Skip to content

Move authentication registration to an AOT-safe Abstractions registry - #4821

Draft
paulmedynski wants to merge 1 commit into
dev/paul/aot/phase-1.2from
dev/paul/aot/phase-1.3
Draft

paulmedynski wants to merge 1 commit into
dev/paul/aot/phase-1.2from
dev/paul/aot/phase-1.3

Conversation

@paulmedynski

Copy link
Copy Markdown
Contributor

Description

Move authentication registration/bootstrap into Abstractions and remove the reflective registration bridge to the driver.

  • Delegate public GetProvider/SetProvider directly to the registry and wire driver authentication lookups to the public API.
  • Relocate SqlAuthenticationInitializer, remove its driver/reference declarations and add its forwards together.
  • Preserve configuration/initializer/application/discovered-default precedence, replacement callbacks and traced/cached failure behavior.
  • Add cached default-true switches, separate trimming/AOT capability guards and attribute polyfills.
  • Preserve netstandard2.0 compatibility and add net10.0 AOT analysis.
  • Relocate authentication resources with correct embedding, resilient StringBuilder formatting and fatal-exception classification.
  • Add ordinary xUnit coverage and remove the redundant driver-manager test class. Update public documentation/build guidance.

Layer 3 of 6 in the seven-PR phase-one authentication stack. Exact runtime family-version enforcement is deliberately left to the next layer; existing Azure identity/loading checks are retained.

Issues

No issue is automatically closed by this core relocation layer.

Testing

  • dotnet build build.proj -t:TestAbstractions -p:TestFramework=net10.0 -p:ReferenceType=Project -p:Configuration=Release --verbosity quiet — passed.
  • dotnet test src/Microsoft.Data.SqlClient.Extensions/Abstractions/test/Abstractions.Test.csproj -c Release -f net10.0 -p:ReferenceType=Project --verbosity minimal — passed, 62 tests.
  • dotnet test src/Microsoft.Data.SqlClient/tests/UnitTests/Microsoft.Data.SqlClient.UnitTests.csproj -c Release -f net10.0 -p:ReferenceType=Project --filter 'FullyQualifiedName~TypeForwardTests|FullyQualifiedName~AuthenticationConfigurationSchemaTest|FullyQualifiedName~EnableAppConfigSwitchTest' --verbosity minimal — passed, 15 tests.
  • dotnet build build.proj -t:TestAuthenticationConfiguration -p:ReferenceType=Project -p:Configuration=Release -p:TestFramework=net10.0 --verbosity minimal — passed, current/legacy app.config.
  • env NUGET_PACKAGES=/home/paul/dev/SqlClient/dev/paul/aot/phase-1.3/artifacts/pr3-validation/package-cache dotnet build build.proj -t:TestAuthenticationConfiguration -p:ReferenceType=Package -p:Configuration=Release -p:TestFramework=net10.0 -p:PackageVersionSqlClient=7.1.0-pr3validation539d3dddb --verbosity minimal — passed, isolated production packages and current/legacy app.config.
  • dotnet test src/Microsoft.Data.SqlClient.Extensions/Azure/test/Azure.Test.csproj -c Release -f net10.0 -p:ReferenceType=Project --no-build --filter 'FullyQualifiedName~DefaultAuthProviderTests|FullyQualifiedName~WamBrokerTests' --verbosity minimal — passed, 18 tests.
  • dotnet build build.proj -t:BuildSqlClient -p:ReferenceType=Project -p:Configuration=Release --verbosity minimal — passed, all driver/reference/unsupported TFMs.
  • dotnet build src/Microsoft.Data.SqlClient/tests/UnitTests/Microsoft.Data.SqlClient.UnitTests.csproj -c Release -f net462 -p:ReferenceType=Project --verbosity minimal — passed, cross-build only.
  • dotnet build src/Microsoft.Data.SqlClient.Extensions/Abstractions/test/Abstractions.Test.csproj -c Release -f net462 -p:ReferenceType=Project --verbosity minimal — passed, cross-build only.
  • dotnet publish artifacts/pr3-validation/PublishSmoke/PublishSmoke.csproj -c Release -r linux-x64 -p:ReferenceType=Project -p:PublishMode=trim --self-contained true -o artifacts/pr3-validation/trimmed --verbosity minimal and artifacts/pr3-validation/trimmed/PublishSmoke — passed, temporary publish smoke.
  • dotnet publish artifacts/pr3-validation/PublishSmoke/PublishSmoke.csproj -c Release -r linux-x64 -p:ReferenceType=Project -p:PublishMode=aot -o artifacts/pr3-validation/aot --verbosity minimal and artifacts/pr3-validation/aot/PublishSmoke — passed, temporary publish smoke.
  • git diff --check and git diff --cached --check — passed.

.NET Framework runtime execution was not performed on Linux. An initial smoke command globally set PublishTrimmed=true and failed with NETSDK1124 on netstandard projects; scoping the publish mode to the smoke application corrected it. Dedicated, committed full scenario/publish fixtures and CI arrive in the final layer.

Guidelines

Please review the contribution guidelines before submitting a pull request:

Delegate authentication registration and lookup directly, preserve configuration precedence and Azure discovery, and enable trimmed/NativeAOT registration with cached capability guards. Relocate authentication resources and add ordinary regression tests while retaining the dedicated configuration harness.

Defer exact runtime family-version enforcement and full publish/CI scenarios to subsequent stack layers.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 9, 2026 18:24
@paulmedynski
paulmedynski added this pull request to stack #4822 October 9, 2026 18:25

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Fatal constructor failures can be swallowed, trimming guidance is inaccurate, and the new switch lacks default-value coverage.

3 open findings
What changed in this PR

Relocates authentication registration and initialization into Abstractions, removing the driver reflection bridge while preserving compatibility through type forwarding.

Changes:

  • Adds an AOT-aware provider registry, feature switches, diagnostics, and localized resources.
  • Forwards SqlAuthenticationInitializer and routes driver lookups through the public registry.
  • Expands authentication tests and documentation.
File Description
src/​Microsoft.Data.SqlClient/​tests/​UnitTests/​TypeForwardTests.cs Tests initializer forwarding.
src/​Microsoft.Data.SqlClient/​tests/​UnitTests/​Microsoft/​Data/​SqlClient/​EnableAppConfigSwitchTest.cs Removes relocated configuration test.
src/​Microsoft.Data.SqlClient/​tests/​FunctionalTests/​AADAuthenticationTests.cs Updates registry documentation.
src/​Microsoft.Data.SqlClient/​tests/​AuthenticationTests/​ConfigurationTest/​Program.cs Verifies relocated initialization.
src/​Microsoft.Data.SqlClient/​src/​TypeForwards.Abstractions.cs Forwards initializer type.
src/​Microsoft.Data.SqlClient/​src/​Resources/​Strings.zh-Hant.resx Removes moved authentication strings.
src/​Microsoft.Data.SqlClient/​src/​Resources/​Strings.zh-Hans.resx Removes moved authentication strings.
src/​Microsoft.Data.SqlClient/​src/​Resources/​Strings.tr.resx Removes moved authentication strings.
src/​Microsoft.Data.SqlClient/​src/​Resources/​Strings.ru.resx Removes moved authentication strings.
src/​Microsoft.Data.SqlClient/​src/​Resources/​Strings.resx Removes moved authentication strings.
src/​Microsoft.Data.SqlClient/​src/​Resources/​Strings.pt-BR.resx Removes moved authentication strings.
src/​Microsoft.Data.SqlClient/​src/​Resources/​Strings.pl.resx Removes moved authentication strings.
src/​Microsoft.Data.SqlClient/​src/​Resources/​Strings.ko.resx Removes moved authentication strings.
src/​Microsoft.Data.SqlClient/​src/​Resources/​Strings.ja.resx Removes moved authentication strings.
src/​Microsoft.Data.SqlClient/​src/​Resources/​Strings.it.resx Removes moved authentication strings.
src/​Microsoft.Data.SqlClient/​src/​Resources/​Strings.fr.resx Removes moved authentication strings.
src/​Microsoft.Data.SqlClient/​src/​Resources/​Strings.es.resx Removes moved authentication strings.
src/​Microsoft.Data.SqlClient/​src/​Resources/​Strings.Designer.cs Removes moved resource accessors.
src/​Microsoft.Data.SqlClient/​src/​Resources/​Strings.de.resx Removes moved authentication strings.
src/​Microsoft.Data.SqlClient/​src/​Resources/​Strings.cs.resx Removes moved authentication strings.
src/​Microsoft.Data.SqlClient/​src/​PackageReadme.md Documents registry relocation and AOT behavior.
src/​Microsoft.Data.SqlClient/​src/​Microsoft/​Data/​SqlClient/​SqlUtil.cs Removes relocated exception factories.
src/​Microsoft.Data.SqlClient/​src/​Microsoft/​Data/​SqlClient/​SqlAuthenticationProviderManager.cs Removes driver-owned registry.
src/​Microsoft.Data.SqlClient/​src/​Microsoft/​Data/​SqlClient/​Connection/​SqlConnectionInternal.cs Uses the public provider registry.
src/​Microsoft.Data.SqlClient/​ref/​Microsoft.Data.SqlClient.cs Removes relocated initializer declaration.
src/​Microsoft.Data.SqlClient.Extensions/​Azure/​test/​WamBrokerTests.cs Updates registry references.
src/​Microsoft.Data.SqlClient.Extensions/​Azure/​test/​DefaultAuthProviderTests.cs Updates bootstrap test context.
src/​Microsoft.Data.SqlClient.Extensions/​Abstractions/​test/​SqlAuthenticationProviderTest.cs Tests direct registration without the driver.
src/​Microsoft.Data.SqlClient.Extensions/​Abstractions/​test/​ExceptionHelpersTest.cs Tests fatal-exception classification.
src/​Microsoft.Data.SqlClient.Extensions/​Abstractions/​test/​AzureProviderConstructionTest.cs Moves Azure construction tests.
src/​Microsoft.Data.SqlClient.Extensions/​Abstractions/​test/​AuthenticationStringsTest.cs Tests resilient message formatting.
src/​Microsoft.Data.SqlClient.Extensions/​Abstractions/​test/​AuthenticationRegistryTest.cs Tests registry callbacks and failures.
src/​Microsoft.Data.SqlClient.Extensions/​Abstractions/​test/​AuthenticationFeatureSwitchesTest.cs Tests switch caching.
src/​Microsoft.Data.SqlClient.Extensions/​Abstractions/​src/​TrimmingAttributes.cs Adds netstandard annotation polyfills.
src/​Microsoft.Data.SqlClient.Extensions/​Abstractions/​src/​SqlAuthenticationProviderRegistry.cs Implements registry and bootstrap.
src/​Microsoft.Data.SqlClient.Extensions/​Abstractions/​src/​SqlAuthenticationProvider.Internal.cs Removes the reflection bridge.
src/​Microsoft.Data.SqlClient.Extensions/​Abstractions/​src/​SqlAuthenticationProvider.cs Delegates directly to the registry.
src/​Microsoft.Data.SqlClient.Extensions/​Abstractions/​src/​SqlAuthenticationInitializer.cs Defines the relocated public type.
src/​Microsoft.Data.SqlClient.Extensions/​Abstractions/​src/​Resources/​Strings.zh-Hant.resx Adds localized authentication strings.
src/​Microsoft.Data.SqlClient.Extensions/​Abstractions/​src/​Resources/​Strings.zh-Hans.resx Adds localized authentication strings.
src/​Microsoft.Data.SqlClient.Extensions/​Abstractions/​src/​Resources/​Strings.tr.resx Adds localized authentication strings.
src/​Microsoft.Data.SqlClient.Extensions/​Abstractions/​src/​Resources/​Strings.ru.resx Adds localized authentication strings.
src/​Microsoft.Data.SqlClient.Extensions/​Abstractions/​src/​Resources/​Strings.resx Adds neutral authentication strings.
src/​Microsoft.Data.SqlClient.Extensions/​Abstractions/​src/​Resources/​Strings.pt-BR.resx Adds localized authentication strings.
src/​Microsoft.Data.SqlClient.Extensions/​Abstractions/​src/​Resources/​Strings.pl.resx Adds localized authentication strings.
src/​Microsoft.Data.SqlClient.Extensions/​Abstractions/​src/​Resources/​Strings.ko.resx Adds localized authentication strings.
src/​Microsoft.Data.SqlClient.Extensions/​Abstractions/​src/​Resources/​Strings.ja.resx Adds localized authentication strings.
src/​Microsoft.Data.SqlClient.Extensions/​Abstractions/​src/​Resources/​Strings.it.resx Adds localized authentication strings.
src/​Microsoft.Data.SqlClient.Extensions/​Abstractions/​src/​Resources/​Strings.fr.resx Adds localized authentication strings.
src/​Microsoft.Data.SqlClient.Extensions/​Abstractions/​src/​Resources/​Strings.es.resx Adds localized authentication strings.
src/​Microsoft.Data.SqlClient.Extensions/​Abstractions/​src/​Resources/​Strings.de.resx Adds localized authentication strings.
src/​Microsoft.Data.SqlClient.Extensions/​Abstractions/​src/​Resources/​Strings.cs.resx Adds localized authentication strings.
src/​Microsoft.Data.SqlClient.Extensions/​Abstractions/​src/​PackageReadme.md Documents registration and trimming.
src/​Microsoft.Data.SqlClient.Extensions/​Abstractions/​src/​ExceptionHelpers.cs Classifies recoverable exceptions.
src/​Microsoft.Data.SqlClient.Extensions/​Abstractions/​src/​AuthenticationStrings.cs Implements localized error formatting.
src/​Microsoft.Data.SqlClient.Extensions/​Abstractions/​src/​AuthenticationFeatureSwitches.cs Adds cached authentication switches.
src/​Microsoft.Data.SqlClient.Extensions/​Abstractions/​src/​Abstractions.csproj Adds net10 and AOT analysis.
src/​Microsoft.Data.SqlClient.Extensions/​Abstractions/​doc/​SqlAuthenticationProvider.xml Documents new registry behavior.
BUILDGUIDE.md Documents targets and tests.
.github/​instructions/​features.instructions.md Documents authentication switches.
.github/​instructions/​architecture.instructions.md Records the new ownership model.
Files not reviewed (1)
  • src/Microsoft.Data.SqlClient/src/Resources/Strings.Designer.cs: Generated file

🧠 Review effort: Balanced


💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +292 to +305
catch (Exception ex)
when (ex is
AmbiguousMatchException or
ArgumentException or
BadImageFormatException or
FileLoadException or
FileNotFoundException or
MemberAccessException or
MethodAccessException or
MissingMethodException or
NotSupportedException or
TargetInvocationException or
TypeInitializationException or
TypeLoadException)
Comment on lines +20 to +26
/// <summary>Changing AppContext after first access must not change the switch or its guard.</summary>
[Theory]
[InlineData("EnableAppConfig", "s_enableAppConfig", true)]
[InlineData("EnableAppConfig", "s_enableAppConfig", false)]
[InlineData("EnableAzureExtensionDiscovery", "s_enableAzureExtensionDiscovery", true)]
[InlineData("EnableAzureExtensionDiscovery", "s_enableAzureExtensionDiscovery", false)]
public void SwitchRetainsFirstValue(string propertyName, string fieldName, bool initialValue)
Comment on lines +45 to +49
Set switches before first registry access. On .NET 10 trimmed and NativeAOT publishes, both
reflective paths are removed automatically. Explicitly construct and register a provider for
each required authentication method before opening connections. The Azure provider is supplied
by `Microsoft.Data.SqlClient.Extensions.Azure`. Publish-time overrides use
`RuntimeHostConfigurationOption` with `Trim="true"`; runtime changes cannot affect trimming.
@codecov

codecov Bot commented Oct 9, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
⚠️ Please upload report for BASE (dev/paul/aot/phase-1.2@539d3dd). Learn more about missing BASE report.

Additional details and impacted files
@@                    Coverage Diff                    @@
##             dev/paul/aot/phase-1.2    #4821   +/-   ##
=========================================================
  Coverage                          ?   64.91%           
=========================================================
  Files                             ?      285           
  Lines                             ?    68290           
  Branches                          ?        0           
=========================================================
  Hits                              ?    44331           
  Misses                            ?    23959           
  Partials                          ?        0           
Flag Coverage Δ
PR-SqlClient-Project 64.91% <100.00%> (?)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: To triage

Development

Successfully merging this pull request may close these issues.

2 participants