Skip to content

NegotiateAuthentication larger code size and also brings in BigInteger #90898

Description

@NinoFloris

Afaik the following PR #87930 is part of .NET 8.0 preview 7, it caused a 60kb size regression for us:

preview 6: https://github.com/npgsql/npgsql/actions/runs/5930686472
preview 7: https://github.com/npgsql/npgsql/actions/runs/5931742857

Mostly due to it bringing in BigInteger (and a managed NegotiateAuthentication impl?)

Not sure what we can or want to do here.

/cc @filipnavara

Screenshot 2023-08-22 at 00 04 06

Activity

  1. ghost added
    needs-area-labelAn area label is needed to ensure this gets routed to the appropriate area owners
    on Aug 21, 2023
  2. ghost added
    untriagedNew issue has not been triaged by the area owner
    on Aug 21, 2023
  3. added and removed
    needs-area-labelAn area label is needed to ensure this gets routed to the appropriate area owners
    on Aug 21, 2023
  4. wfurt commented on Aug 22, 2023

    @wfurt
    Member

    what platforms is this on @NinoFloris? I think we do want to keep the managed implementation in. We can perhaps try to make it more trimming friendly.

  5. NinoFloris commented on Aug 22, 2023

    @NinoFloris
    ContributorAuthor

    These builds were done on ubuntu

  6. filipnavara commented on Aug 22, 2023

    @filipnavara
    Member

    It should be trimmed out on Linux for NativeAOT unless the UseManagedNtlm option is turned on. I'll have a look.

  7. filipnavara commented on Aug 22, 2023

    @filipnavara
    Member

    Can you try adding this to the test app .csproj?

    <ItemGroup>
      <RuntimeHostConfigurationOption Include="System.Net.Security.UseManagedNtlm" Value="false" Trim="true" />
    </ItemGroup>

    Generally the idea is that the ILLink substitution (https://github.com/dotnet/runtime/blob/main/src/libraries/System.Net.Security/src/ILLink/ILLink.Substitutions.xml) will turn System.Net.NegotiateAuthenticationPal.UseManagedNtlm into false and trim away the rest of the code. There are two possible failures that I can think of: 1) the substitution not taking place when the feature option is not specified at all, and 2) the resulting branch trimming not happening.

    UPD: Apparently this doesn't help. :-/
    UPD2: It does actually work, I just forgot to add Trim="true".

  8. filipnavara commented on Aug 22, 2023

    @filipnavara
    Member

    I reread the ILLink documentation and it seems we are missing featuredefault="true" attribute there. On .NET 9 we would need to conditionally use different substitution for macOS/iOS though.

  9. NinoFloris commented on Aug 22, 2023

    @NinoFloris
    ContributorAuthor

    Does that mean it should be fixed for rc2 or where do we stand? Npgsql is a library, I can't ask people to flip these switches for us.

  10. filipnavara commented on Aug 22, 2023

    @filipnavara
    Member

    I will try to submit the fix and then we can see about backports.

  11. filipnavara commented on Aug 22, 2023

    @filipnavara
    Member

    I was not able to get featuredefault to do the right thing on NativeAOT yet. I'm trying to figure out whether it is supposed to work, or not. The alternative is to specify the option through RuntimeHostConfigurationOption in the NativeAOT build integration. I'll post once I have more details to share.

  12. ghost added
    in-prThere is an active PR which will close this issue when it is merged
    on Aug 22, 2023
  13. added this to the 9.0.0 milestone on Aug 29, 2023
  14. removed their assignment
    on Aug 29, 2023
  15. ghost removed
    untriagedNew issue has not been triaged by the area owner
    on Aug 29, 2023
  16. karelz commented on Aug 29, 2023

    @karelz
    Member

    Triage: @wfurt discussed it with @jkotas and his suggestion was to NOT take it for 8.0 as it is size improvement, but not functional impact.
    @NinoFloris are you ok with that for npgsql customers? (cc @roji)

  17. filipnavara commented on Aug 29, 2023

    @filipnavara
    Member

    I generally agree it doesn't meet the bar for 8.0 servicing, but should we try to backport the SDK switch (dotnet/sdk#34903) to make the workaround easier?

  18. ghost removed
    in-prThere is an active PR which will close this issue when it is merged
    on Aug 29, 2023
  19. NinoFloris commented on Aug 29, 2023

    @NinoFloris
    ContributorAuthor

    Thanks, @karelz we are. We have added an explicit opt-in to our slim builder for "integrated security" auth, sidestepping the issue.

  20. added
    size-reductionIssues impacting final app size primary for size sensitive workloads
    on Aug 29, 2023
  21. roji commented on Aug 29, 2023

    @roji
    Member

    Yeah, agreed this isn't critical for a 8.0 backport.

  22. ghost locked as resolved and limited conversation to collaborators on Sep 29, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions