Skip to content

Enable Unix domain sockets on iOS and tvOS - #135167

Open
shatanov wants to merge 7 commits into
dotnet:mainfrom
shatanov:fix-96143-apple-unix-domain-sockets
Open

shatanov wants to merge 7 commits into
dotnet:mainfrom
shatanov:fix-96143-apple-unix-domain-sockets

Conversation

@shatanov

@shatanov shatanov commented Oct 3, 2026 •

Copy link
Copy Markdown

UnixDomainSocketEndPoint throws PlatformNotSupportedException on iOS and tvOS because SocketProtocolSupportPal unconditionally reports AF_UNIX as unsupported. This prevents applications from using Unix domain sockets even at paths permitted by the Apple sandbox.

Remove the iOS/tvOS exclusion and use the existing native socket probe. The explicit WASI exclusion remains.

Restore the address family from getsockname when Socket(SafeSocketHandle) cannot query it directly. Apple simulator functional CI exposed this missing fallback: Unix socket clones had unknown families, null endpoints, and Connected == false.

Add an ungated iOS/tvOS regression test for support, socket and endpoint construction, and address-family reconstruction from SafeHandle without binding. Strengthen the existing connected clone test with family and endpoint assertions.

Adapt socket and HTTP ConnectCallback tests to Apple app containers with short names and the shorter UTF-8 representation of the absolute or relative temporary directory. Share this directory selection between the two suites. HTTP client and server use the same directory, and the HTTP identifier starts with a letter to avoid numeric URI-host normalization.

Tests requiring successful filesystem binding use the cached PlatformDetection.SupportsUnixDomainSocketBinding condition in their ConditionalFact/Theory attributes. On iOS/tvOS this probes the shared socket directory once and reports binding as unavailable only when Bind returns AccessDenied. Other bind errors remain visible. Socket construction, endpoint validation, equality, negative tests, and the Linux abstract-address case remain independent of this permission check. Fix nullable server cleanup so it cannot mask failed setup.

Validation

  • git diff --check: passed.
  • Local Linux arm64 build of the modified sources passed in the official dotnet-buildtools/prereqs:ubuntu-24.04-arm64v8 container: ./build.sh mono+libs -rc Release -arch arm64 /p:RestoreConfigFile=/work/runtime/NuGet.config (Release Mono runtime, Debug libraries).
  • UnixDomainSocketTest: 21 passed, 0 failed, 0 skipped on Mono JIT; 21 passed, 0 failed, 0 skipped on Mono Interpreter. Both runs include Socket_SendReceive_Clone_Success.
  • ConnectCallback_UseUnixDomainSocket_Success: 4 passed, 0 failed, 0 skipped on each of Mono JIT and Interpreter, covering HTTP/1.1 and HTTP/2 with and without TLS. Used /p:WithCategories=failing to explicitly include the HTTP assembly, which is excluded by default on Linux/Mono under the existing assembly-level ActiveIssue for System.Net.*.Tests are unstable or slow/long-running on a S.P.CoreLib checked runtime #131. The tests themselves were unchanged for local execution.
  • Rebuilt both test projects and reran the four focused Linux test runs after the cached-condition refactor in 054c7c90a. TestUtilities also builds successfully for net472, with 0 warnings and 0 errors.
  • Apple functional CI at 75f6cb8c87760cd57ef90e2e5335917142a0bc15: CoreCLR UnixDomainSocketTest has 21 passed / 1 skipped / 0 failed on both iOS Simulator x64 and iOS Simulator arm64, including the connected-clone and unbound Apple regression tests. tvOS has 7 passed / 15 skipped / 0 failed: the unbound Apple regression passes; filesystem-bind cases are skipped because the sandbox denies Bind.
  • The full Apple pipelines still have failures: runtime-ioslike 1626149 reports missing OpenSSL native library, JIT/runtime failures, and app launch/execution timeouts; runtime-ioslikesimulator 1626150 has JIT/runtime failures and a Helix monitoring timeout. The successful socket results above predate 054c7c90a; Apple validation of the cached-condition refactor is still pending.
  • Local macOS arm64 baseline could not complete ILCompiler publishing because full Xcode and Swift libraries are unavailable; no local device or simulator tests were executed.

Resolves #96143

Remove the blanket Apple restriction so the existing native socket probe
can detect AF_UNIX support on iOS and tvOS. Keep the WASI exclusion.

Add independently gated regression coverage and shorten socket paths in
newly enabled tests, including paths in simulator app containers.

Fix dotnet#96143
@dotnet-policy-service dotnet-policy-service Bot added the community-contribution Indicates that the PR has been added by a community member label Oct 3, 2026
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 4 pipeline(s).
12 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @karelz, @dotnet/ncl
See info in area-owners.md if you want to be subscribed.

@shatanov

shatanov commented Oct 3, 2026

Copy link
Copy Markdown
Author

@dotnet-policy-service agree

@shatanov
shatanov marked this pull request as ready for review October 4, 2026 07:25
@shatanov

shatanov commented Oct 4, 2026

Copy link
Copy Markdown
Author

/azp run runtime-ioslike

@azure-pipelines

Copy link
Copy Markdown
Commenter does not have sufficient privileges for PR 135167 in repo dotnet/runtime

@shatanov

shatanov commented Oct 4, 2026

Copy link
Copy Markdown
Author

/azp run runtime-ioslikesimulator

@azure-pipelines

Copy link
Copy Markdown
Commenter does not have sufficient privileges for PR 135167 in repo dotnet/runtime

@shatanov

shatanov commented Oct 5, 2026

Copy link
Copy Markdown
Author

@kotlarmilos Could you please review the iOS/tvOS changes in this PR and help run the runtime-ioslike and runtime-ioslikesimulator pipelines?

@wfurt

wfurt commented Oct 6, 2026

Copy link
Copy Markdown
Member

/azp run runtime-ioslike

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

@wfurt

wfurt commented Oct 6, 2026

Copy link
Copy Markdown
Member

/azp run runtime-ioslikesimulator

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

@shatanov

shatanov commented Oct 6, 2026 •

Copy link
Copy Markdown
Author

@wfurt @dotnet/ncl Could you please review this fix for #96143?

The follow-up fixes address Unix socket cloning via SafeHandle, Apple sandbox-denied filesystem bindings in the tests, and the SkipTestException namespace import. The latest commit is 75f6cb8.

Local Linux arm64 validation passed on both Mono JIT and Mono Interpreter: 21 UnixDomainSocketTest cases and 4 ConnectCallback_UseUnixDomainSocket_Success cases per mode, with no failures or skips. The three previously failing Mono build checks now pass.

Could you also rerun runtime-ioslike and runtime-ioslikesimulator on the latest commit to validate the Apple-specific behavior? Thank you.

@rzikm

rzikm commented Oct 7, 2026

Copy link
Copy Markdown
Member

/azp run runtime-ioslike

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

@rzikm

rzikm commented Oct 7, 2026

Copy link
Copy Markdown
Member

/azp run runtime-ioslikesimulator

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

Comment thread src/libraries/System.Net.Http/tests/FunctionalTests/SocketsHttpHandlerTest.cs Outdated
Comment on lines +154 to +158
if (_addressFamily == AddressFamily.Unknown)
{
_addressFamily = SocketAddressPal.GetAddressFamily(buffer.Slice(0, bufferLength));
}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

How can this happen? does not LoadSocketTypeFromHandle call above lookup the address family from the handle?

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LoadSocketTypeFromHandle does attempt to obtain the family, but its native implementation can succeed while returning AddressFamily.Unknown.

The relevant path is SystemNative_GetSocketType:

  • With HAVE_SYS_PROCINFO_H, it uses proc_pidfdinfo to read soi_family.
  • Otherwise, it queries the domain only if SO_DOMAIN is available. If that option is absent, the query fails, or the value cannot be converted, it sets AddressFamily_AF_UNKNOWN. It still returns Error_SUCCESS after collecting the remaining socket properties.

The iOS Simulator and tvOS product-build logs from 1626150 and 1626149 explicitly report Looking for include file sys/proc_info.h - not found, confirming those builds use the latter branch. I have not instrumented the native call to distinguish an absent SO_DOMAIN from a failed query on the original failing run; the important contract here is that success does not guarantee a known family.

The constructor already calls GetSockName immediately afterward. This change recovers the family from that returned sockaddr only when _addressFamily is Unknown, before the endpoint switch, without adding another native call. Previously, an unknown family bypassed the Unix endpoint case, leaving _rightEndPoint unset and preventing the subsequent peer lookup from establishing Connected. That matches the connected-clone failure seen in the earlier simulator run.

There is now Apple CI coverage at 75f6cb8: Socket_SendReceive_Clone_Success and the unbound Socket_OSSupportsUnixDomainSockets_OnAppleMobile regression both pass on iOS Simulator x64 and arm64. On tvOS, the unbound regression passes; the connected-clone test is skipped because the sandbox denies filesystem binding. The full Apple pipelines still have failures and timeouts outside these socket tests. The new test-condition refactor in 054c7c9 needs a fresh Apple run; the constructor change is unchanged.

@wfurt

wfurt commented Oct 7, 2026

Copy link
Copy Markdown
Member

The change looks reasonable to me. But it would still be nice to get some feedback from the platform folks....

Use a lazy PlatformDetection property in conditional attributes so the
Apple sandbox bind probe runs once. Share the selected socket directory
and keep Linux abstract-address coverage independent of filesystem binds.
@rzikm rzikm added the os-tvos Apple tvOS label Oct 8, 2026
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to 'os-tvos': @vitek-karas, @kotlarmilos, @steveisok, @akoeplinger
See info in area-owners.md if you want to be subscribed.

@akoeplinger

Copy link
Copy Markdown
Member

looks reasonable to me as well. we should just make sure the new tests actually run :)

@shatanov

shatanov commented Oct 9, 2026

Copy link
Copy Markdown
Author

@akoeplinger, thanks for taking a look. Could you please run runtime-ioslike and runtime-ioslikesimulator on the current head, e9b1e34?

The filesystem-bind probe now uses a cached PlatformDetection property in the ConditionalFact/Theory attributes, so we still need Apple validation of that change. The unbound Socket_OSSupportsUnixDomainSockets_OnAppleMobile regression remains independent of the bind condition.

The earlier Apple run at 75f6cb8 passed the unbound regression on tvOS and both iOS Simulator architectures, and the connected-clone test on both simulators; tvOS filesystem-bind tests were skipped because its sandbox denied binding. After the refactor, all 21 Unix-domain socket cases and 4 HTTP ConnectCallback cases passed locally on each of Linux arm64 Mono JIT and Interpreter.

The new runs should let us confirm the actual execution and skip results for the Apple regression, connected-clone, and HTTP Unix-domain socket tests on the current code.

@wfurt

wfurt commented Oct 9, 2026

Copy link
Copy Markdown
Member

/azp run runtime-ioslikesimulator

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

@wfurt

wfurt commented Oct 9, 2026

Copy link
Copy Markdown
Member

/azp run runtime-ioslike

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-System.Net.Sockets community-contribution Indicates that the PR has been added by a community member os-tvos Apple tvOS

Projects

None yet

Development

Successfully merging this pull request may close these issues.

UnixDomainSocketEndPoint no longer constructable on iOS (.NET 8)

4 participants