Repository navigation
Conversation
Remove the blanket Apple restriction so the existing native socket probe can detect AF_UNIX support on iOS and tvOS. Keep the WASI exclusion. Add independently gated regression coverage and shorten socket paths in newly enabled tests, including paths in simulator app containers. Fix dotnet#96143
|
Azure Pipelines: Successfully started running 4 pipeline(s). 12 pipeline(s) were filtered out due to trigger conditions. There may be pipelines that require an authorized user to comment /azp run to run. |
|
Tagging subscribers to this area: @karelz, @dotnet/ncl |
|
@dotnet-policy-service agree |
|
/azp run runtime-ioslike |
|
Commenter does not have sufficient privileges for PR 135167 in repo dotnet/runtime |
|
/azp run runtime-ioslikesimulator |
|
Commenter does not have sufficient privileges for PR 135167 in repo dotnet/runtime |
|
@kotlarmilos Could you please review the iOS/tvOS changes in this PR and help run the |
|
/azp run runtime-ioslike |
|
Azure Pipelines: Successfully started running 1 pipeline(s). |
|
/azp run runtime-ioslikesimulator |
|
Azure Pipelines: Successfully started running 1 pipeline(s). |
|
@wfurt @dotnet/ncl Could you please review this fix for #96143? The follow-up fixes address Unix socket cloning via SafeHandle, Apple sandbox-denied filesystem bindings in the tests, and the SkipTestException namespace import. The latest commit is 75f6cb8. Local Linux arm64 validation passed on both Mono JIT and Mono Interpreter: 21 UnixDomainSocketTest cases and 4 ConnectCallback_UseUnixDomainSocket_Success cases per mode, with no failures or skips. The three previously failing Mono build checks now pass. Could you also rerun runtime-ioslike and runtime-ioslikesimulator on the latest commit to validate the Apple-specific behavior? Thank you. |
|
/azp run runtime-ioslike |
|
Azure Pipelines: Successfully started running 1 pipeline(s). |
|
/azp run runtime-ioslikesimulator |
|
Azure Pipelines: Successfully started running 1 pipeline(s). |
| if (_addressFamily == AddressFamily.Unknown) | ||
| { | ||
| _addressFamily = SocketAddressPal.GetAddressFamily(buffer.Slice(0, bufferLength)); | ||
| } | ||
|
|
There was a problem hiding this comment.
How can this happen? does not LoadSocketTypeFromHandle call above lookup the address family from the handle?
There was a problem hiding this comment.
LoadSocketTypeFromHandle does attempt to obtain the family, but its native implementation can succeed while returning AddressFamily.Unknown.
The relevant path is SystemNative_GetSocketType:
- With
HAVE_SYS_PROCINFO_H, it usesproc_pidfdinfoto readsoi_family. - Otherwise, it queries the domain only if
SO_DOMAINis available. If that option is absent, the query fails, or the value cannot be converted, it setsAddressFamily_AF_UNKNOWN. It still returnsError_SUCCESSafter collecting the remaining socket properties.
The iOS Simulator and tvOS product-build logs from 1626150 and 1626149 explicitly report Looking for include file sys/proc_info.h - not found, confirming those builds use the latter branch. I have not instrumented the native call to distinguish an absent SO_DOMAIN from a failed query on the original failing run; the important contract here is that success does not guarantee a known family.
The constructor already calls GetSockName immediately afterward. This change recovers the family from that returned sockaddr only when _addressFamily is Unknown, before the endpoint switch, without adding another native call. Previously, an unknown family bypassed the Unix endpoint case, leaving _rightEndPoint unset and preventing the subsequent peer lookup from establishing Connected. That matches the connected-clone failure seen in the earlier simulator run.
There is now Apple CI coverage at 75f6cb8: Socket_SendReceive_Clone_Success and the unbound Socket_OSSupportsUnixDomainSockets_OnAppleMobile regression both pass on iOS Simulator x64 and arm64. On tvOS, the unbound regression passes; the connected-clone test is skipped because the sandbox denies filesystem binding. The full Apple pipelines still have failures and timeouts outside these socket tests. The new test-condition refactor in 054c7c9 needs a fresh Apple run; the constructor change is unchanged.
|
The change looks reasonable to me. But it would still be nice to get some feedback from the platform folks.... |
Use a lazy PlatformDetection property in conditional attributes so the Apple sandbox bind probe runs once. Share the selected socket directory and keep Linux abstract-address coverage independent of filesystem binds.
|
Tagging subscribers to 'os-tvos': @vitek-karas, @kotlarmilos, @steveisok, @akoeplinger |
|
looks reasonable to me as well. we should just make sure the new tests actually run :) |
|
@akoeplinger, thanks for taking a look. Could you please run The filesystem-bind probe now uses a cached The earlier Apple run at 75f6cb8 passed the unbound regression on tvOS and both iOS Simulator architectures, and the connected-clone test on both simulators; tvOS filesystem-bind tests were skipped because its sandbox denied binding. After the refactor, all 21 Unix-domain socket cases and 4 HTTP ConnectCallback cases passed locally on each of Linux arm64 Mono JIT and Interpreter. The new runs should let us confirm the actual execution and skip results for the Apple regression, connected-clone, and HTTP Unix-domain socket tests on the current code. |
|
/azp run runtime-ioslikesimulator |
|
Azure Pipelines: Successfully started running 1 pipeline(s). |
|
/azp run runtime-ioslike |
|
Azure Pipelines: Successfully started running 1 pipeline(s). |
UnixDomainSocketEndPoint throws PlatformNotSupportedException on iOS and tvOS because SocketProtocolSupportPal unconditionally reports AF_UNIX as unsupported. This prevents applications from using Unix domain sockets even at paths permitted by the Apple sandbox.
Remove the iOS/tvOS exclusion and use the existing native socket probe. The explicit WASI exclusion remains.
Restore the address family from getsockname when Socket(SafeSocketHandle) cannot query it directly. Apple simulator functional CI exposed this missing fallback: Unix socket clones had unknown families, null endpoints, and Connected == false.
Add an ungated iOS/tvOS regression test for support, socket and endpoint construction, and address-family reconstruction from SafeHandle without binding. Strengthen the existing connected clone test with family and endpoint assertions.
Adapt socket and HTTP ConnectCallback tests to Apple app containers with short names and the shorter UTF-8 representation of the absolute or relative temporary directory. Share this directory selection between the two suites. HTTP client and server use the same directory, and the HTTP identifier starts with a letter to avoid numeric URI-host normalization.
Tests requiring successful filesystem binding use the cached
PlatformDetection.SupportsUnixDomainSocketBindingcondition in their ConditionalFact/Theory attributes. On iOS/tvOS this probes the shared socket directory once and reports binding as unavailable only when Bind returns AccessDenied. Other bind errors remain visible. Socket construction, endpoint validation, equality, negative tests, and the Linux abstract-address case remain independent of this permission check. Fix nullable server cleanup so it cannot mask failed setup.Validation
git diff --check: passed.dotnet-buildtools/prereqs:ubuntu-24.04-arm64v8container:./build.sh mono+libs -rc Release -arch arm64 /p:RestoreConfigFile=/work/runtime/NuGet.config(Release Mono runtime, Debug libraries).UnixDomainSocketTest: 21 passed, 0 failed, 0 skipped on Mono JIT; 21 passed, 0 failed, 0 skipped on Mono Interpreter. Both runs includeSocket_SendReceive_Clone_Success.ConnectCallback_UseUnixDomainSocket_Success: 4 passed, 0 failed, 0 skipped on each of Mono JIT and Interpreter, covering HTTP/1.1 and HTTP/2 with and without TLS. Used/p:WithCategories=failingto explicitly include the HTTP assembly, which is excluded by default on Linux/Mono under the existing assembly-level ActiveIssue for System.Net.*.Tests are unstable or slow/long-running on a S.P.CoreLib checked runtime #131. The tests themselves were unchanged for local execution.054c7c90a.TestUtilitiesalso builds successfully for net472, with 0 warnings and 0 errors.75f6cb8c87760cd57ef90e2e5335917142a0bc15: CoreCLRUnixDomainSocketTesthas 21 passed / 1 skipped / 0 failed on both iOS Simulator x64 and iOS Simulator arm64, including the connected-clone and unbound Apple regression tests. tvOS has 7 passed / 15 skipped / 0 failed: the unbound Apple regression passes; filesystem-bind cases are skipped because the sandbox denies Bind.054c7c90a; Apple validation of the cached-condition refactor is still pending.Resolves #96143