindingRedirectVerification.psm1importsPackageGraph.psm1for parsing and is pure over text. The deployed-version source is an injected scriptblock, so unit tests run on in-memory fixtures. The repository-level tests build the version map from every csprojReference Includevalue. Membership is by assembly name across all projects, not per project. An assembly with no csproj Reference anywhere is reported as unverifiable and is not a finding. The ratchet test pins the sorted set ofAssemblyName|NewVersionfindings (15 pairs) and the sorted unverifiable names (3) and compares the detector's examined count with an independent count of<bindingRedirectelements (1176).Verification
Completed (local, through the PoshQC tools; evidence under the feature folder):
but got 11).git diff --numstatreads1 1, line endings readw/crlf, BOM bytes239,187,191.Pester line coverage for
scripts/dependenciesis not measured locally. It comes from the CI Pester job on this pull request and is reported in the PR conversation, not in this body: Not verified in this PR at the time of writing.Recommended: review the CI Pester job result and its coverage figure for
BindingRedirectVerification.psm1.Backward Compatibility / Migration Notes
No public API changes and no C# source, project, solution or manifest change. The
app.configedits raise the Fizzler redirect upper bound and target from1.3.0.0to1.3.1.0, which is the version the two Fizzler-referencing projects already deploy.Risks and Mitigations
Review Guide
scripts/dependencies/BindingRedirectVerification.psm1tests/scripts/dependencies/BindingRedirectVerification.Tests.ps1(tests 13 and 14 are the repository-level ones)app.configdiffs (mechanical)Follow-ups
The following are not filed from this branch; the coordinator promotes them.
Azure.Core,Microsoft.Bcl.Memory,Microsoft.Bcl.Numerics,Microsoft.Extensions.Diagnostics.Abstractions,Microsoft.Identity.Client,Microsoft.Identity.Client.Extensions.Msal,Microsoft.IdentityModel.Abstractions,...JsonWebTokens,...Logging,...Protocols,...Protocols.OpenIdConnect,...Tokens,...Validators,System.IdentityModel.Tokens.Jwt, andSystem.ClientModel(six configs at1.3.0.0against Reference1.16.0.0). Detail:evidence/other/p2-t16-known-debt-followup.2026-10-02T03-54.mdin the feature folder.System.Linq.AsyncEnumerable,Microsoft.IdentityModel.Clients.ActiveDirectory,netstandard); the detector lists them as unverifiable.Should -Throw; whitespace-only and emptyProjectTextinputs are documented but untested; the known-debt test bundles five assertions in oneIt.GitHub Auto-close