Repository navigation
Pass TPA through host-runtime contract instead of property string - #132861
Conversation
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: e234f49e-502f-4c6e-bacd-0971bb2033e7
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: e234f49e-502f-4c6e-bacd-0971bb2033e7
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: e234f49e-502f-4c6e-bacd-0971bb2033e7
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: e234f49e-502f-4c6e-bacd-0971bb2033e7
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: e234f49e-502f-4c6e-bacd-0971bb2033e7
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: e234f49e-502f-4c6e-bacd-0971bb2033e7
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: e234f49e-502f-4c6e-bacd-0971bb2033e7
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 11aa1554-f420-4cb0-91cb-1bba7ec51725
|
Azure Pipelines: Successfully started running 4 pipeline(s). 12 pipeline(s) were filtered out due to trigger conditions. There may be pipelines that require an authorized user to comment /azp run to run. |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
There are merge-blocking correctness issues in CoreCLR binder allocation handling and in corerun’s get_assembly_names callback behavior that can cause crashes or unintended fallback paths.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Review tier: Lite
Findings: 1
New issues introduced by this change (1)
| Severity | Finding |
|---|---|
src/coreclr/hosts/corerun/corerun.cpp — get_assembly_names returns false when the host-resolved assembly list is empty. Per the… |
Suppressed comments (2)
Previously missed (1) — in code that hasn't changed since the last review.
src/coreclr/binder/applicationcontext.cpp:111
wszSimpleNameis allocated with plainnew []and used unconditionally. In the binder we generally usenew (nothrow)+ an explicitE_OUTOFMEMORYpath (see SAFE_NEW in bindertypes.hpp); otherwise a failed allocation can lead to a null deref inwcscpy_s(and in builds without C++ exceptions, plainnewmay return null).
This issue also appears on line 134 of the same file.
src/coreclr/binder/applicationcontext.cpp:141
- Same allocation issue here for both
wszSimpleNameandwszFileName: plainnew []is used with no failure handling. This can turn an OOM into a crash (or an unhandled exception, depending on the build configuration).
LPWSTR wszSimpleName = new WCHAR[simpleName.GetCount() + 1];
wcscpy_s(wszSimpleName, simpleName.GetCount() + 1, simpleName.GetUnicode());
LPWSTR wszFileName = new WCHAR[fileName.GetCount() + 1];
wcscpy_s(wszFileName, fileName.GetCount() + 1, fileName.GetUnicode());
SimpleNameToFileNameMapEntry mapEntry{ wszSimpleName, wszFileName };
m_pTrustedPlatformAssemblyMap->AddOrReplace(mapEntry);
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
There are merge-blocking correctness issues in the updated binding/loader paths (notably missing allocation-failure checks in CoreCLR binder and a Mono preload-hook early-termination case) that should be fixed before approval.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Review tier: Lite
Findings: 3
New issues introduced by this change (4)
| Severity | Finding |
|---|---|
src/coreclr/binder/applicationcontext.cpp — The TPA-name path uses new WCHAR[...] without any null/OOM check, but this function otherwise… |
|
src/mono/mono/mini/monovm.c — When using host-resolved TPA entries, failing to resolve a single assembly path currently breaks… |
|
src/native/corehost/hostpolicy/hostpolicy_context.cpp — name is derived by stripping only the last extension from the resolved path. This can produce a… |
|
src/installer/tests/HostActivation.Tests/DependencyResolution/DependencyResolutionCommandResultExtensions.cs — Splitting stderr with Split(Environment.NewLine) is brittle if the captured output uses different… |
Issues resolved since last review (1)
| Severity | Finding |
|---|---|
src/coreclr/hosts/corerun/corerun.cpp — get_assembly_names returns false when the host-resolved assembly list is empty. Per the… View resolved comment |
Suppressed comments (1)
src/coreclr/binder/applicationcontext.cpp:138
- Same issue in the legacy TPA-property parsing path:
wszSimpleName/wszFileNameallocations no longer check for failure beforewcscpy_s, despite this method using HRESULT-style control flow for OOM elsewhere.
LPWSTR wszSimpleName = new WCHAR[simpleName.GetCount() + 1];
wcscpy_s(wszSimpleName, simpleName.GetCount() + 1, simpleName.GetUnicode());
LPWSTR wszFileName = new WCHAR[fileName.GetCount() + 1];
wcscpy_s(wszFileName, fileName.GetCount() + 1, fileName.GetUnicode());
|
Azure Pipelines: Successfully started running 4 pipeline(s). 12 pipeline(s) were filtered out due to trigger conditions. There may be pipelines that require an authorized user to comment /azp run to run. |


Pass trusted platform assemblies from the host to the runtime through
host_runtime_contractcallbacks instead of as a large string with path separators.The host provides the resolved assembly names during initialization and the runtime requests each resolved path when needed. This reduces unnecessary parsing, reduces the amount we allocate as part of startup, and allows running applications with paths including a path separator.
The
TRUSTED_PLATFORM_ASSEMBLIESproperty can still be explicitly queried (reconstructed on demand) and can still be explicitly supplied by custom hosts.Resolves #3163
Resolves #75882
Resolves #104402
cc @dotnet/appmodel @AaronRobinsonMSFT
Windows x64, basic console app:
Startup was measured with the dotnet/performance
TimeToMain2ETW harness, from process start until a minimal console app emitted its first event. Native allocations were with the minimal app blocked onConsole.ReadLine().