Skip to content

[release/10.0] Fix NativeAOT EventPipe use-after-free by waiting for active writers - #134999

Merged
steveisok merged 3 commits into
release/10.0from
copilot/release-10-0-backport-pr-134838
Oct 2, 2026
Merged

steveisok merged 3 commits into
release/10.0from
copilot/release-10-0-backport-pr-134838

Conversation

Copilot AI commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Backport of #134838 to release/10.0

/cc @MichalStrehovsky

Customer Impact

  • Customer reported
  • Found internally

#134785: Customer was seeing intermittent crashes with clrmd and EventSourceSupport.

Regression

  • Yes
  • No

This was broken from the start (#80382).

Testing

Intermittent crash that is hard to reproduce. Code review only.

Risk

Low risk, the new logic matches CoreCLR code.

IMPORTANT: If this backport is for a servicing release, please verify that:

  • For .NET 8 and .NET 9: The PR target branch is release/X.0-staging, not release/X.0.
  • For .NET 10+: The PR target branch is release/X.0 (no -staging suffix).

Package authoring no longer needed in .NET 9

IMPORTANT: Starting with .NET 9, you no longer need to edit a NuGet package's csproj to enable building and bump the version.
Keep in mind that we still need package authoring in .NET 8 and older versions.

@azure-pipelines

azure-pipelines Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @agocke
See info in area-owners.md if you want to be subscribed.

@MichalStrehovsky

Copy link
Copy Markdown
Member

@copilot continue the backport. make sure the PR title and description matches the template

…active writers

Co-authored-by: MichalStrehovsky <13110571+MichalStrehovsky@users.noreply.github.com>

Copilot AI commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

@copilot continue the backport. make sure the PR title and description matches the template

Backported in 1221d4caf, keeping the original four-file scope with release/10.0 compatibility adaptations. Baseline, CoreCLR, and NativeAOT+libraries builds passed; enabledisable and buffersize passed on both runtimes (four executions). Secret/whitespace checks passed; fallback code review found no issues. CodeQL analysis was skipped because the database was too large.

I cannot directly update the title/body with the available tools (metadata APIs are read-only, and browser access is blocked). The PR therefore still needs the following metadata applied, based on .github/PULL_REQUEST_TEMPLATE/servicing_pull_request_template.md:

Title

[release/10.0] Fix NativeAOT EventPipe use-after-free by waiting for active writers

Description

Fixes Issue #134785

main PR #134838

# Description

Backport #134838. NativeAOT's EP_YIELD_WHILE was a no-op, allowing EventPipe readers to consume and free buffers while writers still used them. Restore condition-rechecking waits and share thread-yield backoff with CoreCLR through minipal.

Release/10.0 adaptations are limited to required includes and implementing the helper's one-millisecond sleep directly, since this branch lacks minipal_sleep.

# Customer Impact

NativeAOT applications using EventSource/EventPipe can crash intermittently due to use-after-free during tracing. The fix prevents readers from freeing buffers still in use by writers.

# Regression

The faulty no-op is present in release/10.0. It has not been established that this was newly introduced in .NET 10.

# Testing

Linux x64 Debug:
- Unchanged baseline: ./build.sh clr+libs+host — passed.
- Patched build: ./build.sh clr — passed.
- NativeAOT build: ./build.sh clr.aot+libs -rc Debug -lc Debug — passed.
- Existing enabledisable and buffersize EventPipe tests — passed on CoreCLR and NativeAOT (four executions).

Tests ran through their standalone launch scripts. NativeAOT test builds used the documented IlcToolsPath override to the complete local compiler; NuGet auditing was disabled only for those local commands because vulnerability-data endpoints were unavailable. Test dependencies emitted trimming/AOT warnings. No dependency or repository configuration changes were made.

Whitespace and secret checks passed. Fallback code review found no significant issues. CodeQL analysis was skipped because its database was too large. Other operating systems and architectures were not tested locally.

# Risk

Low to moderate. This restores required synchronization using the existing CoreCLR yield/backoff strategy, but the shared helper also affects CoreCLR scheduling. The backport is limited to four files, and both runtime builds and targeted tracing tests passed on Linux x64.

# Package authoring no longer needed in .NET 9

No package-authoring changes are required for .NET 10.

@MichalStrehovsky

Copy link
Copy Markdown
Member

@copilot undo the changes to hosting.cpp to minimize risk

Co-authored-by: MichalStrehovsky <13110571+MichalStrehovsky@users.noreply.github.com>

Copilot AI commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

@copilot undo the changes to hosting.cpp to minimize risk

Restored hosting.cpp exactly to its pre-backport state in ff9d8ee6f. CoreCLR yield behavior is unchanged; the NativeAOT fix remains intact. Baseline and CoreCLR builds passed, as did both targeted EventPipe tests. Review and secret checks passed; CodeQL analysis was skipped due to database size.

@MichalStrehovsky MichalStrehovsky changed the title [WIP] Backport changes from PR #134838 to release/10.0 [release/10.0] Fix NativeAOT EventPipe use-after-free by waiting for active writers Oct 1, 2026
@MichalStrehovsky MichalStrehovsky added Servicing-consider Issue for next servicing release review area-NativeAOT-coreclr and removed area-VM-coreclr labels Oct 1, 2026
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @agocke, @dotnet/ilc-contrib
See info in area-owners.md if you want to be subscribed.

@MichalStrehovsky
MichalStrehovsky marked this pull request as ready for review October 1, 2026 05:00
@MichalStrehovsky
MichalStrehovsky requested a balanced review from Copilot October 1, 2026 05:01
@MichalStrehovsky

Copy link
Copy Markdown
Member

/azp run runtime-nativeaot-outerloop

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The concurrency and cross-platform behavior lacks executable validation and warrants final human review.

Review effort: Balanced
Findings: None

What changed in this PR

Backports the NativeAOT EventPipe writer synchronization fix to prevent buffers from being freed during active writes.

Changes:

  • Adds a portable thread-yield helper with contention backoff.
  • Re-enables EventPipe’s condition-rechecking wait loop.
  • Validation was code review only; builds and tests were not run.
File Description
src/​native/​minipal/​time.h Declares the thread-yield helper.
src/​native/​minipal/​time.c Implements yielding and eventual sleeping.
src/​coreclr/​nativeaot/​Runtime/​eventpipe/​ep-rt-aot.h Waits for active EventPipe writers.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

@rbhanda rbhanda added Servicing-approved Approved for servicing release and removed Servicing-consider Issue for next servicing release review labels Oct 1, 2026
@rbhanda rbhanda added this to the 10.0.15 milestone Oct 1, 2026
@steveisok
steveisok enabled auto-merge (squash) October 2, 2026 14:13
@steveisok

Copy link
Copy Markdown
Member

/ba-g Known issues unrelated

@steveisok
steveisok merged commit 1788cc3 into release/10.0 Oct 2, 2026
191 of 201 checks passed
@steveisok
steveisok deleted the copilot/release-10-0-backport-pr-134838 branch October 2, 2026 14:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-NativeAOT-coreclr Servicing-approved Approved for servicing release

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants