Skip to content

Prefer posix_spawn on apple targets #126097

Description

@adamsitnik
  • The only way to limit handle inheritance in performant way on apple targets is to use POSIX_SPAWN_CLOEXEC_DEFAULT supported by posix_spawn. So it's a must have for Make Process.Start have a option to change handle inheritance #13943.
  • It would allow us to support Process APIs on iOS. The only unclear part is testing.
  • It's the recommended and most performant way to spawn processes on Apple targets. The numbers I got for Prefer posix_spawn on OSX #126063 show even up to x100 boost on arm64 and x5 on x64.
  • We can't take for granted that it would just work on all the platforms. For example in Don't use vfork on android #118085, we had to switch to fork (from vfork) on Android. However, it's worth just asking Copilot to write a prototype and use EgorBot to run some simple benchmarks on Linux x64 and arm64. We should benchmark various scenarios that would include processes that are cheap and expensive to copy . Check https://rust-lang.github.io/rfcs//3228-process-process_group.html for rust approached it.
  • We still need a fallback to fork/exec to support setguid, setuid and groups:

if (setCredentials)
{
if (SetGroups(groups, groupsLength, getGroupsBuffer) == -1 ||
setgid(groupId) == -1 ||
setuid(userId) == -1)
{
ExitChild(waitForChildToExecPipe[WRITE_END_OF_PIPE], errno);
}
}

cc @jkotas @stephentoub @tmds

Activity

  1. added this to the 11.0.0 milestone on Mar 25, 2026
  2. self-assigned this
    on Mar 25, 2026
  3. dotnet-policy-service commented on Mar 25, 2026

    @dotnet-policy-service
    Contributor

    Tagging subscribers to this area: @dotnet/area-system-diagnostics-process
    See info in area-owners.md if you want to be subscribed.

  4. jkotas commented on Mar 25, 2026

    @jkotas
    Member

    It would allow us to support Process APIs on iOS.

    Are you sure? I do not think iOS app sandbox allows launching processes.

  5. jkotas commented on Mar 25, 2026

    @jkotas
    Member

    We still need a fallback to fork/exec to support setguid, setuid and groups:

    How is it going to work when one uses both these features and limited handle inheritance?

  6. adamsitnik commented on Mar 25, 2026

    @adamsitnik
    MemberAuthor

    Are you sure? I do not think iOS app sandbox allows launching processes.

    Please take it with a grain of salt, as I have 0 experience but based on my findings: iOS Sandboxing Prohibits Executing External Binaries, but you can run executables that are inside your app bundle, code‑signed with your app and "permitted by Apple’s policies" (whatever it means)

  7. adamsitnik commented on Mar 25, 2026

    @adamsitnik
    MemberAuthor

    How is it going to work when one uses both these features and limited handle inheritance?

    Similarly to other platforms that don't provide a performant way to enforce it (like old Linux kernels), we have at least two options:

    1. enforce it anyway, at the cost of performance penalty (iterate over all opened fd and apply the FD_CLOEXEC flag using fcntl)
    2. treat the API as one that ensures that given handles are always going to be inherited and other handles will not if underlying OS supports a built-in mechanism to do it.

    I would like to recommend to enable this feature by default to some of our tooling (SDK, MSBuild, VS etc), but if we go with option 1 it may cause performance regressions on platforms that we care about (like the old RHEL that we still support). On the other hand, @tmds has put a lot of effort into ensuring dotnet/runtime uses FD_CLOEXEC everywhere by default, so I could also just recommend these tools to do:

    processStartInfo.InheritedHandles = OperatingSystem.IsWindows() ? [] : null;

    @jkotas @stephentoub what would be your preference?

  8. tmds commented on Mar 25, 2026

    @tmds
    Member

    like the old RHEL that we still support

    close_range was backported to RHEL 8: https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/8/html/8.4_release_notes/new-features

  9. locked and limited conversation to collaborators on Apr 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions