Skip to content

Fix components-key validation timeouts under load - #3108

Merged
Vincent Biret (baywet) merged 5 commits into
mainfrom
copilot/fix-components-key-validation-timeout
Oct 9, 2026
Merged

Vincent Biret (baywet) merged 5 commits into
mainfrom
copilot/fix-components-key-validation-timeout

Conversation

Copilot AI commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Pull Request

Description

Components-key validation can throw RegexMatchTimeoutException during LoadAsync when scheduling or GC pauses exceed its 100 ms timeout. This change removes timeout-dependent matching while preserving accepted keys and error messages.

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Documentation update
  • Other (please describe):

Related Issue(s)

Changes Made

  • .NET 8+: Source-generate the existing regex; its generated matching path contains no timeout checks.
  • .NET Standard 2.0: Use an equivalent linear character scan, preserving the $ anchor’s acceptance of one final newline.
  • Regression coverage: Exercise both matchers across character and newline boundaries, plus LoadAsync with million-character valid and invalid keys.

Testing

  • Unit tests added/updated
  • Integration tests added/updated
  • Manual testing performed
  • All existing tests pass

Checklist

  • My code follows the code style of this project
  • I have performed a self-review of my own code
  • I have made corresponding changes to the documentation
  • My changes generate no new warnings
  • I have added tests that prove my fix is effective or that my feature works
  • New and existing unit tests pass locally with my changes

Versions applicability

  • My change applies to the version 1.X of the library, if so PR link:
  • My change applies to the version 2.X of the library, if so PR link:
  • My change applies to the version 3.X of the library, if so PR link:
  • I have evaluated the applicability of my change against the other versions above.

See the contributing guidelines for more information about how patches are applied across multiple versions.

Additional Notes

RegexOptions.NonBacktracking is deliberately omitted: it prevents source generation and falls back to a runtime regex.

Co-authored-by: baywet <7905502+baywet@users.noreply.github.com>
Copilot AI changed the title [WIP] Fix components-key validation timeout issue during LoadAsync Fix components-key validation timeouts under load Oct 9, 2026
Comment thread test/Microsoft.OpenApi.Tests/Validations/OpenApiComponentsValidationTests.cs Outdated
Comment thread src/Microsoft.OpenApi/Validations/Rules/OpenApiComponentsRules.cs Outdated
Comment thread src/Microsoft.OpenApi/Validations/Rules/OpenApiComponentsRules.cs Fixed
Co-authored-by: baywet <7905502+baywet@users.noreply.github.com>
@github-code-quality

github-code-quality Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Code Coverage Overview

Languages: C#

C# / code-coverage/dotnet

The overall line coverage in commit 0a241bd in the copilot/fix-componen... branch is 61%. The line coverage in commit c719c42 in the main branch is 32%.

Show a line coverage summary of the most impacted files.
File main c719c42 copilot/fix-componen... 0a241bd +/-
/_/src/Humanize...lePrefixSort.cs 0% 0% 0%
/_/src/Humanize...tes/ByteRate.cs 0% 0% 0%
/_/src/Humanize...tes/ByteSize.cs 0% 0% 0%
/_/src/Humanize...zeExtensions.cs 0% 0% 0%
/_/src/Humanize...ngExtensions.cs 0% 0% 0%
/_/src/Humanize...zeExtensions.cs 0% 0% 0%
/_/src/Humanize...tterRegistry.cs 0% 0% 0%
/_/src/Humanize...orExtensions.cs 0% 4% +4%
/_/src/Humanize...s/Vocabulary.cs 0% 68% +68%
/_/src/Humanize...Vocabularies.cs 0% 100% +100%

Updated October 09, 2026 14:29 UTC

@baywet
Vincent Biret (baywet) requested a balanced review from Copilot October 9, 2026 13:26
@baywet
Vincent Biret (baywet) marked this pull request as ready for review October 9, 2026 13:26
@baywet
Vincent Biret (baywet) requested a review from a team as a code owner October 9, 2026 13:26
@baywet
Vincent Biret (baywet) enabled auto-merge (squash) October 9, 2026 13:26

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The supported netstandard2.0 path retains the finite timeout and is not exercised by the new tests.

2 open findings
What changed in this PR

Fixes nondeterministic component-key validation timeouts during OpenAPI loading.

Changes:

  • Adds source-generated regex matching for .NET 8+.
  • Adds component-key boundary and long-key regression tests.
  • Documents repository regex-handling conventions.
File Description
OpenApiComponentsRules.cs Introduces target-specific regex matching.
OpenApiComponentsValidationTests.cs Adds validation and load regression tests.
agents.md Documents regex conventions.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/Microsoft.OpenApi/Validations/Rules/OpenApiComponentsRules.cs
@sonarqubecloud

sonarqubecloud Bot commented Oct 9, 2026

Copy link
Copy Markdown

@baywet
Vincent Biret (baywet) merged commit 01d4729 into main Oct 9, 2026
19 checks passed
@baywet
Vincent Biret (baywet) deleted the copilot/fix-components-key-validation-timeout branch October 9, 2026 17:29
Vincent Biret (baywet) added a commit that referenced this pull request Oct 9, 2026
* Initial plan

* fix(library): avoid components key validation timeouts under load



* fix(library): use conditional regex fallback for older frameworks



---------

Co-authored-by: Copilot <198982749+Copilot@users.noreply.github.com>
Co-authored-by: baywet <7905502+baywet@users.noreply.github.com>
Deniz İrgin (Blind-Striker) added a commit to opencode-dotnet/opencode-sdk-dotnet that referenced this pull request Oct 9, 2026
The roadmap also records the Microsoft.OpenApi bump that microsoft/OpenAPI.NET#3108 unblocks.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Components-key validation can fail LoadAsync under load: 100 ms wall-clock timeout on a linear regex

5 participants