Skip to content

fix(936): repoint stale analyzer paths and stop the CI package cache from masking them - #937

Merged
drmoisan merged 1 commit into
mainfrom
bug/stale-analyzer-include-paths
Sep 29, 2026
Merged

drmoisan merged 1 commit into
mainfrom
bug/stale-analyzer-include-paths

Conversation

@drmoisan

Copy link
Copy Markdown
Owner

Suggested title

fix(936): repoint stale analyzer paths and stop the CI package cache from masking them

Summary

  • main fails to compile after a clean package restore (CS0006 in 17 projects). This PR fixes it.
  • Every <Analyzer Include> path now points at the versions declared in packages.config: Meziantou.Analyzer 3.0.290 (was 3.0.235) and MSTest.Analyzers 4.4.1 (was 4.4.0).
  • The restore-keys fallback is removed from the packages/ cache in _build-analyzers.yml, _build-nullable.yml and _mstest-coverage.yml. That fallback is why CI stayed green while clean builds failed.

Why

  • The Dependabot grouped update raised the package versions in every packages.config but left the analyzer paths in the project files on the old version folders.
  • A clean restore creates only the new folders, so the compiler cannot find the analyzer DLLs. This is the same class of defect as Bug: Bug: Meziantou.Analyzer HintPath skew masked by CI cache restore-keys fallback #898.
  • CI restored an older packages/ cache through the prefix fallback. That older cache still contained the superseded folders, so every required check passed against package folders a clean checkout does not have.

What Changed

Project files

  • 17 .csproj files: Meziantou.Analyzer.3.0.235\ becomes 3.0.290\, and MSTest.Analyzers.4.4.0\ becomes 4.4.1\.
  • Only the <Analyzer Include> path lines change: 34 lines in total.

CI

  • restore-keys is removed from the three packages/ cache steps, and the comment that described the fallback as safe is replaced with the reason it is not.
  • _format-check.yml caches only the dotnet tools directory, so it is unchanged.

Docs

Architecture / How It Fits Together

nuget restore materializes packages/{id}.{version}/ from each packages.config. Analyzer DLLs reach the compiler through <Analyzer Include> paths in each project file. Those paths must name the same version folder that restore creates.

Verification

Completed, on a fresh detached worktree at main with an empty packages/ folder:

  • Before the fix, msbuild /t:Rebuild failed with CS0006 for both analyzer packages.
  • After the fix:
    • msbuild TaskMaster.sln /t:Rebuild /m /p:Configuration=Debug "/p:Platform=Any CPU" /p:TreatWarningsAsErrors=true exits 0.
    • msbuild TaskMaster.sln /t:Rebuild /m /p:Configuration=Debug "/p:Platform=Any CPU" /p:EnableNETAnalyzers=true /p:EnforceCodeStyleInBuild=true exits 0.
  • actionlint on the three workflows exits 0.
  • dotnet tool run csharpier check . exits 0.
  • A scan of every ..\packages\<dir>\ reference against the clean restore finds no missing folder other than the Exists()-guarded altcover.8.6.45 import, which Bug: package-manifest-consistency-residuals #929 tracks.

Not verified in this PR

  • The MSTest coverage suite was not run locally. CI's required mstest-coverage check runs it on this PR.

Recommended

  • From an empty packages/ folder, run msbuild TaskMaster.sln /t:Restore /p:RestorePackagesConfig=true, then the rebuild above.

Backward Compatibility / Migration Notes

  • There is no code or API change.
  • Local checkouts that still hold the old version folders keep building.

Risks and Mitigations

Slower CI on a cache miss. A packages.config change now restores from scratch.

  • This is intended: it is the only way CI builds what the manifests declare.

The existing exact-key cache still holds superseded folders.

  • They are unreferenced after this fix, and the next packages.config change produces a new key.

Rollback: revert this commit.

Review Guide

  1. Review the three workflow diffs.
  2. Skim the .csproj diffs. They are the same mechanical two-string substitution across 17 files.

Follow-ups

GitHub Auto-close

🤖 Generated with Claude Code

…from masking them

Dependabot PR #921 bumped Meziantou.Analyzer to 3.0.290 and MSTest.Analyzers
to 4.4.1 in every packages.config but left the <Analyzer Include> paths on
3.0.235 and 4.4.0. A clean restore creates only the new folders, so main
failed to compile with CS0006 in 17 projects.

CI stayed green because the packages/ cache in _build-analyzers.yml,
_build-nullable.yml and _mstest-coverage.yml fell back through restore-keys
to an older cache that still held the superseded folders. The fallback is
removed so a cache miss restores exactly what the manifests declare.

Verified on a fresh worktree with an empty packages/ folder: rebuild with
TreatWarningsAsErrors and the analyzer rebuild both exit 0; actionlint and
CSharpier check exit 0.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@drmoisan
drmoisan merged commit 89e202e into main Sep 29, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant