Skip to content

Make the analysis of generated code opt-in - #1425

Merged
meziantou merged 1 commit into
mainfrom
feature/code-analysis-opt-in-1f53f6
Sep 6, 2026
Merged

meziantou merged 1 commit into
mainfrom
feature/code-analysis-opt-in-1f53f6

Conversation

@meziantou

@meziantou meziantou commented Sep 6, 2026 •

Copy link
Copy Markdown
Owner

Fix #1424

Follow-up to #1423, which added MEZIANTOU_ANALYZER_GENERATED_CODE as an opt-out. This flips it to an opt-in: the rules now skip generated code unless the variable is set.

What changed

AnalysisContextExtensions.GetAdditionalFlags returns Analyze | ReportDiagnostics only when the variable is 1 or true (trimmed, case-insensitive), and None for anything else, including the variable being unset.

Each rule's own flags remain the minimum, so nothing changes for the rules that pass more than None:

Flags passed by the rule Rules Behavior without the variable
None 145 Skip generated code (was: analyze and let report_generated_code decide)
Analyze 6 Analyze it, as they need the whole compilation to be correct (e.g. MA0053)
Analyze | ReportDiagnostics 23 Analyze it and report in it, as the generated file is the subject of the rule (e.g. the Blazor rules)

Why

Analyzing generated code costs build time, and a project where nothing reports in generated code pays it for nothing, which is the vast majority of them: you cannot fix code you do not own. Making it opt-in means only the projects that ask for it pay the cost.

Notes for reviewers

Two behavior changes are worth knowing, both covered by tests:

  • report_generated_code = true is no longer sufficient on its own for the 145 rules that skip generated code, as it only decides what a rule reports among the code it analyzes. It now needs the environment variable too. Setting it to false still always works, as a rule can only report what it is allowed to report.
  • A rule that skips generated code never sees it, so Roslyn's own detection applies instead, which also treats the symbols marked [GeneratedCode] or [DebuggerNonUserCode] as generated. A symbol marked with one of those attributes in a hand written file is therefore skipped by default, where previously only the file of the diagnostic mattered.

Also updated: the BannedSymbols.txt message, the XML documentation of ConfigureAnalysisOfGeneratedCode and GeneratedCodeReporting, docs/generated-code.md, the README section, and the Generated code guidance in AGENTS.md.

Tests

GeneratedCodeAnalysisTests simulates the variable with an OptedIn flags constant, as the rules read it once per process. Added coverage for the two new defaults (a rule configured with report_generated_code but not opted in reports nothing, and a rule opted in without configuration reports nothing) and for both sides of the [GeneratedCode] case. AnalysisContextExtensionsTests was flipped to opted-in/not-opted-in values.

dotnet test passes on the five Roslyn versions: 19808 tests, 0 failures. dotnet run --project src/DocumentationGenerator exits 0 with no markdown change.

Analyzing generated code costs build time, and most projects never report
anything in it, so the rules now skip it unless the
MEZIANTOU_ANALYZER_GENERATED_CODE environment variable opts in with "1" or
"true". The rules that need generated code to be correct, such as MA0053, and
the ones that report in it by default, such as the Blazor rules, are unchanged,
as the flags they pass to ConfigureAnalysisOfGeneratedCode are still the
minimum.

report_generated_code only decides what a rule reports among the code it
analyzes, so it now needs the environment variable to report in generated code
with a rule that skips it. Setting it to false still always works.
@meziantou
meziantou enabled auto-merge (squash) September 6, 2026 22:01
@meziantou
meziantou merged commit 48996bf into main Sep 6, 2026
13 checks passed
@meziantou
meziantou deleted the feature/code-analysis-opt-in-1f53f6 branch September 6, 2026 22:06
This was referenced Oct 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

MA0004 gets reported in Generated ASP.NET Core Route Builder code even when it's disabled

1 participant