Skip to content

Pass TPA through host-runtime contract instead of property string - #132861

Merged
elinor-fung merged 20 commits into
dotnet:mainfrom
elinor-fung:host-contract-tpa
Oct 6, 2026
Merged

elinor-fung merged 20 commits into
dotnet:mainfrom
elinor-fung:host-contract-tpa

Conversation

@elinor-fung

@elinor-fung elinor-fung commented Aug 27, 2026 •

Copy link
Copy Markdown
Member

Pass trusted platform assemblies from the host to the runtime through host_runtime_contract callbacks instead of as a large string with path separators.

The host provides the resolved assembly names during initialization and the runtime requests each resolved path when needed. This reduces unnecessary parsing, reduces the amount we allocate as part of startup, and allows running applications with paths including a path separator.

The TRUSTED_PLATFORM_ASSEMBLIES property can still be explicitly queried (reconstructed on demand) and can still be explicitly supplied by custom hosts.

Resolves #3163
Resolves #75882
Resolves #104402

cc @dotnet/appmodel @AaronRobinsonMSFT

Windows x64, basic console app:

Metric Main Branch Delta
Startup, launch-level median 67.684 ms 66.831 ms -0.853 ms (-1.26%)
Native allocated bytes at live snapshot 10,131.65 KiB 9,593.95 KiB -537.70 KiB (-5.31%)
Live retained native bytes 1,955.30 KiB 1,871.10 KiB -84.20 KiB (-4.31%)

Startup was measured with the dotnet/performance TimeToMain2 ETW harness, from process start until a minimal console app emitted its first event. Native allocations were with the minimal app blocked on Console.ReadLine().

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: e234f49e-502f-4c6e-bacd-0971bb2033e7
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: e234f49e-502f-4c6e-bacd-0971bb2033e7
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: e234f49e-502f-4c6e-bacd-0971bb2033e7
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: e234f49e-502f-4c6e-bacd-0971bb2033e7
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: e234f49e-502f-4c6e-bacd-0971bb2033e7
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: e234f49e-502f-4c6e-bacd-0971bb2033e7
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: e234f49e-502f-4c6e-bacd-0971bb2033e7
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 11aa1554-f420-4cb0-91cb-1bba7ec51725
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 4 pipeline(s).
12 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

Comment thread src/coreclr/binder/applicationcontext.cpp
@elinor-fung
elinor-fung marked this pull request as ready for review September 2, 2026 20:29
Copilot AI lite review requested due to automatic review settings September 2, 2026 20:29
Comment thread src/coreclr/binder/applicationcontext.cpp
Comment thread src/coreclr/binder/applicationcontext.cpp
Comment thread src/coreclr/binder/applicationcontext.cpp
Comment thread src/coreclr/binder/applicationcontext.cpp
Comment thread src/coreclr/hosts/corerun/corerun.cpp Outdated
Comment thread src/coreclr/vm/hostinformation.cpp
Comment thread src/coreclr/vm/hostinformation.cpp Outdated
Comment thread src/mono/mono/mini/hostinformation.c
Copilot AI review requested due to automatic review settings September 3, 2026 18:44

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

There are merge-blocking correctness issues in CoreCLR binder allocation handling and in corerun’s get_assembly_names callback behavior that can cause crashes or unintended fallback paths.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Review tier: Lite
Findings: 1 Medium severity

New issues introduced by this change (1)
Severity Finding
Medium severity src/​coreclr/​hosts/​corerun/​corerun.cpp — get_assembly_names returns false when the host-resolved assembly list is empty. Per the…
Suppressed comments (2)

Previously missed (1) — in code that hasn't changed since the last review.

src/coreclr/binder/applicationcontext.cpp:111

  • wszSimpleName is allocated with plain new [] and used unconditionally. In the binder we generally use new (nothrow) + an explicit E_OUTOFMEMORY path (see SAFE_NEW in bindertypes.hpp); otherwise a failed allocation can lead to a null deref in wcscpy_s (and in builds without C++ exceptions, plain new may return null).

This issue also appears on line 134 of the same file.

src/coreclr/binder/applicationcontext.cpp:141

  • Same allocation issue here for both wszSimpleName and wszFileName: plain new [] is used with no failure handling. This can turn an OOM into a crash (or an unhandled exception, depending on the build configuration).
                LPWSTR wszSimpleName = new WCHAR[simpleName.GetCount() + 1];
                wcscpy_s(wszSimpleName, simpleName.GetCount() + 1, simpleName.GetUnicode());

                LPWSTR wszFileName = new WCHAR[fileName.GetCount() + 1];
                wcscpy_s(wszFileName, fileName.GetCount() + 1, fileName.GetUnicode());

                SimpleNameToFileNameMapEntry mapEntry{ wszSimpleName, wszFileName };
                m_pTrustedPlatformAssemblyMap->AddOrReplace(mapEntry);

Comment thread src/coreclr/hosts/corerun/corerun.cpp
Copilot AI review requested due to automatic review settings September 3, 2026 20:35

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

There are merge-blocking correctness issues in the updated binding/loader paths (notably missing allocation-failure checks in CoreCLR binder and a Mono preload-hook early-termination case) that should be fixed before approval.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Review tier: Lite
Findings: 3 Medium severity · 1 Low severity

New issues introduced by this change (4)
Severity Finding
Medium severity src/​coreclr/​binder/​applicationcontext.cpp — The TPA-name path uses new WCHAR[...] without any null/OOM check, but this function otherwise…
Medium severity src/​mono/​mono/​mini/​monovm.c — When using host-resolved TPA entries, failing to resolve a single assembly path currently breaks…
Medium severity src/​native/​corehost/​hostpolicy/​hostpolicy_context.cpp — name is derived by stripping only the last extension from the resolved path. This can produce a…
Low severity src/​installer/​tests/​HostActivation.Tests/​DependencyResolution/​DependencyResolutionCommandResultExtensions.cs — Splitting stderr with Split(Environment.NewLine) is brittle if the captured output uses different…
Issues resolved since last review (1)
Severity Finding
Medium severity src/​coreclr/​hosts/​corerun/​corerun.cpp — get_assembly_names returns false when the host-resolved assembly list is empty. Per the… View resolved comment
Suppressed comments (1)

src/coreclr/binder/applicationcontext.cpp:138

  • Same issue in the legacy TPA-property parsing path: wszSimpleName/wszFileName allocations no longer check for failure before wcscpy_s, despite this method using HRESULT-style control flow for OOM elsewhere.
                LPWSTR wszSimpleName = new WCHAR[simpleName.GetCount() + 1];
                wcscpy_s(wszSimpleName, simpleName.GetCount() + 1, simpleName.GetUnicode());

                LPWSTR wszFileName = new WCHAR[fileName.GetCount() + 1];
                wcscpy_s(wszFileName, fileName.GetCount() + 1, fileName.GetUnicode());

Comment thread src/coreclr/binder/applicationcontext.cpp
Comment thread src/mono/mono/mini/monovm.c
Comment thread src/native/corehost/hostpolicy/hostpolicy_context.cpp
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 4 pipeline(s).
12 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

Comment thread src/coreclr/binder/applicationcontext.cpp
@elinor-fung
elinor-fung merged commit c95e736 into dotnet:main Oct 6, 2026
177 of 180 checks passed
@github-project-automation github-project-automation Bot moved this to Done in AppModel Oct 6, 2026
@dotnet-milestone-bot dotnet-milestone-bot Bot added this to the 12.0-preview1 milestone Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

Status: Done

6 participants