Skip to content

[Android arm32] System.Security.Cryptography.Pkcs.Tests crashes in HmacCreate #131856

Description

@matouskozak

Build Information

Build: 20260803.2

Build error leg or test failing: android-arm Release AllSubsets_CoreCLR - System.Security.Cryptography.Pkcs.Tests

Error Details

The Android arm32 test process crashes while Pkcs12InfoTests.ReadEmptyPfx(Int32) verifies a PKCS#12 MAC. XHarness reports exit code 80 (APP_CRASH).

Fatal error.
Got a SIGSEGV while executing native code. This usually indicates
a fatal error in the runtime or one of the native libraries
used by your application.
   at Interop+Crypto.<HmacCreate>g____PInvoke|96_0(Byte*, Int32, IntPtr)
   at System.Security.Cryptography.HMACCommon.ChangeKeyImpl(System.ReadOnlySpan`1<Byte>)
   at System.Security.Cryptography.IncrementalHash.CreateHMAC(System.Security.Cryptography.HashAlgorithmName, System.ReadOnlySpan`1<Byte>)
   at System.Security.Cryptography.Asn1.Pkcs12.PfxAsn.VerifyMac(System.ReadOnlySpan`1<Char>, System.ReadOnlySpan`1<Byte>)
   at System.Security.Cryptography.Pkcs.Pkcs12Info.VerifyMac(System.ReadOnlySpan`1<Char>)
   at System.Security.Cryptography.Pkcs.Pkcs12Info.VerifyMac(System.String)
   at System.Security.Cryptography.Pkcs.Tests.Pkcs12.Pkcs12InfoTests.ReadEmptyPfx(Int32)

XHarness exit code: 80 (APP_CRASH)

Error Message

{
  "ErrorMessage": [
    "Got a SIGSEGV while executing native code.",
    "at Interop+Crypto.<HmacCreate>",
    "at System.Security.Cryptography.Pkcs.Tests.Pkcs12.Pkcs12InfoTests.ReadEmptyPfx(Int32)"
  ],
  "BuildRetry": false,
  "ExcludeConsoleLog": false
}

Duplicate Search

No existing issue was found for this HmacCreate / ReadEmptyPfx Android SIGSEGV signature. #37094 is a closed historical issue for different PKCS failures on Android.

Note

This issue was drafted with GitHub Copilot assistance.

Known issue validation

Build: 🔎 https://dev.azure.com/dnceng-public/public/_build/results?buildId=1538577
Error message validated: [Got a SIGSEGV while executing native code. at Interop+Crypto.<HmacCreate> at System.Security.Cryptography.Pkcs.Tests.Pkcs12.Pkcs12InfoTests.ReadEmptyPfx(Int32)]
Result validation: ✅ Known issue matched with the provided build.
Validation performed at: 8/5/2026 6:51:18 AM UTC

Report

Build Repository Test Pull Request
1624231 dotnet/runtime System.Security.Cryptography.Pkcs.Tests.WorkItemExecution
1615485 dotnet/runtime System.Security.Cryptography.Pkcs.Tests.WorkItemExecution #134819

Summary

24-Hour Hit Count 7-Day Hit Count 1-Month Count
0 1 2

Activity

  1. dotnet-policy-service commented on Aug 5, 2026

    @dotnet-policy-service
    Contributor

    Tagging subscribers to 'arch-android': @vitek-karas, @simonrozsival, @steveisok, @akoeplinger
    See info in area-owners.md if you want to be subscribed.

  2. dotnet-policy-service commented on Aug 5, 2026

    @dotnet-policy-service
    Contributor

    Tagging subscribers to this area: @bartonjs, @vcsjones, @dotnet/area-system-security
    See info in area-owners.md if you want to be subscribed.

  3. self-assigned this
    on Aug 5, 2026
  4. vcsjones commented on Aug 5, 2026

    @vcsjones
    Member

    Posting what Copilot makes of the crash:

    Conclusion: We can pinpoint the immediate crash mechanism, but not why ART reaches that invalid entrypoint.

    1. Crash mechanism
    • XHarness reports exit  80  ( APP_CRASH ); Android reports  SIGSEGV ,  SEGV_ACCERR .

    • ART attempts to execute  QuickImtConflictTrampoline  from a  boot.oat  mapping that is  rw- , not executable.

    • Native stack is identical in both occurrences:

      /system/framework/arm/boot.oat   QuickImtConflictTrampoline
      /memfd:jit-cache                 javax.crypto.Mac.getInstance+136
      libart.so                        CallStaticObjectMethod...
      libSystem.Security...Android.so  CryptoNative_HmacCreate+332
      

    This occurs while  CryptoNative_HmacCreate  calls Java  Mac.getInstance .

    1. Strongest indicator
    • This looks most like an ART 32-bit JIT/dispatch problem, although that is not proven.  Mac.getInstance  has been ART-JIT-compiled, then dispatches through an IMT trampoline pointing into non-executable memory.
    • Both failures have the same ART and  boot.oat  build IDs, offsets, test ordering, and stack—even though they occurred on two different Pixel 6a devices, different Android monthly builds, and different runtime builds.
    • There is no LMK/OOM evidence in either log. The process exited from  SIGSEGV , not an OOM kill.
    • Memory pressure still cannot be excluded as a trigger, especially 32-bit virtual-address pressure or state left by the preceding deeply nested PFX tests.
  5. BrzVlad commented on Aug 10, 2026

    @BrzVlad
    Member

    @vcsjones Are you targeting .net 11 fix for this ? So we can triage it accordingly

  6. added this to the 12.0.0 milestone on Aug 13, 2026
  7. removed
    untriagedNew issue has not been triaged by the area owner
    on Aug 13, 2026
  8. removed
    blocking-clean-ciBlocking PR or rolling runs of 'runtime' or 'runtime-extra-platforms'
    on Sep 17, 2026
  9. jeffschwMSFT commented on Sep 17, 2026

    @jeffschwMSFT
    Member

    removing blocking-clean-ci as it has not failed in 30 days

    24-Hour Hit Count 7-Day Hit Count 1-Month Count
    0 0 0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions