Repository navigation
[ci-scan] Test failure: X509Certificate2CollectionRemoveRangeArray under crossgen2 R2R (recurrence) #129576
Description
Activity
- addedblocking-clean-ciBlocking PR or rolling runs of 'runtime' or 'runtime-extra-platforms'Blocking PR or rolling runs of 'runtime' or 'runtime-extra-platforms'Known Build ErrorUse this to report build issues in the .NET Helix tabUse this to report build issues in the .NET Helix tab
on Jun 18, 2026 - addeduntriagedNew issue has not been triaged by the area ownerNew issue has not been triaged by the area owner
on Jun 18, 2026 dotnet-policy-service commented
on Jun 18, 2026 ContributorMore actionsTagging subscribers to this area: @bartonjs, @vcsjones, @dotnet/area-system-security
See info in area-owners.md if you want to be subscribed.- addedarea-crossgen2-coreclronly use for closed issuesonly use for closed issuesand removed
on Jun 18, 2026 github-actions commented
on Jun 19, 2026 on Jun 19, 2026 – with GitHub ActionsContributorAuthorMore actionsWorkflow artifact: ci-fix
Artifact kind: handoff
Linked KBE: #129576Note
AI/Copilot-generated triage note.
This Known Build Error has no producible automated code change (reason: crossgen2/R2R codegen exception handling bug — the product code is correct and the fix requires changes to R2R compilation/exception dispatch, which exceeds automated bounds), so I could not open even a best-effort PR. Looping in owners so it can be fixed forward rather than muted.
Root cause (best analysis)
X509Certificate2CollectionRemoveRangeArray(atCollectionTests.cs:1037) consistently fails under crossgen2 R2R compilation on all three platforms (linux-x64, windows-x64, osx-x64). The assertionAssert.Equal(2, cc.Count)gets 0 instead.The product code in
X509Certificate2Collection.RemoveRange(X509Certificate2[])(line 342–362) is correct: it removes elements in atryblock, and if any removal throws, thecatchblock re-adds all previously removed elements and re-throws. WhenRemoveRange(new[] { c1, c2, null })is called:Remove(c1)succeeds,Remove(c2)succeeds (i=2, collection empty)Remove(null)throwsArgumentNullException- The
catchblock should re-addc1andc2, restoring count to 2
Under R2R compilation, the collection ends up with 0 elements, meaning the
catchblock either does not execute or does not successfully re-add. This strongly suggests a crossgen2/R2R codegen issue with try-catch-rethrow exception handling.This has been persistent across 15+ consecutive failures and 4 predecessor KBEs (#129210, #128993, #128815, #128538) that were all closed without a fix.
Evidence
- Failing build: https://dev.azure.com/dnceng-public/public/_build/results?buildId=1467809
- First build it occurred: persistent across entire scanned window (may predate 2026-06-04)
- Confirmed in follow-up: https://dev.azure.com/dnceng-public/public/_build/results?buildId=1470164 (2026-06-18)
- Possible related PR: none identified with sufficient confidence — appears to be a pre-existing R2R exception handling bug
Suggested reviewers / area contacts
- Area owners (
area-crossgen2-coreclr):@dotnet/crossgen-contrib - Lead:
@agocke
The fix would likely involve investigating how crossgen2 R2R compiles the try-catch-rethrow pattern in
RemoveRange, specifically whether the catch block's variable capture (the loop counteri) and control flow are correct in the R2R-compiled output.
Filed by
ci-failure-fix, which attempts validated fixes for[ci-scan]Known Build Errors and otherwise loops in owners. Comment here or on the workflow file to suggest changes;ci-failure-scan-feedbackreads in-scope feedback daily and opens (or updates) a PR with prompt edits.Note
🔒 Integrity filter blocked 2 items
The following items were blocked because they don't meet the GitHub integrity level.
- #128501
search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved". - [ci-scan] Test failure: CryptoStreamTests.ReadWrite_Success MemberData not found on maccatalyst #128451
issue_read: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
To allow these resources, lower
min-integrityin your GitHub frontmatter:tools: github: min-integrity: approved # merged | approved | unapproved | none
Generated by CI Outer-Loop Failure Fixer · ● 17.2M · ◷
- added and removedarea-crossgen2-coreclronly use for closed issuesonly use for closed issues
on Jun 22, 2026 Duplicate of #128392 which is closed.
- removeduntriagedNew issue has not been triaged by the area ownerNew issue has not been triaged by the area owner
on Jun 29, 2026 - locked and limited conversation to collaborators
on Jul 30, 2026
Metadata
Metadata
Assignees
Labels
Type
Projects
- StatusShow more project fieldsNo status
Build Information
Build: https://dev.azure.com/dnceng-public/public/_build/results?buildId=1467809
Build error leg or test failing: linux-x64 Release TestReadyToRun_Libraries - System.Security.Cryptography.Tests
Error Details
CollectionTests.X509Certificate2CollectionRemoveRangeArrayfails under R2R/crossgen2. The test callsRemoveRangeon anX509Certificate2Collectionand expects 2 certificates to remain, but finds 0.Prior KBEs #129210, #128993, #128815, and #128538 were filed and closed, but the failure persists.
Affected legs:
First build it occurred:
Predecessor: #129210 (closed 2026-06-16 as not_planned; source build finished after closure)
Related: #128993, #128815, #128538
Error Message
{ "ErrorMessage": ["X509Certificate2CollectionRemoveRangeArray", "Assert.Equal() Failure: Values differ", "Expected: 2", "Actual: 0"], "ErrorPattern": "", "BuildRetry": false, "ExcludeConsoleLog": false }Filed by
ci-failure-scan(detection only).ci-failure-fixwalks open[ci-scan]KBEs and either opens a small fix PR or comments here to loop in owners — it never disables the test.Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
dotnet.github.ioSee Network Configuration for more information.
Note
🔒 Integrity filter blocked 1 item
The following item was blocked because it doesn't meet the GitHub integrity level.
search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".To allow these resources, lower
min-integrityin your GitHub frontmatter:Report
Summary