Unify hosted NuGet routing and XML splice anchors - #597
Mikola Lysenko (mikolalysenko) wants to merge 5 commits into
Conversation
|
bugbot run Generated by Claude Code |
|
[burn-down agent] Labeled Ready for review at
Generated by Claude Code |
|
Review updated for The original refactor decoded The correction normalizes literal XML attribute whitespace before entity decoding and writes decoded tab/LF/CR as numeric references. This preserves both character references and literal-whitespace names without changing existing source markup. Validation: 193 NuGet core tests passed; the new eight-form regression fails on the original PR head and passes with the fix. Eight real offline .NET 8.0.129 restores passed against a local feed. Independent review also passed 18 XML identity cases and separate NuGet controls. The fixed commit merges cleanly with current main. No remaining code finding from this review. The Ready label has been restored after all checks completed on the corrected commit. |
|
bugbot run |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 8fa9750. Configure here.
Final-head CI is complete: 482 successful checks, 6 skipped; no failures or pending checks. Bugbot passed, there are no unresolved review threads, and the PR is mergeable.
Hosted NuGet rewrites previously interpreted
nuget.configwith private regexes while restore and VEX used the shared XML reader. Commented-out sources could suppress the nuget.org fallback, and inert sections could receive the inserted Socket source or mapping. The CLI could then report a redirect that NuGet could not consume.Fixes #561 and #585 by using the existing bounded NuGet XML reader for routing data and live insertion spans. This completes the hosted portion of #594 discussed in architecture discussion #560.
The shared model identifies comments, CDATA, processing instructions, quoted attributes, directly scoped sections, and insertion points after the last direct
<clear>child. One insertion helper handles normal and self-closing sections. Malformed or ambiguous layouts refuse the redirect before any config edit, redirect claim, or lock re-pin.Source names retain their XML identity when copied into fallback mappings. The reader normalizes literal CRLF and attribute whitespace before decoding character references; the writer escapes decoded tab, newline, and carriage return as numeric references. Thus
corp	feedremains a tab-bearing name, while a literal attribute tab remains a space as NuGet interprets it. Original source markup stays byte-for-byte intact.Validation:
8fa9750c.Note
Medium Risk
Changes core hosted NuGet redirect and lock re-pin behavior on real
nuget.configinput; mistakes could cause NU1100/NU1403 or false redirect claims, though fail-closed validation and broad tests reduce exposure.Overview
Hosted NuGet redirects no longer splice
nuget.configwith private regexes while restore/VEX use the shared tokenizer. The NuGet reader now records live byte spans forconfiguration,packageSources, andpackageSourceMapping(including insert points after the last direct<clear>), flags repeated sections, and normalizes literal attribute whitespace before entity decode so source keys match NuGet’s identity rules.add_nuget_sourcetakes the parsed model, inserts sources/mappings only at those spans (expanding self-closing sections in place), re-parses after source edits, and encodes keys when writing fallback*mappings. Malformed or ambiguous layouts emitredirect_nuget_config_unwritableand skip config edits and lock re-pinning even if a Socket source already appears.Regression coverage includes commented inactive sources/mappings (e2e #561/#585), refusal to edit inside comments/CDATA/PIs, attribute-whitespace identity, and expanded empty mapping blocks.
Reviewed by Cursor Bugbot for commit 8fa9750. Configure here.