Skip to content

[ci-scan] Test failure: X509Certificate2CollectionRemoveRangeArray under crossgen2 R2R (recurrence) #129576

Description

@github-actions

Build Information

Build: https://dev.azure.com/dnceng-public/public/_build/results?buildId=1467809
Build error leg or test failing: linux-x64 Release TestReadyToRun_Libraries - System.Security.Cryptography.Tests

Error Details

CollectionTests.X509Certificate2CollectionRemoveRangeArray fails under R2R/crossgen2. The test calls RemoveRange on an X509Certificate2Collection and expects 2 certificates to remain, but finds 0.

Prior KBEs #129210, #128993, #128815, and #128538 were filed and closed, but the failure persists.

[FAIL] System.Security.Cryptography.X509Certificates.Tests.CollectionTests.X509Certificate2CollectionRemoveRangeArray
Assert.Equal() Failure: Values differ
Expected: 2
Actual:   0
   at System.Security.Cryptography.X509Certificates.Tests.CollectionTests.X509Certificate2CollectionRemoveRangeArray()
   in /_/src/libraries/System.Security.Cryptography/tests/X509Certificates/CollectionTests.cs:line 1037

Affected legs:

  • runtime-coreclr crossgen2 (def 124): linux-x64 Release TestReadyToRun_Libraries
  • runtime-coreclr crossgen2 (def 124): windows-x64 Release TestReadyToRun_Libraries
  • runtime-coreclr crossgen2 (def 124): osx-x64 Release TestReadyToRun_Libraries

First build it occurred:

Predecessor: #129210 (closed 2026-06-16 as not_planned; source build finished after closure)
Related: #128993, #128815, #128538

Error Message

{
  "ErrorMessage": ["X509Certificate2CollectionRemoveRangeArray", "Assert.Equal() Failure: Values differ", "Expected: 2", "Actual:   0"],
  "ErrorPattern": "",
  "BuildRetry": false,
  "ExcludeConsoleLog": false
}

Filed by ci-failure-scan (detection only). ci-failure-fix walks open [ci-scan] KBEs and either opens a small fix PR or comments here to loop in owners — it never disables the test.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • dotnet.github.io

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "dotnet.github.io"

See Network Configuration for more information.

Note

🔒 Integrity filter blocked 1 item

The following item was blocked because it doesn't meet the GitHub integrity level.

  • #101522 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".

To allow these resources, lower min-integrity in your GitHub frontmatter:

tools:
  github:
    min-integrity: approved  # merged | approved | unapproved | none

Generated by CI Outer-Loop Failure Scanner · ● 50.8M · ◷

Report

Build Repository Test Pull Request
1472620 dotnet/runtime System.Security.Cryptography.X509Certificates.Tests.CollectionTests.X509Certificate2CollectionRemoveRangeArray #129589

Summary

24-Hour Hit Count 7-Day Hit Count 1-Month Count
0 0 1

Activity

  1. dotnet-policy-service commented on Jun 18, 2026

    @dotnet-policy-service
    Contributor

    Tagging subscribers to this area: @bartonjs, @vcsjones, @dotnet/area-system-security
    See info in area-owners.md if you want to be subscribed.

  2. github-actions commented on Jun 19, 2026

    @github-actions
    ContributorAuthor

    Workflow artifact: ci-fix
    Artifact kind: handoff
    Linked KBE: #129576

    Note

    AI/Copilot-generated triage note.

    This Known Build Error has no producible automated code change (reason: crossgen2/R2R codegen exception handling bug — the product code is correct and the fix requires changes to R2R compilation/exception dispatch, which exceeds automated bounds), so I could not open even a best-effort PR. Looping in owners so it can be fixed forward rather than muted.

    Root cause (best analysis)

    X509Certificate2CollectionRemoveRangeArray (at CollectionTests.cs:1037) consistently fails under crossgen2 R2R compilation on all three platforms (linux-x64, windows-x64, osx-x64). The assertion Assert.Equal(2, cc.Count) gets 0 instead.

    The product code in X509Certificate2Collection.RemoveRange(X509Certificate2[]) (line 342–362) is correct: it removes elements in a try block, and if any removal throws, the catch block re-adds all previously removed elements and re-throws. When RemoveRange(new[] { c1, c2, null }) is called:

    1. Remove(c1) succeeds, Remove(c2) succeeds (i=2, collection empty)
    2. Remove(null) throws ArgumentNullException
    3. The catch block should re-add c1 and c2, restoring count to 2

    Under R2R compilation, the collection ends up with 0 elements, meaning the catch block either does not execute or does not successfully re-add. This strongly suggests a crossgen2/R2R codegen issue with try-catch-rethrow exception handling.

    This has been persistent across 15+ consecutive failures and 4 predecessor KBEs (#129210, #128993, #128815, #128538) that were all closed without a fix.

    Evidence

    Suggested reviewers / area contacts

    • Area owners (area-crossgen2-coreclr): @dotnet/crossgen-contrib
    • Lead: @agocke

    The fix would likely involve investigating how crossgen2 R2R compiles the try-catch-rethrow pattern in RemoveRange, specifically whether the catch block's variable capture (the loop counter i) and control flow are correct in the R2R-compiled output.


    Filed by ci-failure-fix, which attempts validated fixes for [ci-scan] Known Build Errors and otherwise loops in owners. Comment here or on the workflow file to suggest changes; ci-failure-scan-feedback reads in-scope feedback daily and opens (or updates) a PR with prompt edits.

    Note

    🔒 Integrity filter blocked 2 items

    The following items were blocked because they don't meet the GitHub integrity level.

    To allow these resources, lower min-integrity in your GitHub frontmatter:

    tools:
      github:
        min-integrity: approved  # merged | approved | unapproved | none

    Generated by CI Outer-Loop Failure Fixer · ● 17.2M · ◷

  3. jtschuster commented on Jun 29, 2026

    @jtschuster
    Member

    Duplicate of #128392 which is closed.

  4. locked and limited conversation to collaborators on Jul 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    • Status
      No status

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions