Tags: dotnet/wpf
Tags
[release/11.0-rc1] Source code updates from dotnet/dotnet (#11853) [release/11.0-rc1] Source code updates from dotnet/dotnet
Merged PR 64268: [9.0] Fix kern subsetting regression for fonts with … …>64KB kern tables ## Problem Font subsetting during XPS/PDF export and printing fails for fonts whose format 0 `kern` table exceeds 64KB - including the in-box Calibri family (Calibri, Cambria, Constantia, Corbel). The operation is wrongly rejected, breaking print/export for documents that use these fonts. ## Root cause A hardening check added to `AdjustKernFormat0` validated the format 0 kern pair data against the kern **subtable** `length` field. That field is a `uint16` (OpenType), so for any kern subtable larger than 64KB it wraps and reports a value far smaller than the real table size. The computed pair-array size then exceeds the wrapped length and the subtable is rejected, even though the font is valid and the data is in bounds. ## Fix Validate the pair data against the `uint32` kern **table-directory** length (`TTTableLength(pOutputBufferInfo, KERN_TAG)`) instead of the wrapping `uint16` subtable `length`. The directory length is a genuine 32-bit field that correctly describes tables over 64KB, so valid fonts pass while oversized/malformed data is still rejected. The overflow guard (`ULongMult32`) and the per-read `CheckInOffset`/`CheckOutOffset` bounds checks are unchanged, so the security hardening the original check was part of remains fully in effect. Fixes the regression tracked in ICM 851080013 / DTS-3049842 (KB5120708). Co-authored-by: Copilot ---- #### AI description (iteration 1) #### PR Classification Bug fix addressing a regression in TrueType font kern table subsetting for fonts with kern tables exceeding 64KB. #### PR Summary Fixes a validation issue where kern subtables larger than 64KB were incorrectly rejected due to uint16 length field limitations. The fix validates against the uint32 kern table-directory length instead of the subtable's uint16 length field. - `modtable.cpp`: Changed kern subtable size validation to use `TTTableLength()` with `KERN_TAG` instead of `KernSubHeader.length` to support kern tables >64KB <!-- GitOpsUserAgent=GitOps.Apps.Server.pullrequestcopilot -->
Merged PR 64317: [internal/release/8.0] Update dependencies from dnce… …ng/internal/dotnet-winforms This pull request updates the following dependencies [marker]: <> (Begin:Coherency Updates) ## Coherency Updates The following updates ensure that dependencies with a *CoherentParentDependency* attribute were produced in a build used as input to the parent dependency's build. See [Dependency Description Format](https://github.com/dotnet/arcade/blob/master/Documentation/DependencyDescriptionFormat.md#dependency-description-overview) [DependencyUpdate]: <> (Begin) - **Coherency Updates**: - **Microsoft.NETCore.Platforms**: from 8.0.31-servicing.26413.7 to 8.0.31-servicing.26420.15 (parent: Microsoft.Private.Winforms) - **Microsoft.NETCore.App.Ref**: from 8.0.31 to 8.0.31 (parent: Microsoft.Private.Winforms) - **Microsoft.NETCore.App.Runtime.win-x64**: from 8.0.31 to 8.0.31 (parent: Microsoft.Private.Winforms) - **VS.Redist.Common.NetCore.SharedFramework.x64.8.0**: from 8.0.31-servicing.26413.7 to 8.0.31-servicing.26420.15 (parent: Microsoft.Private.Winforms) [DependencyUpdate]: <> (End) [marker]: <> (End:Coherency Updates) [marker]: <> (Begin:0ce99e90-7dcb-4849-5aa3-08dbd5a5c716) ## From https://dev.azure.com/dnceng/internal/_git/dotnet-winforms - **Subscription**: [0ce99e90-7dcb-4849-5aa3-08dbd5a5c716](https://maestro.dot.net/subscriptions?search=0ce99e90-7dcb-4849-5aa3-08dbd5a5c716) - **Build**: [20260821.6](https://dev.azure.com/dnceng/internal/_build/results?buildId=3054251) ([328131](https://maestro.dot.net/channel/3880/azdo:dnceng:internal:dotnet-winforms/build/328131)) - **Date Produced**: August 21, 2026 10:13:19 PM UTC - **Commit**: [f4ddf3475a1269429508fe203cdfc4e21c3599d1](https://dev.azure.com/dnceng/internal/_git/dotnet-winforms?_a=history&version=GCf4ddf3475a1269429508fe203cdfc4e21c3599d1) - **Branch**: [refs/heads/internal/release/8.0](https://dev.azure.com/dnceng/internal/_git/dotnet-winforms?version=GBrefs/heads/internal/release/8.0) [DependencyUpdate]: <> (Begin) - **Dependency Updates**: - From [8.0.31-servicing.26414.1 to 8.0.31-servicing.26421.6][1] - Microsoft.Dotnet.WinForms.ProjectTemplates - Microsoft.Private.Winforms - From [8.0.31 to 8.0.31][1] - System.Drawing.Common [1]: https://dev.azure.com/dnceng/internal/_git/dotnet-winforms/branches?baseVersion=GCba3a08e4461bab26853e623cb98c324b4f9dc990&targetVersion=GCf4ddf3475a1269429508fe203cdfc4e21c3599d1&_a=files [DependencyUpdate]: <> (End) [marker]: <> (End:0ce99e90-7dcb-4849-5aa3-08dbd5a5c716)
Merged PR 63150: [internal/release/8.0] Update dependencies from dnce… …ng/internal/dotnet-winforms This pull request updates the following dependencies [marker]: <> (Begin:Coherency Updates) ## Coherency Updates The following updates ensure that dependencies with a *CoherentParentDependency* attribute were produced in a build used as input to the parent dependency's build. See [Dependency Description Format](https://github.com/dotnet/arcade/blob/master/Documentation/DependencyDescriptionFormat.md#dependency-description-overview) [DependencyUpdate]: <> (Begin) - **Coherency Updates**: - **System.Security.Cryptography.Xml**: from 8.0.4 to 8.0.4 (parent: Microsoft.Private.Winforms) [DependencyUpdate]: <> (End) [marker]: <> (End:Coherency Updates) [marker]: <> (Begin:0ce99e90-7dcb-4849-5aa3-08dbd5a5c716) ## From https://dev.azure.com/dnceng/internal/_git/dotnet-winforms - **Subscription**: [0ce99e90-7dcb-4849-5aa3-08dbd5a5c716](https://maestro.dot.net/subscriptions?search=0ce99e90-7dcb-4849-5aa3-08dbd5a5c716) - **Build**: [20260723.1](https://dev.azure.com/dnceng/internal/_build/results?buildId=3029631) ([324105](https://maestro.dot.net/channel/3880/azdo:dnceng:internal:dotnet-winforms/build/324105)) - **Date Produced**: July 23, 2026 9:57:54 AM UTC - **Commit**: [3bde17662ffbf8c378d06d58f99da47eb047eb23](https://dev.azure.com/dnceng/internal/_git/dotnet-winforms?_a=history&version=GC3bde17662ffbf8c378d06d58f99da47eb047eb23) - **Branch**: [refs/heads/internal/release/8.0](https://dev.azure.com/dnceng/internal/_git/dotnet-winforms?version=GBrefs/heads/internal/release/8.0) [DependencyUpdate]: <> (Begin) - **Dependency Updates**: - From [8.0.30-servicing.26370.2 to 8.0.30-servicing.26373.1][1] - Microsoft.Dotnet.WinForms.ProjectTemplates - Microsoft.Private.Winforms - From [8.0.30 to 8.0.30][1] - System.Drawing.Common [1]: https://dev.azure.com/dnceng/internal/_git/dotnet-winforms/branches?baseVersion=GC4a0978e1dc7ab568427b618bb06b7c50d9acad33&targetVersion=GC3bde17662ffbf8c378d06d58f99da47eb047eb23&_a=files [DependencyUpdate]: <> (End) [marker]: <> (End:0ce99e90-7dcb-4849-5aa3-08dbd5a5c716)
Merged PR 63066: [release/9.0] Removing faulty DefaultCredentialZoneP… …olicy tests #### AI description (iteration 1) #### PR Classification Test cleanup and removal of faulty integration tests that depended on COM interop with `IInternetSecurityManager`. #### PR Summary Removes unreliable tests that tested zone-based credential policy through native COM zone lookups and integration with `WpfWebRequestHelper.CreateRequest`, refocusing tests on deterministic code paths only. - `DefaultCredentialsZonePolicyTests.cs`: Removed `CreateRequest_HonorsPolicyForUseDefaultCredentials` integration test and the `IInternetSecurityManager` COM interface definition with its `FakeSecurityManager` test double - `DefaultCredentialsZonePolicyTests.cs`: Removed zone matrix test (`ShouldSendDefaultCredentials_ZoneMatrix`) and unknown zone test that relied on the fake security manager - `DefaultCredentialsZonePolicyTests.cs`: Consolidated IP fast-path tests into a single parameterized test covering IPv4/IPv6 loopback and private address ranges - `DefaultCredentialsZonePolicyTests.cs`: Updated class documentation to clarify that only deterministic paths (null/relative URIs, local/private IPs, and security manager initialization failure) are tested <!-- GitOpsUserAgent=GitOps.Apps.Server.pullrequestcopilot -->
Merged PR 62415: [internal/release/8.0] Update dependencies from dnce… …ng/internal/dotnet-winforms This pull request updates the following dependencies [marker]: <> (Begin:Coherency Updates) ## Coherency Updates The following updates ensure that dependencies with a *CoherentParentDependency* attribute were produced in a build used as input to the parent dependency's build. See [Dependency Description Format](https://github.com/dotnet/arcade/blob/master/Documentation/DependencyDescriptionFormat.md#dependency-description-overview) [DependencyUpdate]: <> (Begin) - **Coherency Updates**: - **Microsoft.NETCore.Platforms**: from 8.0.29-servicing.26315.23 to 8.0.29-servicing.26324.3 (parent: Microsoft.Private.Winforms) - **Microsoft.NETCore.App.Ref**: from 8.0.29 to 8.0.29 (parent: Microsoft.Private.Winforms) - **Microsoft.NETCore.App.Runtime.win-x64**: from 8.0.29 to 8.0.29 (parent: Microsoft.Private.Winforms) - **VS.Redist.Common.NetCore.SharedFramework.x64.8.0**: from 8.0.29-servicing.26315.23 to 8.0.29-servicing.26324.3 (parent: Microsoft.Private.Winforms) - **System.Security.Cryptography.Xml**: from 8.0.3 to 8.0.4 (parent: Microsoft.Private.Winforms) [DependencyUpdate]: <> (End) [marker]: <> (End:Coherency Updates) [marker]: <> (Begin:0ce99e90-7dcb-4849-5aa3-08dbd5a5c716) ## From https://dev.azure.com/dnceng/internal/_git/dotnet-winforms - **Subscription**: [0ce99e90-7dcb-4849-5aa3-08dbd5a5c716](https://maestro.dot.net/subscriptions?search=0ce99e90-7dcb-4849-5aa3-08dbd5a5c716) - **Build**: [20260625.2](https://dev.azure.com/dnceng/internal/_build/results?buildId=3008190) ([320236](https://maestro.dot.net/channel/3880/azdo:dnceng:internal:dotnet-winforms/build/320236)) - **Date Produced**: June 25, 2026 5:17:41 PM UTC - **Commit**: [997e819eac134e12bc1b2e50d8644d1aadd387d1](https://dev.azure.com/dnceng/internal/_git/dotnet-winforms?_a=history&version=GC997e819eac134e12bc1b2e50d8644d1aadd387d1) - **Branch**: [refs/heads/internal/release/8.0](https://dev.azure.com/dnceng/internal/_git/dotnet-winforms?version=GBrefs/heads/internal/release/8.0) [DependencyUpdate]: <> (Begin) - **Dependency Updates**: - From [8.0.29-servicing.26316.1 to 8.0.29-servicing.26325.2][1] - Microsoft.Dotnet.WinForms.ProjectTemplates - Microsoft.Private.Winforms - From [8.0.29 to 8.0.29][1] - System.Drawing.Common [1]: https://dev.azure.com/dnceng/internal/_git/dotnet-winforms/branches?baseVersion=GCe126432737a0d81e9e6cea3ae9467828ab9529db&targetVersion=GC997e819eac134e12bc1b2e50d8644d1aadd387d1&_a=files [DependencyUpdate]: <> (End) [marker]: <> (End:0ce99e90-7dcb-4849-5aa3-08dbd5a5c716)
PreviousNext