Skip to content

[Change Safety] Fix forwarding in read-modify-write cmdlets - #30211

Merged
Yabo Hu (VeryEarly) merged 13 commits into
Azure:mainfrom
YangAn-microsoft:fix/change-safety-read-parameter-forwarding
Sep 29, 2026
Merged

Yabo Hu (VeryEarly) merged 13 commits into
Azure:mainfrom
YangAn-microsoft:fix/change-safety-read-parameter-forwarding

Conversation

@YangAn-microsoft

@YangAn-microsoft YangAn-microsoft commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Summary

This PR fixes two Change Safety parameter-forwarding issues in custom cmdlets that read a resource before writing it.

Issue 1: write-only parameters were forwarded to the preliminary GET

A custom update/remove cmdlet receives Change Safety parameters dynamically. The wrapper previously splatted the same $PSBoundParameters dictionary into both its preliminary GET and its final write.

Simple example:

Set-AzEventHub ... -ChangeReference <change-id>
  -> Get-AzEventHub ... -ChangeReference <change-id>   # GET does not support this parameter
  -> parameter binding fails; the write is never reached

The fix builds $readParameters from the exact GET command's metadata and uses it only for the preliminary read. The original $PSBoundParameters dictionary is preserved for the write, so current and future write-only dynamic parameters continue to flow without hard-coded parameter names.

Set-AzEventHub ... -ChangeReference <change-id>
  -> Get-AzEventHub ...                               # read parameters only
  -> private write ... -ChangeReference <change-id>   # original write parameters

This pattern is applied to 11 EventHub, 11 Service Bus, 4 Network Security Perimeter, and 4 CDN wrappers.

Issue 2: GeoDR identity paths dropped parameters before the write

The EventHub and Service Bus GeoDR BreakViaIdentity and FailViaIdentity paths rebuild EnvPSBoundParameters before invoking a private write command. That reconstructed dictionary contained identity and runtime parameters but omitted Change Safety dynamic parameters.

Simple example:

Set-AzEventHubGeoDRConfigurationFailOver -InputObject <alias> -ChangeReference <change-id>
  -> preliminary GET succeeds
  -> EnvPSBoundParameters is rebuilt
  -> Invoke-AzEventHubFailDisasterRecoveryConfigOver runs without ChangeReference

The fix inspects the exact generated Break/Fail target's dynamic parameter metadata and copies supported, bound dynamic parameters into EnvPSBoundParameters. Explicit identity/path parameters remain excluded because the wrapper supplies them directly. ContainsKey() is used so this works with both hashtables and the real PSBoundParametersDictionary used during cmdlet invocation.

This applies to the EventHub and Service Bus Break/Fail via-identity paths.

Upcoming Release entries document the fix in Az.Cdn, Az.EventHub, Az.Network, and Az.ServiceBus.

Validation

Offline

  • All 36 changed PowerShell files parsed successfully.
  • All four generation metadata files contain valid JSON.
  • git diff --check passed.

Live-test method

The changed modules were generated and built from this branch, and temporary resources were provisioned in Azure. Each tested command was invoked through both its expanded and via-identity parameter sets with:

-ChangeReference '/subscriptions/change-ref'

This is deliberately not a valid Change Safety resource ID. The expected safe result is InvalidPolicyTokenRequest during policy-token acquisition.

Reaching that error proves both sides of the forwarding flow:

  1. The preliminary GET did not receive the write-only parameter and successfully found the resource.
  2. The final write did receive ChangeReference and attempted Change Safety token acquisition.
  3. The invalid reference stopped execution before the destructive request.

The harness also verified that the target resource remained present after every invocation. Generated commands can emit this as a non-terminating error, so the harness inspected the PowerShell error collection rather than treating a normal return as success.

Live-test results

All 52 executed parameter-set paths reached the expected InvalidPolicyTokenRequest, and every target resource remained present.

Module Public commands exercised Parameter sets Result
EventHub Set-AzEventHub, Set-AzEventHubConsumerGroup, Set-AzEventHubAuthorizationRule, Set-AzEventHubNamespace, Set-AzEventHubNetworkRuleSet, Set-AzEventHubApplicationGroup, Approve-AzEventHubPrivateEndpointConnection, Deny-AzEventHubPrivateEndpointConnection, Set-AzEventHubGeoDRConfigurationBreakPair, Set-AzEventHubGeoDRConfigurationFailOver Expanded + ViaIdentity 20/20 expected safe failures
Service Bus Set-AzServiceBusQueue, Set-AzServiceBusTopic, Set-AzServiceBusSubscription, Set-AzServiceBusRule, Set-AzServiceBusAuthorizationRule, Set-AzServiceBusNamespace, Set-AzServiceBusNetworkRuleSet, Approve-AzServiceBusPrivateEndpointConnection, Deny-AzServiceBusPrivateEndpointConnection, Set-AzServiceBusGeoDRConfigurationBreakPair, Set-AzServiceBusGeoDRConfigurationFailOver Expanded + ViaIdentity 22/22 expected safe failures
Network Security Perimeter Update-AzNetworkSecurityPerimeterAccessRule, Update-AzNetworkSecurityPerimeterAssociation, Update-AzNetworkSecurityPerimeterLink Expanded + ViaIdentity 6/6 expected safe failures
CDN Update-AzFrontDoorCdnProfile, Remove-AzFrontDoorCdnProfile Expanded + ViaIdentity 4/4 expected safe failures

Live testing also exposed the Contains() incompatibility with PSBoundParametersDictionary; the ContainsKey() fix is included and was verified by rerunning the EventHub and Service Bus GeoDR live paths.

Paths not exercised live

These paths could not be run in the available subscription:

Command Parameter-set paths Reason
Set-AzEventHubCluster 2 Requires a dedicated Event Hub cluster; the repository's shared test-cluster subscription was not accessible to the test account.
Update-AzNetworkSecurityPerimeterLoggingConfiguration 2 Azure blocked the preliminary GET because the tenant is not allowlisted and the required EnableServiceTagsInNsp AFEC flag is unavailable.
Update-AzCdnProfile, Remove-AzCdnProfile for classic CDN 4 Azure no longer permits creating new Microsoft classic CDN profiles, and the test subscription has no existing classic profile.

All temporary Azure resource groups created for live testing were deleted and verified absent afterward.

Scope

The separate two-write Start-AzFrontDoorCdnProfilePrepareMigration forwarding case is deferred to a follow-up. Direct-write namespace failover wrappers remain unchanged because they do not perform a preliminary GET.

Copilot AI lite review requested due to automatic review settings September 28, 2026 04:22
Keep target command parameters separate from metadata-filtered read parameters so dynamic write parameters are not passed to preliminary GET operations.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@YangAn-microsoft
YangAn-microsoft force-pushed the fix/change-safety-read-parameter-forwarding branch from cb94438 to 7533e67 Compare September 28, 2026 04:26

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

GeoDR via-identity paths drop write-side dynamic parameters, and required changelog references are missing.

Review effort: Lite
Findings: 4 Medium severity

Open (4)
What changed in this PR

Fixes Change Safety parameter forwarding for read-modify-write cmdlets across EventHub, Service Bus, and Network Security Perimeter.

Changes:

  • Separates preliminary-read and target-write parameters using command metadata.
  • Updates wrappers, regression tests, packaging metadata, generation IDs, and changelogs.
  • Outstanding: four moderate GeoDR via-identity forwarding findings and three nit-level missing [#30117] changelog references.
File Reviewed change
src/​ServiceBus/​ServiceBus/​ChangeLog.md Documents the forwarding fix.
src/​ServiceBus/​ServiceBus.Autorest/​test/​ReadParameterForwarding.Tests.ps1 Adds forwarding regression tests.
src/​ServiceBus/​ServiceBus.Autorest/​generate-info.json Triggers regeneration.
src/​ServiceBus/​ServiceBus.Autorest/​custom/​Set-AzServiceBusTopic.ps1 Separates read/write parameters.
src/​ServiceBus/​ServiceBus.Autorest/​custom/​Set-AzServiceBusSubscription.ps1 Separates read/write parameters.
src/​ServiceBus/​ServiceBus.Autorest/​custom/​Set-AzServiceBusRule.ps1 Separates read/write parameters.
src/​ServiceBus/​ServiceBus.Autorest/​custom/​Set-AzServiceBusQueue.ps1 Separates read/write parameters.
src/​ServiceBus/​ServiceBus.Autorest/​custom/​Set-AzServiceBusNetworkRuleSet.ps1 Separates read/write parameters.
src/​ServiceBus/​ServiceBus.Autorest/​custom/​Set-AzServiceBusNamespace.ps1 Separates read/write parameters.
src/​ServiceBus/​ServiceBus.Autorest/​custom/​Set-AzServiceBusGeoDRConfigurationFailOver.ps1 Updates failover forwarding.
src/​ServiceBus/​ServiceBus.Autorest/​custom/​Set-AzServiceBusGeoDRConfigurationBreakPair.ps1 Updates break-pair forwarding.
src/​ServiceBus/​ServiceBus.Autorest/​custom/​Set-AzServiceBusAuthorizationRule.ps1 Updates authorization-rule forwarding.
src/​ServiceBus/​ServiceBus.Autorest/​custom/​Get-AzServiceBusReadParameters.ps1 Filters parameters using read-command metadata.
src/​ServiceBus/​ServiceBus.Autorest/​custom/​Deny-AzServiceBusPrivateEndpointConnection.ps1 Separates read/write parameters.
src/​ServiceBus/​ServiceBus.Autorest/​custom/​Approve-AzServiceBusPrivateEndpointConnection.ps1 Separates read/write parameters.
src/​Network/​NetworkSecurityPerimeter.Autorest/​test/​ReadParameterForwarding.Tests.ps1 Adds forwarding regression tests.
src/​Network/​NetworkSecurityPerimeter.Autorest/​generate-info.json Triggers regeneration.
src/​Network/​NetworkSecurityPerimeter.Autorest/​custom/​Update-AzNetworkSecurityPerimeterLoggingConfiguration.ps1 Separates read/write parameters.
src/​Network/​NetworkSecurityPerimeter.Autorest/​custom/​Update-AzNetworkSecurityPerimeterLink.ps1 Separates read/write parameters.
src/​Network/​NetworkSecurityPerimeter.Autorest/​custom/​Update-AzNetworkSecurityPerimeterAssociation.ps1 Separates read/write parameters.
src/​Network/​NetworkSecurityPerimeter.Autorest/​custom/​Update-AzNetworkSecurityPerimeterAccessRule.ps1 Separates read/write parameters.
src/​Network/​NetworkSecurityPerimeter.Autorest/​custom/​Get-AzNetworkSecurityPerimeterReadParameters.ps1 Filters parameters using read-command metadata.
src/​Network/​Network/​ChangeLog.md Documents the forwarding fix.
src/​EventHub/​EventHub/​ChangeLog.md Documents the forwarding fix.
src/​EventHub/​EventHub.Autorest/​test/​ReadParameterForwarding.Tests.ps1 Adds forwarding regression tests.
src/​EventHub/​EventHub.Autorest/​generate-info.json Triggers regeneration.
src/​EventHub/​EventHub.Autorest/​custom/​Set-AzEventHubNetworkRuleSet.ps1 Separates read/write parameters.
src/​EventHub/​EventHub.Autorest/​custom/​Set-AzEventHubNamespace.ps1 Separates read/write parameters.
src/​EventHub/​EventHub.Autorest/​custom/​Set-AzEventHubGeoDRConfigurationFailOver.ps1 Updates failover forwarding.
src/​EventHub/​EventHub.Autorest/​custom/​Set-AzEventHubGeoDRConfigurationBreakPair.ps1 Updates break-pair forwarding.
src/​EventHub/​EventHub.Autorest/​custom/​Set-AzEventHubConsumerGroup.ps1 Separates read/write parameters.
src/​EventHub/​EventHub.Autorest/​custom/​Set-AzEventHubCluster.ps1 Separates read/write parameters.
src/​EventHub/​EventHub.Autorest/​custom/​Set-AzEventHubAuthorizationRule.ps1 Updates authorization-rule forwarding.
src/​EventHub/​EventHub.Autorest/​custom/​Set-AzEventHubApplicationGroup.ps1 Separates read/write parameters.
src/​EventHub/​EventHub.Autorest/​custom/​Set-AzEventHub.ps1 Separates read/write parameters.
src/​EventHub/​EventHub.Autorest/​custom/​Get-AzEventHubReadParameters.ps1 Filters parameters using read-command metadata.
src/​EventHub/​EventHub.Autorest/​custom/​Deny-AzEventHubPrivateEndpointConnection.ps1 Separates read/write parameters.
src/​EventHub/​EventHub.Autorest/​custom/​Approve-AzEventHubPrivateEndpointConnection.ps1 Separates read/write parameters.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Copilot AI review requested due to automatic review settings September 28, 2026 04:28
@a0x1ab

Copy link
Copy Markdown
Member

/azp run

@azure-pipelines

Copy link
Copy Markdown
Contributor
Azure Pipelines:
Successfully started running 3 pipeline(s).

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Four via-identity wrappers still drop Change Safety parameters before the write, with additional test and changelog follow-ups.

Review effort: Lite
Findings: 4 Medium severity · 3 Low severity

Open (7)

Comment thread src/EventHub/EventHub/ChangeLog.md Outdated
Comment thread src/Network/Network/ChangeLog.md Outdated
Comment thread src/ServiceBus/ServiceBus/ChangeLog.md Outdated
Remove the module-specific helper functions and filter read parameters directly at each preliminary read site while preserving the independent target parameter dictionary.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI review requested due to automatic review settings September 28, 2026 04:46

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Identity-path Change Safety parameters are dropped, and related regression coverage and changelog references remain incomplete.

Review effort: Lite
Findings: 4 Medium severity · 3 Low severity

Open (7)
Previously missed (4)

In code that hasn't changed since last review

Medium severity Forward Change Safety parameters in BreakViaIdentity

src/​EventHub/​EventHub.Autorest/​custom/​Set-AzEventHubGeoDRConfigurationBreakPair.ps1:164

In the BreakViaIdentity path, the Change Safety entries remain in $targetParameters but are not copied into $EnvPSBoundParameters; the final invocation at line 190 therefore drops -AcquirePolicyToken/-ChangeReference even though the wrapped Break cmdlet exposes both dynamic parameters. Please forward the target's write-only dynamic entries into this invocation without duplicating the explicitly supplied path parameters.

Medium severity Forward Change Safety parameters in FailViaIdentity

src/​EventHub/​EventHub.Autorest/​custom/​Set-AzEventHubGeoDRConfigurationFailOver.ps1:164

In the FailViaIdentity path, the Change Safety entries remain in $targetParameters but are not copied into $EnvPSBoundParameters; the final invocation at line 190 therefore drops -AcquirePolicyToken/-ChangeReference even though the wrapped Fail cmdlet exposes both dynamic parameters. Please forward the target's write-only dynamic entries into this invocation without duplicating the explicitly supplied path parameters.

Medium severity Forward Change Safety parameters in BreakViaIdentity

src/​ServiceBus/​ServiceBus.Autorest/​custom/​Set-AzServiceBusGeoDRConfigurationBreakPair.ps1:165

In the BreakViaIdentity path, the Change Safety entries remain in $targetParameters but are not copied into $EnvPSBoundParameters; the final invocation at line 190 therefore drops -AcquirePolicyToken/-ChangeReference even though the wrapped Break cmdlet exposes both dynamic parameters. Please forward the target's write-only dynamic entries into this invocation without duplicating the explicitly supplied path parameters.

Medium severity Forward Change Safety parameters in FailViaIdentity

src/​ServiceBus/​ServiceBus.Autorest/​custom/​Set-AzServiceBusGeoDRConfigurationFailOver.ps1:165

In the FailViaIdentity path, the Change Safety entries remain in $targetParameters but are not copied into $EnvPSBoundParameters; the final invocation at line 190 therefore drops -AcquirePolicyToken/-ChangeReference even though the wrapped FailExpanded cmdlet exposes both dynamic parameters. Please forward the target's write-only dynamic entries into this invocation without duplicating the explicitly supplied path parameters.

Centralize command-metadata filtering per module to avoid duplicating the same read-parameter intersection at every read-modify-write call site.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI review requested due to automatic review settings September 28, 2026 04:54
The forwarding fix will ship with the existing unreleased Change Safety enablement, so keep a single release note for the feature.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Four moderate ViaIdentity forwarding issues still drop preserved dynamic write parameters.

Review effort: Lite
Findings: 4 Medium severity

Open (4)
Resolved since last review (3)
Previously missed (4)

In code that hasn't changed since last review

Medium severity ViaIdentity drops dynamic write parameters

src/​EventHub/​EventHub.Autorest/​custom/​Set-AzEventHubGeoDRConfigurationBreakPair.ps1:156

The ViaIdentity path still rebuilds $EnvPSBoundParameters from only the transport fields and invokes the write with that dictionary, so the dynamic parameters preserved in $targetParameters (-AcquirePolicyToken, -ChangeReference, and future write parameters) are silently dropped for this parameter set. Build this dictionary from $targetParameters after removing the path parameters supplied explicitly to the private cmdlet.

Medium severity ViaIdentity drops dynamic write parameters

src/​EventHub/​EventHub.Autorest/​custom/​Set-AzEventHubGeoDRConfigurationFailOver.ps1:156

The ViaIdentity path still rebuilds $EnvPSBoundParameters from only the transport fields and invokes the write with that dictionary, so the dynamic parameters preserved in $targetParameters (-AcquirePolicyToken, -ChangeReference, and future write parameters) are silently dropped for this parameter set. Build this dictionary from $targetParameters after removing the path parameters supplied explicitly to the private cmdlet.

Medium severity ViaIdentity drops dynamic write parameters

src/​ServiceBus/​ServiceBus.Autorest/​custom/​Set-AzServiceBusGeoDRConfigurationBreakPair.ps1:157

The ViaIdentity path still rebuilds $EnvPSBoundParameters from only the transport fields and invokes the write with that dictionary, so the dynamic parameters preserved in $targetParameters (-AcquirePolicyToken, -ChangeReference, and future write parameters) are silently dropped for this parameter set. Build this dictionary from $targetParameters after removing the path parameters supplied explicitly to the private cmdlet.

Medium severity ViaIdentity drops dynamic write parameters

src/​ServiceBus/​ServiceBus.Autorest/​custom/​Set-AzServiceBusGeoDRConfigurationFailOver.ps1:157

The ViaIdentity path still rebuilds $EnvPSBoundParameters from only the transport fields and invokes the write with that dictionary, so the dynamic parameters preserved in $targetParameters (-AcquirePolicyToken, -ChangeReference, and future write parameters) are silently dropped for this parameter set. Build this dictionary from $targetParameters after removing the path parameters supplied explicitly to the private cmdlet.

Copilot AI review requested due to automatic review settings September 28, 2026 05:00
Keep target writes on the original PSBoundParameters dictionary and introduce only helper-filtered read parameters for preliminary GET operations.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Four moderate forwarding issues remain in via-identity GeoDR branches.

Review effort: Lite
Findings: 4 Medium severity

Open (4)
Previously missed (4)

In code that hasn't changed since last review

Medium severity Preserve runtime parameters in BreakViaIdentity write

src/​EventHub/​EventHub.Autorest/​custom/​Set-AzEventHubGeoDRConfigurationBreakPair.ps1:156

The BreakViaIdentity branch still rebuilds $EnvPSBoundParameters with only the common pipeline/proxy values, so -AcquirePolicyToken and -ChangeReference remain in $targetParameters but are never passed to the private via-identity write cmdlet. That cmdlet exposes these dynamic parameters, so construct the write splat from the target dictionary (removing only the explicitly supplied path arguments) to preserve Change Safety and other runtime parameters in this branch.

                    $EnvPSBoundParameters['Debug'] = $Debug
                }
                if ($PSBoundParameters.ContainsKey('HttpPipelineAppend')) {
                    $EnvPSBoundParameters['HttpPipelineAppend'] = $HttpPipelineAppend
                }
Medium severity Preserve runtime parameters in FailViaIdentity write

src/​EventHub/​EventHub.Autorest/​custom/​Set-AzEventHubGeoDRConfigurationFailOver.ps1:156

The FailViaIdentity branch still rebuilds $EnvPSBoundParameters with only the common pipeline/proxy values, so -AcquirePolicyToken and -ChangeReference remain in $targetParameters but are never passed to the private via-identity write cmdlet. That cmdlet exposes these dynamic parameters, so construct the write splat from the target dictionary (removing only the explicitly supplied path arguments) to preserve Change Safety and other runtime parameters in this branch.

                    $EnvPSBoundParameters['Debug'] = $Debug
                }
                if ($PSBoundParameters.ContainsKey('HttpPipelineAppend')) {
                    $EnvPSBoundParameters['HttpPipelineAppend'] = $HttpPipelineAppend
                }
Medium severity Preserve runtime parameters in BreakViaIdentity write

src/​ServiceBus/​ServiceBus.Autorest/​custom/​Set-AzServiceBusGeoDRConfigurationBreakPair.ps1:157

The BreakViaIdentity branch still rebuilds $EnvPSBoundParameters with only the common pipeline/proxy values, so -AcquirePolicyToken and -ChangeReference remain in $targetParameters but are never passed to the private via-identity write cmdlet. That cmdlet exposes these dynamic parameters, so construct the write splat from the target dictionary (removing only the explicitly supplied path arguments) to preserve Change Safety and other runtime parameters in this branch.

                    $EnvPSBoundParameters['Debug'] = $Debug
                }
                if ($PSBoundParameters.ContainsKey('HttpPipelineAppend')) {
                    $EnvPSBoundParameters['HttpPipelineAppend'] = $HttpPipelineAppend
                }
Medium severity Preserve runtime parameters in FailViaIdentity write

src/​ServiceBus/​ServiceBus.Autorest/​custom/​Set-AzServiceBusGeoDRConfigurationFailOver.ps1:157

The FailViaIdentity branch still rebuilds $EnvPSBoundParameters with only the common pipeline/proxy values, so -AcquirePolicyToken and -ChangeReference remain in $targetParameters but are never passed to the private via-identity write cmdlet. That cmdlet exposes these dynamic parameters, so construct the write splat from the target dictionary (removing only the explicitly supplied path arguments) to preserve Change Safety and other runtime parameters in this branch.

                    $EnvPSBoundParameters['Debug'] = $Debug
                }
                if ($PSBoundParameters.ContainsKey('HttpPipelineAppend')) {
                    $EnvPSBoundParameters['HttpPipelineAppend'] = $HttpPipelineAppend
                }

Copilot AI review requested due to automatic review settings September 28, 2026 05:07
@a0x1ab

Copy link
Copy Markdown
Member

/azp run

@azure-pipelines

Copy link
Copy Markdown
Contributor
Azure Pipelines:
Successfully started running 3 pipeline(s).

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Add execution-level tests confirming filtered read parameters and preserved write parameters.

Review effort: Lite
Findings: 4 Medium severity

Open (4)

Copy all bound dynamic parameters supported by the generated Break and Fail actions into the existing via-identity environment splats without hard-coding Change Safety parameter names.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI review requested due to automatic review settings September 28, 2026 06:01
@azure-pipelines

Copy link
Copy Markdown
Contributor
Azure Pipelines will not run the associated pipelines, because the pull request was updated after the run command was issued. Review the pull request again and issue a new run command.

Resolve the Network Security Perimeter generation ID conflict with a fresh ID for the merged source state.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@a0x1ab

Copy link
Copy Markdown
Member

/azp run

@azure-pipelines

Copy link
Copy Markdown
Contributor
Azure Pipelines:
Successfully started running 3 pipeline(s).

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved review comments or approval blockers were supplied.

Review effort: Lite
Findings: None

Copilot AI review requested due to automatic review settings September 28, 2026 11:25

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved review comments are present, and focused regression coverage is included.

Review effort: Lite
Findings: None

Keep artifact-level helper packaging assertions, but remove source-only generate-info checks because generation metadata is not included in built module artifacts.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI review requested due to automatic review settings September 28, 2026 12:43
@a0x1ab

Copy link
Copy Markdown
Member

/azp run

@azure-pipelines

Copy link
Copy Markdown
Contributor
Azure Pipelines:
Successfully started running 3 pipeline(s).

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The broad cross-module scope and paths not exercised live warrant final human review.

Review effort: Lite
Findings: None

Remove an unrelated blank-line deletion from the Change Safety PR.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI review requested due to automatic review settings September 28, 2026 12:54

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The broad cross-module cmdlet and generated-code changes require final human review.

Review effort: Lite
Findings: None

@a0x1ab

Copy link
Copy Markdown
Member

/azp run

@azure-pipelines

Copy link
Copy Markdown
Contributor
Azure Pipelines:
Successfully started running 3 pipeline(s).

Document the Change Safety forwarding fixes in all affected modules and remove the PR-specific test files.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI review requested due to automatic review settings September 29, 2026 02:10
@a0x1ab

Copy link
Copy Markdown
Member

/azp run

@azure-pipelines

Copy link
Copy Markdown
Contributor
Azure Pipelines:
Successfully started running 3 pipeline(s).

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

Validation covered the forwarding fixes; remaining comments are non-blocking documentation nits.

Review effort: Lite
Findings: 2 Low severity

Open (2)

-->
## Upcoming Release
* Added Change Safety support for additional cmdlets.
* Fixed Change Safety parameter forwarding in custom read-before-write and GeoDR cmdlets.
-->
## Upcoming Release
* Added Change Safety support for additional cmdlets.
* Fixed Change Safety parameter forwarding in custom read-before-write and GeoDR cmdlets.
@VeryEarly
Yabo Hu (VeryEarly) merged commit 95c4e29 into Azure:main Sep 29, 2026
10 of 12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants