[release/10.0] Fix NativeAOT EventPipe use-after-free by waiting for active writers - #134999
Conversation
|
Azure Pipelines: Successfully started running 3 pipeline(s). 13 pipeline(s) were filtered out due to trigger conditions. There may be pipelines that require an authorized user to comment /azp run to run. |
|
Tagging subscribers to this area: @agocke |
|
@copilot continue the backport. make sure the PR title and description matches the template |
…active writers Co-authored-by: MichalStrehovsky <13110571+MichalStrehovsky@users.noreply.github.com>
Backported in I cannot directly update the title/body with the available tools (metadata APIs are read-only, and browser access is blocked). The PR therefore still needs the following metadata applied, based on Title Description Fixes Issue #134785
main PR #134838
# Description
Backport #134838. NativeAOT's EP_YIELD_WHILE was a no-op, allowing EventPipe readers to consume and free buffers while writers still used them. Restore condition-rechecking waits and share thread-yield backoff with CoreCLR through minipal.
Release/10.0 adaptations are limited to required includes and implementing the helper's one-millisecond sleep directly, since this branch lacks minipal_sleep.
# Customer Impact
NativeAOT applications using EventSource/EventPipe can crash intermittently due to use-after-free during tracing. The fix prevents readers from freeing buffers still in use by writers.
# Regression
The faulty no-op is present in release/10.0. It has not been established that this was newly introduced in .NET 10.
# Testing
Linux x64 Debug:
- Unchanged baseline: ./build.sh clr+libs+host — passed.
- Patched build: ./build.sh clr — passed.
- NativeAOT build: ./build.sh clr.aot+libs -rc Debug -lc Debug — passed.
- Existing enabledisable and buffersize EventPipe tests — passed on CoreCLR and NativeAOT (four executions).
Tests ran through their standalone launch scripts. NativeAOT test builds used the documented IlcToolsPath override to the complete local compiler; NuGet auditing was disabled only for those local commands because vulnerability-data endpoints were unavailable. Test dependencies emitted trimming/AOT warnings. No dependency or repository configuration changes were made.
Whitespace and secret checks passed. Fallback code review found no significant issues. CodeQL analysis was skipped because its database was too large. Other operating systems and architectures were not tested locally.
# Risk
Low to moderate. This restores required synchronization using the existing CoreCLR yield/backoff strategy, but the shared helper also affects CoreCLR scheduling. The backport is limited to four files, and both runtime builds and targeted tracing tests passed on Linux x64.
# Package authoring no longer needed in .NET 9
No package-authoring changes are required for .NET 10. |
|
@copilot undo the changes to hosting.cpp to minimize risk |
Co-authored-by: MichalStrehovsky <13110571+MichalStrehovsky@users.noreply.github.com>
Restored |
|
Tagging subscribers to this area: @agocke, @dotnet/ilc-contrib |
|
/azp run runtime-nativeaot-outerloop |
|
Azure Pipelines: Successfully started running 1 pipeline(s). |
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The concurrency and cross-platform behavior lacks executable validation and warrants final human review.
Review effort: Balanced
Findings: None
What changed in this PR
Backports the NativeAOT EventPipe writer synchronization fix to prevent buffers from being freed during active writes.
Changes:
- Adds a portable thread-yield helper with contention backoff.
- Re-enables EventPipe’s condition-rechecking wait loop.
- Validation was code review only; builds and tests were not run.
| File | Description |
|---|---|
src/native/minipal/time.h |
Declares the thread-yield helper. |
src/native/minipal/time.c |
Implements yielding and eventual sleeping. |
src/coreclr/nativeaot/Runtime/eventpipe/ep-rt-aot.h |
Waits for active EventPipe writers. |
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
|
/ba-g Known issues unrelated |
Backport of #134838 to release/10.0
/cc @MichalStrehovsky
Customer Impact
#134785: Customer was seeing intermittent crashes with clrmd and EventSourceSupport.
Regression
This was broken from the start (#80382).
Testing
Intermittent crash that is hard to reproduce. Code review only.
Risk
Low risk, the new logic matches CoreCLR code.
IMPORTANT: If this backport is for a servicing release, please verify that:
release/X.0-staging, notrelease/X.0.release/X.0(no-stagingsuffix).Package authoring no longer needed in .NET 9
IMPORTANT: Starting with .NET 9, you no longer need to edit a NuGet package's csproj to enable building and bump the version.
Keep in mind that we still need package authoring in .NET 8 and older versions.