Skip to content

Replace unsafe code with safe APIs in CoreLib and libraries - #134956

Merged
EgorBo merged 3 commits into
dotnet:mainfrom
EgorBo:reduce-unsafe-libraries
Oct 1, 2026
Merged

EgorBo merged 3 commits into
dotnet:mainfrom
EgorBo:reduce-unsafe-libraries

Conversation

@EgorBo

@EgorBo EgorBo commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Replace selected unsafe operations with safe span, indexing, and SIMD APIs in CoreLib and networking.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 508e84f0-bee1-48c3-809f-3dffe53a7703
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @dotnet/area-system-runtime
See info in area-owners.md if you want to be subscribed.

@EgorBo

EgorBo commented Sep 30, 2026

Copy link
Copy Markdown
Member Author

@MihuBot

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The StreamWriter and SharedArrayPool hot-path substitutions need benchmark evidence demonstrating that they do not restore known overhead.

Review effort: Balanced
Findings: 2 Medium severity

Open (2)
What changed in this PR

Replaces selected unsafe pointer/reference operations with safe span, indexing, endianness, and SIMD APIs across CoreLib, networking, and XML.

Changes:

  • Converts pointer-based buffer and string operations to spans and indexing.
  • Reworks SIMD/table accesses using safe vector and binary APIs.
  • Removes unsafe code from WebSocket masking and socket byte operations.

Two hot-path substitutions require performance validation before approval.

File Description
XmlCharType.cs Uses indexed character-property lookup.
UTF8Encoding.Sealed.cs Uses stack-allocated spans for small conversions.
String.Searching.cs Uses string span search APIs.
String.Manipulation.cs Converts trimming helper to ReadOnlySpan<char>.
StringSearchValuesHelper.cs Uses safe vector and scalar reads.
IndexOfAnyAsciiSearcher.cs Replaces pointer bitmap mutation with vector APIs.
BitmapCharSearchValues.cs Uses span-based iteration.
StreamWriter.cs Replaces pointer copying with span copying.
CharUnicodeInfo.cs Uses indexed and endian-aware table reads.
SharedArrayPool.cs Replaces indirect reference storage with array indexing.
BinaryPrimitives.ReverseEndianness.cs Uses span-based vector loads and stores.
BitConverter.cs Uses direct byte indexing for Boolean conversion.
ManagedWebSocket.cs Implements masking with safe scalar and vector APIs.
NetworkStream.cs Uses single-element spans for byte operations.

Comment thread src/libraries/System.Private.CoreLib/src/System/Buffers/SharedArrayPool.cs Outdated
Comment thread src/libraries/System.Private.CoreLib/src/System/IO/StreamWriter.cs Outdated
EgorBo and others added 2 commits September 30, 2026 18:43
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 508e84f0-bee1-48c3-809f-3dffe53a7703
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 508e84f0-bee1-48c3-809f-3dffe53a7703
@EgorBo

EgorBo commented Sep 30, 2026

Copy link
Copy Markdown
Member Author

@MihuBot

@EgorBo
EgorBo marked this pull request as ready for review September 30, 2026 18:32
@EgorBo

EgorBo commented Sep 30, 2026

Copy link
Copy Markdown
Member Author

@MihaZupan the current subset seems to be bound check free (only some minor extra instructions or heavier encodings)

@EgorBo
EgorBo requested a review from MihaZupan September 30, 2026 18:34
while (--searchSpaceLength >= 0)
{
char c = Unsafe.Add(ref searchSpace, searchSpaceLength);
char c = span[searchSpaceLength];

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this will add an extra bounds check in the loop
https://godbolt.org/z/n9a99Tjn1

@EgorBo EgorBo Sep 30, 2026 •

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

hm.. let me see if it's fixable in JIT. The loop looks trivial enough

@EgorBo EgorBo Oct 1, 2026 •

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@MihaZupan it seems like it's more or less trivial to remove in jit, will do there 🙂 #135008

@EgorBo
EgorBo merged commit ca53699 into dotnet:main Oct 1, 2026
141 of 143 checks passed
@EgorBo
EgorBo deleted the reduce-unsafe-libraries branch October 1, 2026 10:34
@dotnet-milestone-bot dotnet-milestone-bot Bot added this to the 12.0-preview1 milestone Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants