Add CS8618 suppressor for required MSBuild task properties - #13926
Conversation
Add a Roslyn suppressor for CS8618 on required MSBuild task properties, extend the analyzer tests to validate suppressed compiler diagnostics, and rename the analyzer projects from ThreadSafeTaskAnalyzer to TaskAnalyzer to match the package scope. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
Pull request overview
This PR evolves the MSBuild task authoring analyzer package by adding a Roslyn suppressor to remove noisy CS8618 warnings for [Microsoft.Build.Framework.Required] task properties (which MSBuild initializes), while also renaming the analyzer/test projects from ThreadSafeTaskAnalyzer* to the broader TaskAnalyzer* and updating references/docs accordingly.
Changes:
- Added
RequiredTaskPropertyInitializationSuppressorto suppressCS8618on[Required]properties forITaskimplementations. - Expanded analyzer infrastructure (shared helpers + transitive call-chain analyzer) and extended test helpers to assert suppressed compiler diagnostics.
- Renamed analyzer projects and updated solution/CI/docs to reference
TaskAnalyzer.
Reviewed changes
Copilot reviewed 11 out of 24 changed files in this pull request and generated 2 comments.
Show a summary per file
| File | Description |
|---|---|
| src/Tasks/Microsoft.Build.Tasks.csproj | Switches analyzer ProjectReference to TaskAnalyzer. |
| src/TaskAnalyzer/WellKnownTypeNames.cs | Adds metadata name constant for MSBuild RequiredAttribute. |
| src/TaskAnalyzer/TransitiveCallChainAnalyzer.cs | Adds compilation-wide call graph analyzer for transitive unsafe API usage (MSBuildTask0005). |
| src/TaskAnalyzer/TaskAnalyzer.csproj | Updates InternalsVisibleTo to renamed test assembly. |
| src/TaskAnalyzer/SharedAnalyzerHelpers.cs | Adds shared helper utilities for banned API and path-safety analysis. |
| src/TaskAnalyzer/RequiredTaskPropertyInitializationSuppressor.cs | Introduces CS8618 suppressor for [Required] task properties. |
| src/TaskAnalyzer/README.md | Documents suppressor behavior and updates paths/names for renamed projects. |
| src/TaskAnalyzer/MultiThreadableTaskCodeFixProvider.cs | Adds/updates code fixes for MSBuildTask0002/0003 diagnostics. |
| src/TaskAnalyzer/MultiThreadableTaskAnalyzer.cs | Adds/updates main analyzer logic and scope option handling. |
| src/TaskAnalyzer/DiagnosticIds.cs | Defines MSBuildTask0001–0005 IDs. |
| src/TaskAnalyzer/DiagnosticDescriptors.cs | Defines descriptors/severities, including compilation-end rule for transitive diagnostics. |
| src/TaskAnalyzer/BannedApiDefinitions.cs | Declares banned API list + categories for analyzer lookups. |
| src/TaskAnalyzer/AnalyzerReleases.Unshipped.md | Adds unshipped analyzer rule list (0001–0005). |
| src/TaskAnalyzer/AnalyzerReleases.Shipped.md | Initializes shipped file (none shipped yet). |
| src/TaskAnalyzer.Tests/WriteAllTextDetailedTest.cs | Adds a focused diagnostic-count regression test. |
| src/TaskAnalyzer.Tests/TransitiveCallChainAnalyzerTests.cs | Adds tests for transitive call-chain diagnostics and message formatting. |
| src/TaskAnalyzer.Tests/TestHelpers.cs | Extends test harness to return suppressed diagnostics and improves framework stubs. |
| src/TaskAnalyzer.Tests/TaskAnalyzer.Tests.csproj | Updates project reference to renamed analyzer project. |
| src/TaskAnalyzer.Tests/RequiredTaskPropertyInitializationSuppressorTests.cs | Adds test coverage for CS8618 suppression scenarios and negative cases. |
| src/TaskAnalyzer.Tests/MultiThreadableTaskCodeFixProviderTests.cs | Adds code fix tests for TaskEnvironment/path fixes. |
| src/TaskAnalyzer.Tests/MultiThreadableTaskAnalyzerTests.cs | Adds extensive analyzer behavior coverage including scope option cases. |
| MSBuild.slnx | Updates solution entries to TaskAnalyzer projects. |
| eng/dependabot/Directory.Packages.props | Updates comment to reflect renamed analyzer project usage. |
| .vsts-dotnet-ci.yml | Updates CI comment to reference TaskAnalyzer. |
Remove the unused suppressor using directive and narrow CS8618 suppression to required task properties that MSBuild can actually assign, with test coverage for get-only properties. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
|
@AArnott note that the current task analyzer package is non-shipping, it doesn't go to nuget.org is currently only meant for internal consumption. We want to eventually ship it but it's not yet clear when and in which form (separate package vs analyzer moved into Microsoft.Build.Framework package). |
|
@ViktorHofer That is indeed relevant. I guess the question for now is, do you want to take this PR as-is toward that final outcome, or do you want changes made first? I'm OK if this doesn't ship immediately. |
|
I'm super happy to take this and dogfood it on the MSBuild repo - I would like us to decide when the ship bar for the analyzers package is soon though. cc @jankratochvilcz |
|
Agreed: this is the type of thing I want in the analyzer whenever it ships and there's no reason to not dogfood it here (and in SDK) ASAP. |
|
+1 |
JanProvaznik
left a comment
There was a problem hiding this comment.
the functionality addition is welcome, thanks. We'll need to think about the final naming before release I don't like "TaskAnalyzer", "MSBuildAnalyzer" would be more appropriate I think, but I'll not bikeshed that here, but when we actually want to release it.
Updated [Microsoft.Build.Utilities.Core](https://github.com/dotnet/msbuild) from 18.8.2 to 18.9.6. <details> <summary>Release notes</summary> _Sourced from [Microsoft.Build.Utilities.Core's releases](https://github.com/dotnet/msbuild/releases)._ ## 18.9.6 ## What's Changed * [vs18.6] Update dependencies from dotnet/arcade by @dotnet-maestro[bot] in dotnet/msbuild#13793 * [vs18.0] Update dependencies from dotnet/arcade by @dotnet-maestro[bot] in dotnet/msbuild#13859 * [vs18.6] Update dependencies from dotnet/arcade by @dotnet-maestro[bot] in dotnet/msbuild#13858 * [vs18.7] Update dependencies from dotnet/arcade by @dotnet-maestro[bot] in dotnet/msbuild#13863 * CsWin32 follow-up: CLR metadata + TypeLib interop migration by @JeremyKuhne in dotnet/msbuild#13853 * Update vmr-sb-validation.yml for Azure Pipelines by @meghnave in dotnet/msbuild#13871 * Test: keep shell alive 15s in ToolTaskCanChangeCanonicalErrorFormat (#13734) by @jankratochvilcz in dotnet/msbuild#13878 * Add vs18.8 to merge-flow config by @OvesN in dotnet/msbuild#13877 * Stable branding for 18.8 release by @OvesN in dotnet/msbuild#13883 * Bump main to 18.9.0 after vs18.8 snap by @OvesN in dotnet/msbuild#13880 * Avoid checkout in insertion pipeline by @rainersigwald in dotnet/msbuild#13887 * Report actual launch path in MSB4216 for Runtime="NET" task host by @ViktorHofer in dotnet/msbuild#13889 * Migrate Tlblmp and AxImp to Multithreaded Execution by @AlesProkop in dotnet/msbuild#13708 * Replace ErrorUtilities assertion methods with Assumed API and BCL throw helpers by @DustinCampbell in dotnet/msbuild#13790 * Fix CLR_E_SHIM_RUNTIMELOAD in RAR's IMetaDataDispenser activation by @JeremyKuhne in dotnet/msbuild#13899 * [main] Update dependencies from nuget/nuget.client by @dotnet-maestro[bot] in dotnet/msbuild#13905 * [main] Update dependencies from dotnet/arcade by @dotnet-maestro[bot] in dotnet/msbuild#13907 * [main] Update dependencies from dotnet/roslyn by @dotnet-maestro[bot] in dotnet/msbuild#13910 * [vs17.14] Update dependencies from dotnet/arcade by @dotnet-maestro[bot] in dotnet/msbuild#13908 * [vs18.0] Update dependencies from dotnet/arcade by @dotnet-maestro[bot] in dotnet/msbuild#13906 * Fix ToolTask output loss: increase EOF pipe timeout from 2s to 30s by @huulinhnguyen-dev in dotnet/msbuild#13767 * Improve symlink cycle condition by @GangWang01 in dotnet/msbuild#13901 * [vs18.6] Update dependencies from dotnet/arcade by @dotnet-maestro[bot] in dotnet/msbuild#13904 * Add flaky-test detection and auto-fix agentic workflows by @ViktorHofer in dotnet/msbuild#13915 * Quote --ignore-exit-code values so the quarantine pipeline does not shell-split on Unix by @ViktorHofer in dotnet/msbuild#13918 * Fix flaky-test detector PR-evidence loss and raise scan limits by @ViktorHofer in dotnet/msbuild#13919 * Tighten the pr review agent by @JanKrivanek in dotnet/msbuild#13921 * Add environment variables for governance detection by @ViktorHofer in dotnet/msbuild#13920 * Change IsPackable to true and add IsShipping flag by @ViktorHofer in dotnet/msbuild#13924 * [vs18.7] Update dependencies from dotnet/arcade by @dotnet-maestro[bot] in dotnet/msbuild#13911 * Make flaky detector verify recurrence postdates the fix before commenting by @ViktorHofer in dotnet/msbuild#13930 * Fix AbsolutePath.GetCanonicalForm process state leak on Windows by @OvesN in dotnet/msbuild#13788 * Fix flaky detector: unblock dnceng feed, fail fast, and defer quarantine to a second run by @ViktorHofer in dotnet/msbuild#13936 * Update documentation for ImplicitUsings element by @drewnoakes in dotnet/msbuild#13900 * [vs18.6] Point OptProf bootstrapper at rel/stable instead of int.main by @AlesProkop in dotnet/msbuild#13923 * Add CS8618 suppressor for required MSBuild task properties by @AArnott in dotnet/msbuild#13926 * Tighten NodeLaunchData.EnvironmentOverrides nullability to IDictionary<string, string?>? by @OvesN with @Copilot in dotnet/msbuild#13815 * Fix ToolTask EOF wait to be STA-safe via CountdownEvent (MSB4018 in AspNetCompiler) by @YuliiaKovalova in dotnet/msbuild#13917 * [automated] Merge branch 'vs18.6' => 'vs18.7' by @github-actions[bot] in dotnet/msbuild#13941 * Localized file check-in by OneLocBuild Task: Build definition ID 9434: Build ID 14192258 by @dotnet-bot in dotnet/msbuild#13849 * Bumping to 10.0.8 runtime packages by @OvesN in dotnet/msbuild#13898 * Flaky-test workflow: reassure on empty PR list + drop local reproduction (quarantine-first) by @ViktorHofer in dotnet/msbuild#13938 * [Flaky Test] Un-quarantine 5 consistently-green tests by @github-actions[bot] in dotnet/msbuild#13952 * Flaky-test detector: open PRs ready-for-review; drop newly-filed-issues section from PR body by @ViktorHofer in dotnet/msbuild#13958 * [Flaky Test] Quarantine 4 flaky tests by @github-actions[bot] in dotnet/msbuild#13937 * Flaky-test: fix duplicate-issue bug by switching dedup key to a visible code-block key by @ViktorHofer in dotnet/msbuild#13963 * CsWin32 follow-up: WindowsNative + VS Setup Configuration + remaining hand-rolled interop by @JeremyKuhne in dotnet/msbuild#13872 * Add the reviewer release skill checking if the Learn article Change waves is updated by @GangWang01 in dotnet/msbuild#13840 * [main] Source code updates from dotnet/dotnet by @dotnet-maestro[bot] in dotnet/msbuild#13977 ... (truncated) Commits viewable in [compare view](dotnet/msbuild@v18.8.2...v18.9.6). </details> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Context
MSBuild task authors can mark required inputs with
[Required], and MSBuild guarantees those properties are populated before task execution. The C# compiler still reportsCS8618for these members, which forces task authors to add repetitive= null!;initializers that do not reflect how tasks are actually initialized.This analyzer package has also grown beyond just thread-safe task checks, so the old
ThreadSafeTaskAnalyzerproject names were narrower than the current scope.Changes Made
CS8618for properties marked withMicrosoft.Build.Framework.RequiredAttributeon types implementingMicrosoft.Build.Framework.ITask.ITaskimplementations, explicit constructor cases, and negative cases likeSystem.ComponentModel.DataAnnotations.RequiredAttribute.ThreadSafeTaskAnalyzer/ThreadSafeTaskAnalyzer.TeststoTaskAnalyzer/TaskAnalyzer.Tests, and updated the solution, project references, docs, and CI comments to match.Testing
dotnet test src\TaskAnalyzer.Tests\TaskAnalyzer.Tests.csproj -c Release -f net10.0dotnet build src\TaskAnalyzer\TaskAnalyzer.csproj -c Release./build.cmd -v quiet, but it was blocked in this environment while downloadingvswhere.Notes
The suppressor is intentionally scoped to MSBuild's
RequiredAttribute; it does not suppressCS8618for otherRequiredAttributetypes.