Repository navigation
Prefer posix_spawn on apple targets #126097
Description
Activity
dotnet-policy-service commented
on Mar 25, 2026 ContributorMore actionsTagging subscribers to this area: @dotnet/area-system-diagnostics-process
See info in area-owners.md if you want to be subscribed.It would allow us to support Process APIs on iOS.
Are you sure? I do not think iOS app sandbox allows launching processes.
We still need a fallback to fork/exec to support setguid, setuid and groups:
How is it going to work when one uses both these features and limited handle inheritance?
Are you sure? I do not think iOS app sandbox allows launching processes.
Please take it with a grain of salt, as I have 0 experience but based on my findings: iOS Sandboxing Prohibits Executing External Binaries, but you can run executables that are inside your app bundle, code‑signed with your app and "permitted by Apple’s policies" (whatever it means)
How is it going to work when one uses both these features and limited handle inheritance?
Similarly to other platforms that don't provide a performant way to enforce it (like old Linux kernels), we have at least two options:
- enforce it anyway, at the cost of performance penalty (iterate over all opened fd and apply the
FD_CLOEXECflag using fcntl) - treat the API as one that ensures that given handles are always going to be inherited and other handles will not if underlying OS supports a built-in mechanism to do it.
I would like to recommend to enable this feature by default to some of our tooling (SDK, MSBuild, VS etc), but if we go with option 1 it may cause performance regressions on platforms that we care about (like the old RHEL that we still support). On the other hand, @tmds has put a lot of effort into ensuring dotnet/runtime uses FD_CLOEXEC everywhere by default, so I could also just recommend these tools to do:
processStartInfo.InheritedHandles = OperatingSystem.IsWindows() ? [] : null;
@jkotas @stephentoub what would be your preference?
- enforce it anyway, at the cost of performance penalty (iterate over all opened fd and apply the
like the old RHEL that we still support
close_range was backported to RHEL 8: https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/8/html/8.4_release_notes/new-features
Reacted by Adam Sitnik- locked and limited conversation to collaborators
on Apr 28, 2026
POSIX_SPAWN_CLOEXEC_DEFAULTsupported byposix_spawn. So it's a must have for Make Process.Start have a option to change handle inheritance #13943.ProcessAPIs on iOS. The only unclear part is testing.x5on x64.fork(fromvfork) on Android. However, it's worth just asking Copilot to write a prototype and use EgorBot to run some simple benchmarks on Linux x64 and arm64. We should benchmark various scenarios that would include processes that are cheap and expensive to copy . Check https://rust-lang.github.io/rfcs//3228-process-process_group.html for rust approached it.setguid,setuidand groups:runtime/src/native/libs/System.Native/pal_process.c
Lines 406 to 414 in d6c493d
cc @jkotas @stephentoub @tmds