Client-side TLS 1.3 support on OSX - #117428

Merged
rzikm merged 88 commits into
dotnet:mainfrom
rzikm:osx-tls13
Jul 17, 2025
Merged

Client-side TLS 1.3 support on OSX#117428
rzikm merged 88 commits into
dotnet:mainfrom
rzikm:osx-tls13

Conversation

@rzikm

@rzikmrzikm commented Jul 8, 2025

Copy link
Copy Markdown
Member

Replaces #117016.

The goal is to integrate the new NetworkFramework to support client-side TLS 1.3 on OSX to unblock developers working on OSX. The feature is gated behind one of the following

  • System.Net.Security.UseNetworkFramework AppCtx switch
  • DOTNET_SYSTEM_NET_SECURITY_USENETWORKFRAMEWORK environment variable

Ahmet İbrahim Aksoyand others added 30 commits June 16, 2025 19:54
…amework.m
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Stephen Toub <stoub@microsoft.com>
Co-authored-by: Radek Zikmund <32671551+rzikm@users.noreply.github.com>
@rzikm

Copy link
Copy Markdown
MemberAuthor

Removing WIP status as we are getting stable. The target is to merge this PR before the end of week

@rzikmrzikm changed the title [WIP] TLS 1.3 on OSX supportClient-side TLS 1.3 support on OSXJul 14, 2025
@liveans
liveans requested a review from CopilotJuly 14, 2025 15:45

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

Integrates Network.framework for client-side TLS 1.3 on macOS, selectable via an AppContext switch or environment variable

  • Link the Network framework in build scripts (CMake, MSBuild, extra_libs.cmake)
  • Introduce a pal_networkframework native module and wire it up through new C# PAL types (SafeDeleteNwContext, interop)
  • Extend SslStream to choose between SecureTransport and Network.framework paths and update functional tests to skip or adapt when using Network.framework

Reviewed Changes

Copilot reviewed 37 out of 38 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
src/tasks/LibraryBuilder/Templates/CMakeLists.txt.templateLink Network framework for library builds
src/tasks/AppleAppBuilder/Templates/CMakeLists.txt.templateLink Network framework for app builder
src/tasks/AppleAppBuilder/Templates/CMakeLists-librarymode.txt.templateLink Network framework in library mode
src/native/libs/System.Security.Cryptography.Native.Apple/pal_ssl.hChange hostname-match API to accept a SecTrustRef
src/native/libs/System.Security.Cryptography.Native.Apple/pal_ssl.cAdapt hostname-match implementation to use the passed-in trust
src/native/libs/System.Security.Cryptography.Native.Apple/pal_networkframework.mAdd Network.framework–based TLS I/O implementation
src/native/libs/System.Security.Cryptography.Native.Apple/pal_networkframework.hDeclare PAL APIs for Network.framework
src/native/libs/System.Security.Cryptography.Native.Apple/extra_libs.cmakeInclude Network library in extra linking
src/native/libs/System.Security.Cryptography.Native.Apple/entrypoints.cExport new Network.framework entry points
src/native/libs/System.Security.Cryptography.Native.Apple/CMakeLists.txtAdd pal_networkframework.m to native sources
src/mono/msbuild/apple/build/AppleBuild.targetsLink Network framework in Mono MSBuild targets
src/libraries/System.Net.Security/tests/FunctionalTests/*.csUpdate tests to skip or adapt when Network.framework is enabled
src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.Windows.csExpose custom-alert capability on Windows
src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.Unix.csExpose custom-alert capability on Unix
src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.OSX.csExtend PAL to detect and route to Network.framework contexts
src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.Android.csExpose custom-alert capability on Android
src/libraries/System.Net.Security/src/System/Net/Security/SslStream.Protocol.csAdd gating logic and async context selection
src/libraries/System.Net.Security/src/System/Net/Security/SslStream.IO.csSupport async read/write via Network.framework context
src/libraries/System.Net.Security/src/System/Net/Security/SslConnectionInfo.OSX.csHandle connection info for both PAL contexts
src/libraries/System.Net.Security/src/System/Net/Security/Pal.OSX/SafeDeleteSslContext.csRefactor status codes to use Interop.AppleCrypto.OSStatus
src/libraries/System.Net.Security/src/System/Net/Security/Pal.OSX/SafeDeleteNwContext.csImplement SafeDeleteNwContext for Network.framework
src/libraries/System.Net.Security/src/System/Net/Security/Pal.Managed/SslProtocolsValidation.csChange ValidateContiguous to accept ReadOnlySpan<SslProtocols>
src/libraries/System.Net.Security/src/System/Net/CertificateValidationPal.OSX.csUse SecTrustRef for hostname validation in both contexts
src/libraries/System.Net.Security/src/System.Net.Security.csprojDefine TARGET_APPLE and include new interop files
src/libraries/Common/tests/TestUtilities/System/PlatformDetection.csAdd detection for Network.framework and TLS 1.3 client/server support
src/libraries/Common/src/System/Net/ReadWriteAdapter.csExtend IReadWriteAdapter with Task/ValueTask overloads
src/libraries/Common/src/Interop/OSX/System.Security.Cryptography.Native.Apple/Interop.Ssl.csUpdate p/invoke for the new hostname-match signature
src/libraries/Common/src/Interop/OSX/System.Security.Cryptography.Native.Apple/Interop.OSStatus.csAdd OSStatus constants for native error mapping
src/libraries/Common/src/Interop/OSX/Interop.NetworkFramework.csDeclare basic Network.framework interop and error handling
src/libraries/Common/src/Interop/OSX/Interop.NetworkFramework.Tls.csDeclare TLS entry points for the Network.framework shim
src/libraries/Common/src/Interop/OSX/Interop.Libraries.csAdd NetworkFramework library constant
src/coreclr/nativeaot/BuildIntegration/Microsoft.NETCore.Native.Unix.targetsLink Network framework in NativeAOT Unix builds
Comments suppressed due to low confidence (2)

src/native/libs/System.Security.Cryptography.Native.Apple/pal_networkframework.m:1

  • The new Network.framework integration layer is extensive but currently has no direct unit or functional tests; adding tests for handshake, send/receive, and error paths on macOS would help validate this feature.
// Licensed to the .NET Foundation under one or more agreements.

src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.OSX.cs:4

  • The using directives for System.IO, System.Threading, and System.Threading.Tasks appear unused in this file; consider removing them to reduce clutter.
using System.IO;

@build-analysisbuild-analysisBot mentioned this pull request Jul 15, 2025
Comment threadsrc/libraries/Common/tests/TestUtilities/System/PlatformDetection.cs Outdated
…networkframework.m
Co-authored-by: Adeel Mujahid <3840695+am11@users.noreply.github.com>

@wfurtwfurt left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. this is big milestone.

@rzikm

Copy link
Copy Markdown
MemberAuthor

/ba-g WASM failures are unrelated, linux failures are unrelated

Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@rzikm@vcsjones@filipnavara@am11@wfurt@liveans
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Client-side TLS 1.3 support on OSX - #117428

Merged
rzikm merged 88 commits into
dotnet:mainfrom
rzikm:osx-tls13
Jul 17, 2025
Merged

Client-side TLS 1.3 support on OSX#117428
rzikm merged 88 commits into
dotnet:mainfrom
rzikm:osx-tls13

Conversation

@rzikm

@rzikmrzikm commented Jul 8, 2025

Copy link
Copy Markdown
Member

Replaces #117016.

The goal is to integrate the new NetworkFramework to support client-side TLS 1.3 on OSX to unblock developers working on OSX. The feature is gated behind one of the following

  • System.Net.Security.UseNetworkFramework AppCtx switch
  • DOTNET_SYSTEM_NET_SECURITY_USENETWORKFRAMEWORK environment variable

Ahmet İbrahim Aksoyand others added 30 commits June 16, 2025 19:54
…amework.m
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Stephen Toub <stoub@microsoft.com>
Co-authored-by: Radek Zikmund <32671551+rzikm@users.noreply.github.com>
@rzikm

Copy link
Copy Markdown
MemberAuthor

Removing WIP status as we are getting stable. The target is to merge this PR before the end of week

@rzikmrzikm changed the title [WIP] TLS 1.3 on OSX supportClient-side TLS 1.3 support on OSXJul 14, 2025
@liveans
liveans requested a review from CopilotJuly 14, 2025 15:45

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

Integrates Network.framework for client-side TLS 1.3 on macOS, selectable via an AppContext switch or environment variable

  • Link the Network framework in build scripts (CMake, MSBuild, extra_libs.cmake)
  • Introduce a pal_networkframework native module and wire it up through new C# PAL types (SafeDeleteNwContext, interop)
  • Extend SslStream to choose between SecureTransport and Network.framework paths and update functional tests to skip or adapt when using Network.framework

Reviewed Changes

Copilot reviewed 37 out of 38 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
src/tasks/LibraryBuilder/Templates/CMakeLists.txt.templateLink Network framework for library builds
src/tasks/AppleAppBuilder/Templates/CMakeLists.txt.templateLink Network framework for app builder
src/tasks/AppleAppBuilder/Templates/CMakeLists-librarymode.txt.templateLink Network framework in library mode
src/native/libs/System.Security.Cryptography.Native.Apple/pal_ssl.hChange hostname-match API to accept a SecTrustRef
src/native/libs/System.Security.Cryptography.Native.Apple/pal_ssl.cAdapt hostname-match implementation to use the passed-in trust
src/native/libs/System.Security.Cryptography.Native.Apple/pal_networkframework.mAdd Network.framework–based TLS I/O implementation
src/native/libs/System.Security.Cryptography.Native.Apple/pal_networkframework.hDeclare PAL APIs for Network.framework
src/native/libs/System.Security.Cryptography.Native.Apple/extra_libs.cmakeInclude Network library in extra linking
src/native/libs/System.Security.Cryptography.Native.Apple/entrypoints.cExport new Network.framework entry points
src/native/libs/System.Security.Cryptography.Native.Apple/CMakeLists.txtAdd pal_networkframework.m to native sources
src/mono/msbuild/apple/build/AppleBuild.targetsLink Network framework in Mono MSBuild targets
src/libraries/System.Net.Security/tests/FunctionalTests/*.csUpdate tests to skip or adapt when Network.framework is enabled
src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.Windows.csExpose custom-alert capability on Windows
src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.Unix.csExpose custom-alert capability on Unix
src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.OSX.csExtend PAL to detect and route to Network.framework contexts
src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.Android.csExpose custom-alert capability on Android
src/libraries/System.Net.Security/src/System/Net/Security/SslStream.Protocol.csAdd gating logic and async context selection
src/libraries/System.Net.Security/src/System/Net/Security/SslStream.IO.csSupport async read/write via Network.framework context
src/libraries/System.Net.Security/src/System/Net/Security/SslConnectionInfo.OSX.csHandle connection info for both PAL contexts
src/libraries/System.Net.Security/src/System/Net/Security/Pal.OSX/SafeDeleteSslContext.csRefactor status codes to use Interop.AppleCrypto.OSStatus
src/libraries/System.Net.Security/src/System/Net/Security/Pal.OSX/SafeDeleteNwContext.csImplement SafeDeleteNwContext for Network.framework
src/libraries/System.Net.Security/src/System/Net/Security/Pal.Managed/SslProtocolsValidation.csChange ValidateContiguous to accept ReadOnlySpan<SslProtocols>
src/libraries/System.Net.Security/src/System/Net/CertificateValidationPal.OSX.csUse SecTrustRef for hostname validation in both contexts
src/libraries/System.Net.Security/src/System.Net.Security.csprojDefine TARGET_APPLE and include new interop files
src/libraries/Common/tests/TestUtilities/System/PlatformDetection.csAdd detection for Network.framework and TLS 1.3 client/server support
src/libraries/Common/src/System/Net/ReadWriteAdapter.csExtend IReadWriteAdapter with Task/ValueTask overloads
src/libraries/Common/src/Interop/OSX/System.Security.Cryptography.Native.Apple/Interop.Ssl.csUpdate p/invoke for the new hostname-match signature
src/libraries/Common/src/Interop/OSX/System.Security.Cryptography.Native.Apple/Interop.OSStatus.csAdd OSStatus constants for native error mapping
src/libraries/Common/src/Interop/OSX/Interop.NetworkFramework.csDeclare basic Network.framework interop and error handling
src/libraries/Common/src/Interop/OSX/Interop.NetworkFramework.Tls.csDeclare TLS entry points for the Network.framework shim
src/libraries/Common/src/Interop/OSX/Interop.Libraries.csAdd NetworkFramework library constant
src/coreclr/nativeaot/BuildIntegration/Microsoft.NETCore.Native.Unix.targetsLink Network framework in NativeAOT Unix builds
Comments suppressed due to low confidence (2)

src/native/libs/System.Security.Cryptography.Native.Apple/pal_networkframework.m:1

  • The new Network.framework integration layer is extensive but currently has no direct unit or functional tests; adding tests for handshake, send/receive, and error paths on macOS would help validate this feature.
// Licensed to the .NET Foundation under one or more agreements.

src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.OSX.cs:4

  • The using directives for System.IO, System.Threading, and System.Threading.Tasks appear unused in this file; consider removing them to reduce clutter.
using System.IO;

@build-analysisbuild-analysisBot mentioned this pull request Jul 15, 2025
Comment threadsrc/libraries/Common/tests/TestUtilities/System/PlatformDetection.cs Outdated
…networkframework.m
Co-authored-by: Adeel Mujahid <3840695+am11@users.noreply.github.com>

@wfurtwfurt left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. this is big milestone.

@rzikm

Copy link
Copy Markdown
MemberAuthor

/ba-g WASM failures are unrelated, linux failures are unrelated

Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@rzikm@vcsjones@filipnavara@am11@wfurt@liveans
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Client-side TLS 1.3 support on OSX - #117428

Merged
rzikm merged 88 commits into
dotnet:mainfrom
rzikm:osx-tls13
Jul 17, 2025
Merged

Client-side TLS 1.3 support on OSX#117428
rzikm merged 88 commits into
dotnet:mainfrom
rzikm:osx-tls13

Conversation

@rzikm

@rzikmrzikm commented Jul 8, 2025

Copy link
Copy Markdown
Member

Replaces #117016.

The goal is to integrate the new NetworkFramework to support client-side TLS 1.3 on OSX to unblock developers working on OSX. The feature is gated behind one of the following

  • System.Net.Security.UseNetworkFramework AppCtx switch
  • DOTNET_SYSTEM_NET_SECURITY_USENETWORKFRAMEWORK environment variable

Ahmet İbrahim Aksoyand others added 30 commits June 16, 2025 19:54
…amework.m
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Stephen Toub <stoub@microsoft.com>
Co-authored-by: Radek Zikmund <32671551+rzikm@users.noreply.github.com>
@rzikm

Copy link
Copy Markdown
MemberAuthor

Removing WIP status as we are getting stable. The target is to merge this PR before the end of week

@rzikmrzikm changed the title [WIP] TLS 1.3 on OSX supportClient-side TLS 1.3 support on OSXJul 14, 2025
@liveans
liveans requested a review from CopilotJuly 14, 2025 15:45

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

Integrates Network.framework for client-side TLS 1.3 on macOS, selectable via an AppContext switch or environment variable

  • Link the Network framework in build scripts (CMake, MSBuild, extra_libs.cmake)
  • Introduce a pal_networkframework native module and wire it up through new C# PAL types (SafeDeleteNwContext, interop)
  • Extend SslStream to choose between SecureTransport and Network.framework paths and update functional tests to skip or adapt when using Network.framework

Reviewed Changes

Copilot reviewed 37 out of 38 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
src/tasks/LibraryBuilder/Templates/CMakeLists.txt.templateLink Network framework for library builds
src/tasks/AppleAppBuilder/Templates/CMakeLists.txt.templateLink Network framework for app builder
src/tasks/AppleAppBuilder/Templates/CMakeLists-librarymode.txt.templateLink Network framework in library mode
src/native/libs/System.Security.Cryptography.Native.Apple/pal_ssl.hChange hostname-match API to accept a SecTrustRef
src/native/libs/System.Security.Cryptography.Native.Apple/pal_ssl.cAdapt hostname-match implementation to use the passed-in trust
src/native/libs/System.Security.Cryptography.Native.Apple/pal_networkframework.mAdd Network.framework–based TLS I/O implementation
src/native/libs/System.Security.Cryptography.Native.Apple/pal_networkframework.hDeclare PAL APIs for Network.framework
src/native/libs/System.Security.Cryptography.Native.Apple/extra_libs.cmakeInclude Network library in extra linking
src/native/libs/System.Security.Cryptography.Native.Apple/entrypoints.cExport new Network.framework entry points
src/native/libs/System.Security.Cryptography.Native.Apple/CMakeLists.txtAdd pal_networkframework.m to native sources
src/mono/msbuild/apple/build/AppleBuild.targetsLink Network framework in Mono MSBuild targets
src/libraries/System.Net.Security/tests/FunctionalTests/*.csUpdate tests to skip or adapt when Network.framework is enabled
src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.Windows.csExpose custom-alert capability on Windows
src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.Unix.csExpose custom-alert capability on Unix
src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.OSX.csExtend PAL to detect and route to Network.framework contexts
src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.Android.csExpose custom-alert capability on Android
src/libraries/System.Net.Security/src/System/Net/Security/SslStream.Protocol.csAdd gating logic and async context selection
src/libraries/System.Net.Security/src/System/Net/Security/SslStream.IO.csSupport async read/write via Network.framework context
src/libraries/System.Net.Security/src/System/Net/Security/SslConnectionInfo.OSX.csHandle connection info for both PAL contexts
src/libraries/System.Net.Security/src/System/Net/Security/Pal.OSX/SafeDeleteSslContext.csRefactor status codes to use Interop.AppleCrypto.OSStatus
src/libraries/System.Net.Security/src/System/Net/Security/Pal.OSX/SafeDeleteNwContext.csImplement SafeDeleteNwContext for Network.framework
src/libraries/System.Net.Security/src/System/Net/Security/Pal.Managed/SslProtocolsValidation.csChange ValidateContiguous to accept ReadOnlySpan<SslProtocols>
src/libraries/System.Net.Security/src/System/Net/CertificateValidationPal.OSX.csUse SecTrustRef for hostname validation in both contexts
src/libraries/System.Net.Security/src/System.Net.Security.csprojDefine TARGET_APPLE and include new interop files
src/libraries/Common/tests/TestUtilities/System/PlatformDetection.csAdd detection for Network.framework and TLS 1.3 client/server support
src/libraries/Common/src/System/Net/ReadWriteAdapter.csExtend IReadWriteAdapter with Task/ValueTask overloads
src/libraries/Common/src/Interop/OSX/System.Security.Cryptography.Native.Apple/Interop.Ssl.csUpdate p/invoke for the new hostname-match signature
src/libraries/Common/src/Interop/OSX/System.Security.Cryptography.Native.Apple/Interop.OSStatus.csAdd OSStatus constants for native error mapping
src/libraries/Common/src/Interop/OSX/Interop.NetworkFramework.csDeclare basic Network.framework interop and error handling
src/libraries/Common/src/Interop/OSX/Interop.NetworkFramework.Tls.csDeclare TLS entry points for the Network.framework shim
src/libraries/Common/src/Interop/OSX/Interop.Libraries.csAdd NetworkFramework library constant
src/coreclr/nativeaot/BuildIntegration/Microsoft.NETCore.Native.Unix.targetsLink Network framework in NativeAOT Unix builds
Comments suppressed due to low confidence (2)

src/native/libs/System.Security.Cryptography.Native.Apple/pal_networkframework.m:1

  • The new Network.framework integration layer is extensive but currently has no direct unit or functional tests; adding tests for handshake, send/receive, and error paths on macOS would help validate this feature.
// Licensed to the .NET Foundation under one or more agreements.

src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.OSX.cs:4

  • The using directives for System.IO, System.Threading, and System.Threading.Tasks appear unused in this file; consider removing them to reduce clutter.
using System.IO;

@build-analysisbuild-analysisBot mentioned this pull request Jul 15, 2025
Comment threadsrc/libraries/Common/tests/TestUtilities/System/PlatformDetection.cs Outdated
…networkframework.m
Co-authored-by: Adeel Mujahid <3840695+am11@users.noreply.github.com>

@wfurtwfurt left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. this is big milestone.

@rzikm

Copy link
Copy Markdown
MemberAuthor

/ba-g WASM failures are unrelated, linux failures are unrelated

Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@rzikm@vcsjones@filipnavara@am11@wfurt@liveans
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Client-side TLS 1.3 support on OSX - #117428

Merged
rzikm merged 88 commits into
dotnet:mainfrom
rzikm:osx-tls13
Jul 17, 2025
Merged

Client-side TLS 1.3 support on OSX#117428
rzikm merged 88 commits into
dotnet:mainfrom
rzikm:osx-tls13

Conversation

@rzikm

@rzikmrzikm commented Jul 8, 2025

Copy link
Copy Markdown
Member

Replaces #117016.

The goal is to integrate the new NetworkFramework to support client-side TLS 1.3 on OSX to unblock developers working on OSX. The feature is gated behind one of the following

  • System.Net.Security.UseNetworkFramework AppCtx switch
  • DOTNET_SYSTEM_NET_SECURITY_USENETWORKFRAMEWORK environment variable

Ahmet İbrahim Aksoyand others added 30 commits June 16, 2025 19:54
…amework.m
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Stephen Toub <stoub@microsoft.com>
Co-authored-by: Radek Zikmund <32671551+rzikm@users.noreply.github.com>
@rzikm

Copy link
Copy Markdown
MemberAuthor

Removing WIP status as we are getting stable. The target is to merge this PR before the end of week

@rzikmrzikm changed the title [WIP] TLS 1.3 on OSX supportClient-side TLS 1.3 support on OSXJul 14, 2025
@liveans
liveans requested a review from CopilotJuly 14, 2025 15:45

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

Integrates Network.framework for client-side TLS 1.3 on macOS, selectable via an AppContext switch or environment variable

  • Link the Network framework in build scripts (CMake, MSBuild, extra_libs.cmake)
  • Introduce a pal_networkframework native module and wire it up through new C# PAL types (SafeDeleteNwContext, interop)
  • Extend SslStream to choose between SecureTransport and Network.framework paths and update functional tests to skip or adapt when using Network.framework

Reviewed Changes

Copilot reviewed 37 out of 38 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
src/tasks/LibraryBuilder/Templates/CMakeLists.txt.templateLink Network framework for library builds
src/tasks/AppleAppBuilder/Templates/CMakeLists.txt.templateLink Network framework for app builder
src/tasks/AppleAppBuilder/Templates/CMakeLists-librarymode.txt.templateLink Network framework in library mode
src/native/libs/System.Security.Cryptography.Native.Apple/pal_ssl.hChange hostname-match API to accept a SecTrustRef
src/native/libs/System.Security.Cryptography.Native.Apple/pal_ssl.cAdapt hostname-match implementation to use the passed-in trust
src/native/libs/System.Security.Cryptography.Native.Apple/pal_networkframework.mAdd Network.framework–based TLS I/O implementation
src/native/libs/System.Security.Cryptography.Native.Apple/pal_networkframework.hDeclare PAL APIs for Network.framework
src/native/libs/System.Security.Cryptography.Native.Apple/extra_libs.cmakeInclude Network library in extra linking
src/native/libs/System.Security.Cryptography.Native.Apple/entrypoints.cExport new Network.framework entry points
src/native/libs/System.Security.Cryptography.Native.Apple/CMakeLists.txtAdd pal_networkframework.m to native sources
src/mono/msbuild/apple/build/AppleBuild.targetsLink Network framework in Mono MSBuild targets
src/libraries/System.Net.Security/tests/FunctionalTests/*.csUpdate tests to skip or adapt when Network.framework is enabled
src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.Windows.csExpose custom-alert capability on Windows
src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.Unix.csExpose custom-alert capability on Unix
src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.OSX.csExtend PAL to detect and route to Network.framework contexts
src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.Android.csExpose custom-alert capability on Android
src/libraries/System.Net.Security/src/System/Net/Security/SslStream.Protocol.csAdd gating logic and async context selection
src/libraries/System.Net.Security/src/System/Net/Security/SslStream.IO.csSupport async read/write via Network.framework context
src/libraries/System.Net.Security/src/System/Net/Security/SslConnectionInfo.OSX.csHandle connection info for both PAL contexts
src/libraries/System.Net.Security/src/System/Net/Security/Pal.OSX/SafeDeleteSslContext.csRefactor status codes to use Interop.AppleCrypto.OSStatus
src/libraries/System.Net.Security/src/System/Net/Security/Pal.OSX/SafeDeleteNwContext.csImplement SafeDeleteNwContext for Network.framework
src/libraries/System.Net.Security/src/System/Net/Security/Pal.Managed/SslProtocolsValidation.csChange ValidateContiguous to accept ReadOnlySpan<SslProtocols>
src/libraries/System.Net.Security/src/System/Net/CertificateValidationPal.OSX.csUse SecTrustRef for hostname validation in both contexts
src/libraries/System.Net.Security/src/System.Net.Security.csprojDefine TARGET_APPLE and include new interop files
src/libraries/Common/tests/TestUtilities/System/PlatformDetection.csAdd detection for Network.framework and TLS 1.3 client/server support
src/libraries/Common/src/System/Net/ReadWriteAdapter.csExtend IReadWriteAdapter with Task/ValueTask overloads
src/libraries/Common/src/Interop/OSX/System.Security.Cryptography.Native.Apple/Interop.Ssl.csUpdate p/invoke for the new hostname-match signature
src/libraries/Common/src/Interop/OSX/System.Security.Cryptography.Native.Apple/Interop.OSStatus.csAdd OSStatus constants for native error mapping
src/libraries/Common/src/Interop/OSX/Interop.NetworkFramework.csDeclare basic Network.framework interop and error handling
src/libraries/Common/src/Interop/OSX/Interop.NetworkFramework.Tls.csDeclare TLS entry points for the Network.framework shim
src/libraries/Common/src/Interop/OSX/Interop.Libraries.csAdd NetworkFramework library constant
src/coreclr/nativeaot/BuildIntegration/Microsoft.NETCore.Native.Unix.targetsLink Network framework in NativeAOT Unix builds
Comments suppressed due to low confidence (2)

src/native/libs/System.Security.Cryptography.Native.Apple/pal_networkframework.m:1

  • The new Network.framework integration layer is extensive but currently has no direct unit or functional tests; adding tests for handshake, send/receive, and error paths on macOS would help validate this feature.
// Licensed to the .NET Foundation under one or more agreements.

src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.OSX.cs:4

  • The using directives for System.IO, System.Threading, and System.Threading.Tasks appear unused in this file; consider removing them to reduce clutter.
using System.IO;

@build-analysisbuild-analysisBot mentioned this pull request Jul 15, 2025
Comment threadsrc/libraries/Common/tests/TestUtilities/System/PlatformDetection.cs Outdated
…networkframework.m
Co-authored-by: Adeel Mujahid <3840695+am11@users.noreply.github.com>

@wfurtwfurt left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. this is big milestone.

@rzikm

Copy link
Copy Markdown
MemberAuthor

/ba-g WASM failures are unrelated, linux failures are unrelated

Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@rzikm@vcsjones@filipnavara@am11@wfurt@liveans
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Client-side TLS 1.3 support on OSX - #117428

Merged
rzikm merged 88 commits into
dotnet:mainfrom
rzikm:osx-tls13
Jul 17, 2025
Merged

Client-side TLS 1.3 support on OSX#117428
rzikm merged 88 commits into
dotnet:mainfrom
rzikm:osx-tls13

Conversation

@rzikm

@rzikmrzikm commented Jul 8, 2025

Copy link
Copy Markdown
Member

Replaces #117016.

The goal is to integrate the new NetworkFramework to support client-side TLS 1.3 on OSX to unblock developers working on OSX. The feature is gated behind one of the following

  • System.Net.Security.UseNetworkFramework AppCtx switch
  • DOTNET_SYSTEM_NET_SECURITY_USENETWORKFRAMEWORK environment variable

Ahmet İbrahim Aksoyand others added 30 commits June 16, 2025 19:54
…amework.m
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Stephen Toub <stoub@microsoft.com>
Co-authored-by: Radek Zikmund <32671551+rzikm@users.noreply.github.com>
@rzikm

Copy link
Copy Markdown
MemberAuthor

Removing WIP status as we are getting stable. The target is to merge this PR before the end of week

@rzikmrzikm changed the title [WIP] TLS 1.3 on OSX supportClient-side TLS 1.3 support on OSXJul 14, 2025
@liveans
liveans requested a review from CopilotJuly 14, 2025 15:45

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

Integrates Network.framework for client-side TLS 1.3 on macOS, selectable via an AppContext switch or environment variable

  • Link the Network framework in build scripts (CMake, MSBuild, extra_libs.cmake)
  • Introduce a pal_networkframework native module and wire it up through new C# PAL types (SafeDeleteNwContext, interop)
  • Extend SslStream to choose between SecureTransport and Network.framework paths and update functional tests to skip or adapt when using Network.framework

Reviewed Changes

Copilot reviewed 37 out of 38 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
src/tasks/LibraryBuilder/Templates/CMakeLists.txt.templateLink Network framework for library builds
src/tasks/AppleAppBuilder/Templates/CMakeLists.txt.templateLink Network framework for app builder
src/tasks/AppleAppBuilder/Templates/CMakeLists-librarymode.txt.templateLink Network framework in library mode
src/native/libs/System.Security.Cryptography.Native.Apple/pal_ssl.hChange hostname-match API to accept a SecTrustRef
src/native/libs/System.Security.Cryptography.Native.Apple/pal_ssl.cAdapt hostname-match implementation to use the passed-in trust
src/native/libs/System.Security.Cryptography.Native.Apple/pal_networkframework.mAdd Network.framework–based TLS I/O implementation
src/native/libs/System.Security.Cryptography.Native.Apple/pal_networkframework.hDeclare PAL APIs for Network.framework
src/native/libs/System.Security.Cryptography.Native.Apple/extra_libs.cmakeInclude Network library in extra linking
src/native/libs/System.Security.Cryptography.Native.Apple/entrypoints.cExport new Network.framework entry points
src/native/libs/System.Security.Cryptography.Native.Apple/CMakeLists.txtAdd pal_networkframework.m to native sources
src/mono/msbuild/apple/build/AppleBuild.targetsLink Network framework in Mono MSBuild targets
src/libraries/System.Net.Security/tests/FunctionalTests/*.csUpdate tests to skip or adapt when Network.framework is enabled
src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.Windows.csExpose custom-alert capability on Windows
src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.Unix.csExpose custom-alert capability on Unix
src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.OSX.csExtend PAL to detect and route to Network.framework contexts
src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.Android.csExpose custom-alert capability on Android
src/libraries/System.Net.Security/src/System/Net/Security/SslStream.Protocol.csAdd gating logic and async context selection
src/libraries/System.Net.Security/src/System/Net/Security/SslStream.IO.csSupport async read/write via Network.framework context
src/libraries/System.Net.Security/src/System/Net/Security/SslConnectionInfo.OSX.csHandle connection info for both PAL contexts
src/libraries/System.Net.Security/src/System/Net/Security/Pal.OSX/SafeDeleteSslContext.csRefactor status codes to use Interop.AppleCrypto.OSStatus
src/libraries/System.Net.Security/src/System/Net/Security/Pal.OSX/SafeDeleteNwContext.csImplement SafeDeleteNwContext for Network.framework
src/libraries/System.Net.Security/src/System/Net/Security/Pal.Managed/SslProtocolsValidation.csChange ValidateContiguous to accept ReadOnlySpan<SslProtocols>
src/libraries/System.Net.Security/src/System/Net/CertificateValidationPal.OSX.csUse SecTrustRef for hostname validation in both contexts
src/libraries/System.Net.Security/src/System.Net.Security.csprojDefine TARGET_APPLE and include new interop files
src/libraries/Common/tests/TestUtilities/System/PlatformDetection.csAdd detection for Network.framework and TLS 1.3 client/server support
src/libraries/Common/src/System/Net/ReadWriteAdapter.csExtend IReadWriteAdapter with Task/ValueTask overloads
src/libraries/Common/src/Interop/OSX/System.Security.Cryptography.Native.Apple/Interop.Ssl.csUpdate p/invoke for the new hostname-match signature
src/libraries/Common/src/Interop/OSX/System.Security.Cryptography.Native.Apple/Interop.OSStatus.csAdd OSStatus constants for native error mapping
src/libraries/Common/src/Interop/OSX/Interop.NetworkFramework.csDeclare basic Network.framework interop and error handling
src/libraries/Common/src/Interop/OSX/Interop.NetworkFramework.Tls.csDeclare TLS entry points for the Network.framework shim
src/libraries/Common/src/Interop/OSX/Interop.Libraries.csAdd NetworkFramework library constant
src/coreclr/nativeaot/BuildIntegration/Microsoft.NETCore.Native.Unix.targetsLink Network framework in NativeAOT Unix builds
Comments suppressed due to low confidence (2)

src/native/libs/System.Security.Cryptography.Native.Apple/pal_networkframework.m:1

  • The new Network.framework integration layer is extensive but currently has no direct unit or functional tests; adding tests for handshake, send/receive, and error paths on macOS would help validate this feature.
// Licensed to the .NET Foundation under one or more agreements.

src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.OSX.cs:4

  • The using directives for System.IO, System.Threading, and System.Threading.Tasks appear unused in this file; consider removing them to reduce clutter.
using System.IO;

@build-analysisbuild-analysisBot mentioned this pull request Jul 15, 2025
Comment threadsrc/libraries/Common/tests/TestUtilities/System/PlatformDetection.cs Outdated
…networkframework.m
Co-authored-by: Adeel Mujahid <3840695+am11@users.noreply.github.com>

@wfurtwfurt left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. this is big milestone.

@rzikm

Copy link
Copy Markdown
MemberAuthor

/ba-g WASM failures are unrelated, linux failures are unrelated

Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@rzikm@vcsjones@filipnavara@am11@wfurt@liveans
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Client-side TLS 1.3 support on OSX - #117428

Merged
rzikm merged 88 commits into
dotnet:mainfrom
rzikm:osx-tls13
Jul 17, 2025
Merged

Client-side TLS 1.3 support on OSX#117428
rzikm merged 88 commits into
dotnet:mainfrom
rzikm:osx-tls13

Conversation

@rzikm

@rzikmrzikm commented Jul 8, 2025

Copy link
Copy Markdown
Member

Replaces #117016.

The goal is to integrate the new NetworkFramework to support client-side TLS 1.3 on OSX to unblock developers working on OSX. The feature is gated behind one of the following

  • System.Net.Security.UseNetworkFramework AppCtx switch
  • DOTNET_SYSTEM_NET_SECURITY_USENETWORKFRAMEWORK environment variable

Ahmet İbrahim Aksoyand others added 30 commits June 16, 2025 19:54
…amework.m
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Stephen Toub <stoub@microsoft.com>
Co-authored-by: Radek Zikmund <32671551+rzikm@users.noreply.github.com>
@rzikm

Copy link
Copy Markdown
MemberAuthor

Removing WIP status as we are getting stable. The target is to merge this PR before the end of week

@rzikmrzikm changed the title [WIP] TLS 1.3 on OSX supportClient-side TLS 1.3 support on OSXJul 14, 2025
@liveans
liveans requested a review from CopilotJuly 14, 2025 15:45

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

Integrates Network.framework for client-side TLS 1.3 on macOS, selectable via an AppContext switch or environment variable

  • Link the Network framework in build scripts (CMake, MSBuild, extra_libs.cmake)
  • Introduce a pal_networkframework native module and wire it up through new C# PAL types (SafeDeleteNwContext, interop)
  • Extend SslStream to choose between SecureTransport and Network.framework paths and update functional tests to skip or adapt when using Network.framework

Reviewed Changes

Copilot reviewed 37 out of 38 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
src/tasks/LibraryBuilder/Templates/CMakeLists.txt.templateLink Network framework for library builds
src/tasks/AppleAppBuilder/Templates/CMakeLists.txt.templateLink Network framework for app builder
src/tasks/AppleAppBuilder/Templates/CMakeLists-librarymode.txt.templateLink Network framework in library mode
src/native/libs/System.Security.Cryptography.Native.Apple/pal_ssl.hChange hostname-match API to accept a SecTrustRef
src/native/libs/System.Security.Cryptography.Native.Apple/pal_ssl.cAdapt hostname-match implementation to use the passed-in trust
src/native/libs/System.Security.Cryptography.Native.Apple/pal_networkframework.mAdd Network.framework–based TLS I/O implementation
src/native/libs/System.Security.Cryptography.Native.Apple/pal_networkframework.hDeclare PAL APIs for Network.framework
src/native/libs/System.Security.Cryptography.Native.Apple/extra_libs.cmakeInclude Network library in extra linking
src/native/libs/System.Security.Cryptography.Native.Apple/entrypoints.cExport new Network.framework entry points
src/native/libs/System.Security.Cryptography.Native.Apple/CMakeLists.txtAdd pal_networkframework.m to native sources
src/mono/msbuild/apple/build/AppleBuild.targetsLink Network framework in Mono MSBuild targets
src/libraries/System.Net.Security/tests/FunctionalTests/*.csUpdate tests to skip or adapt when Network.framework is enabled
src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.Windows.csExpose custom-alert capability on Windows
src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.Unix.csExpose custom-alert capability on Unix
src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.OSX.csExtend PAL to detect and route to Network.framework contexts
src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.Android.csExpose custom-alert capability on Android
src/libraries/System.Net.Security/src/System/Net/Security/SslStream.Protocol.csAdd gating logic and async context selection
src/libraries/System.Net.Security/src/System/Net/Security/SslStream.IO.csSupport async read/write via Network.framework context
src/libraries/System.Net.Security/src/System/Net/Security/SslConnectionInfo.OSX.csHandle connection info for both PAL contexts
src/libraries/System.Net.Security/src/System/Net/Security/Pal.OSX/SafeDeleteSslContext.csRefactor status codes to use Interop.AppleCrypto.OSStatus
src/libraries/System.Net.Security/src/System/Net/Security/Pal.OSX/SafeDeleteNwContext.csImplement SafeDeleteNwContext for Network.framework
src/libraries/System.Net.Security/src/System/Net/Security/Pal.Managed/SslProtocolsValidation.csChange ValidateContiguous to accept ReadOnlySpan<SslProtocols>
src/libraries/System.Net.Security/src/System/Net/CertificateValidationPal.OSX.csUse SecTrustRef for hostname validation in both contexts
src/libraries/System.Net.Security/src/System.Net.Security.csprojDefine TARGET_APPLE and include new interop files
src/libraries/Common/tests/TestUtilities/System/PlatformDetection.csAdd detection for Network.framework and TLS 1.3 client/server support
src/libraries/Common/src/System/Net/ReadWriteAdapter.csExtend IReadWriteAdapter with Task/ValueTask overloads
src/libraries/Common/src/Interop/OSX/System.Security.Cryptography.Native.Apple/Interop.Ssl.csUpdate p/invoke for the new hostname-match signature
src/libraries/Common/src/Interop/OSX/System.Security.Cryptography.Native.Apple/Interop.OSStatus.csAdd OSStatus constants for native error mapping
src/libraries/Common/src/Interop/OSX/Interop.NetworkFramework.csDeclare basic Network.framework interop and error handling
src/libraries/Common/src/Interop/OSX/Interop.NetworkFramework.Tls.csDeclare TLS entry points for the Network.framework shim
src/libraries/Common/src/Interop/OSX/Interop.Libraries.csAdd NetworkFramework library constant
src/coreclr/nativeaot/BuildIntegration/Microsoft.NETCore.Native.Unix.targetsLink Network framework in NativeAOT Unix builds
Comments suppressed due to low confidence (2)

src/native/libs/System.Security.Cryptography.Native.Apple/pal_networkframework.m:1

  • The new Network.framework integration layer is extensive but currently has no direct unit or functional tests; adding tests for handshake, send/receive, and error paths on macOS would help validate this feature.
// Licensed to the .NET Foundation under one or more agreements.

src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.OSX.cs:4

  • The using directives for System.IO, System.Threading, and System.Threading.Tasks appear unused in this file; consider removing them to reduce clutter.
using System.IO;

@build-analysisbuild-analysisBot mentioned this pull request Jul 15, 2025
Comment threadsrc/libraries/Common/tests/TestUtilities/System/PlatformDetection.cs Outdated
…networkframework.m
Co-authored-by: Adeel Mujahid <3840695+am11@users.noreply.github.com>

@wfurtwfurt left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. this is big milestone.

@rzikm

Copy link
Copy Markdown
MemberAuthor

/ba-g WASM failures are unrelated, linux failures are unrelated

Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@rzikm@vcsjones@filipnavara@am11@wfurt@liveans
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Client-side TLS 1.3 support on OSX - #117428

Merged
rzikm merged 88 commits into
dotnet:mainfrom
rzikm:osx-tls13
Jul 17, 2025
Merged

Client-side TLS 1.3 support on OSX#117428
rzikm merged 88 commits into
dotnet:mainfrom
rzikm:osx-tls13

Conversation

@rzikm

@rzikmrzikm commented Jul 8, 2025

Copy link
Copy Markdown
Member

Replaces #117016.

The goal is to integrate the new NetworkFramework to support client-side TLS 1.3 on OSX to unblock developers working on OSX. The feature is gated behind one of the following

  • System.Net.Security.UseNetworkFramework AppCtx switch
  • DOTNET_SYSTEM_NET_SECURITY_USENETWORKFRAMEWORK environment variable

Ahmet İbrahim Aksoyand others added 30 commits June 16, 2025 19:54
…amework.m
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Stephen Toub <stoub@microsoft.com>
Co-authored-by: Radek Zikmund <32671551+rzikm@users.noreply.github.com>
@rzikm

Copy link
Copy Markdown
MemberAuthor

Removing WIP status as we are getting stable. The target is to merge this PR before the end of week

@rzikmrzikm changed the title [WIP] TLS 1.3 on OSX supportClient-side TLS 1.3 support on OSXJul 14, 2025
@liveans
liveans requested a review from CopilotJuly 14, 2025 15:45

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

Integrates Network.framework for client-side TLS 1.3 on macOS, selectable via an AppContext switch or environment variable

  • Link the Network framework in build scripts (CMake, MSBuild, extra_libs.cmake)
  • Introduce a pal_networkframework native module and wire it up through new C# PAL types (SafeDeleteNwContext, interop)
  • Extend SslStream to choose between SecureTransport and Network.framework paths and update functional tests to skip or adapt when using Network.framework

Reviewed Changes

Copilot reviewed 37 out of 38 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
src/tasks/LibraryBuilder/Templates/CMakeLists.txt.templateLink Network framework for library builds
src/tasks/AppleAppBuilder/Templates/CMakeLists.txt.templateLink Network framework for app builder
src/tasks/AppleAppBuilder/Templates/CMakeLists-librarymode.txt.templateLink Network framework in library mode
src/native/libs/System.Security.Cryptography.Native.Apple/pal_ssl.hChange hostname-match API to accept a SecTrustRef
src/native/libs/System.Security.Cryptography.Native.Apple/pal_ssl.cAdapt hostname-match implementation to use the passed-in trust
src/native/libs/System.Security.Cryptography.Native.Apple/pal_networkframework.mAdd Network.framework–based TLS I/O implementation
src/native/libs/System.Security.Cryptography.Native.Apple/pal_networkframework.hDeclare PAL APIs for Network.framework
src/native/libs/System.Security.Cryptography.Native.Apple/extra_libs.cmakeInclude Network library in extra linking
src/native/libs/System.Security.Cryptography.Native.Apple/entrypoints.cExport new Network.framework entry points
src/native/libs/System.Security.Cryptography.Native.Apple/CMakeLists.txtAdd pal_networkframework.m to native sources
src/mono/msbuild/apple/build/AppleBuild.targetsLink Network framework in Mono MSBuild targets
src/libraries/System.Net.Security/tests/FunctionalTests/*.csUpdate tests to skip or adapt when Network.framework is enabled
src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.Windows.csExpose custom-alert capability on Windows
src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.Unix.csExpose custom-alert capability on Unix
src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.OSX.csExtend PAL to detect and route to Network.framework contexts
src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.Android.csExpose custom-alert capability on Android
src/libraries/System.Net.Security/src/System/Net/Security/SslStream.Protocol.csAdd gating logic and async context selection
src/libraries/System.Net.Security/src/System/Net/Security/SslStream.IO.csSupport async read/write via Network.framework context
src/libraries/System.Net.Security/src/System/Net/Security/SslConnectionInfo.OSX.csHandle connection info for both PAL contexts
src/libraries/System.Net.Security/src/System/Net/Security/Pal.OSX/SafeDeleteSslContext.csRefactor status codes to use Interop.AppleCrypto.OSStatus
src/libraries/System.Net.Security/src/System/Net/Security/Pal.OSX/SafeDeleteNwContext.csImplement SafeDeleteNwContext for Network.framework
src/libraries/System.Net.Security/src/System/Net/Security/Pal.Managed/SslProtocolsValidation.csChange ValidateContiguous to accept ReadOnlySpan<SslProtocols>
src/libraries/System.Net.Security/src/System/Net/CertificateValidationPal.OSX.csUse SecTrustRef for hostname validation in both contexts
src/libraries/System.Net.Security/src/System.Net.Security.csprojDefine TARGET_APPLE and include new interop files
src/libraries/Common/tests/TestUtilities/System/PlatformDetection.csAdd detection for Network.framework and TLS 1.3 client/server support
src/libraries/Common/src/System/Net/ReadWriteAdapter.csExtend IReadWriteAdapter with Task/ValueTask overloads
src/libraries/Common/src/Interop/OSX/System.Security.Cryptography.Native.Apple/Interop.Ssl.csUpdate p/invoke for the new hostname-match signature
src/libraries/Common/src/Interop/OSX/System.Security.Cryptography.Native.Apple/Interop.OSStatus.csAdd OSStatus constants for native error mapping
src/libraries/Common/src/Interop/OSX/Interop.NetworkFramework.csDeclare basic Network.framework interop and error handling
src/libraries/Common/src/Interop/OSX/Interop.NetworkFramework.Tls.csDeclare TLS entry points for the Network.framework shim
src/libraries/Common/src/Interop/OSX/Interop.Libraries.csAdd NetworkFramework library constant
src/coreclr/nativeaot/BuildIntegration/Microsoft.NETCore.Native.Unix.targetsLink Network framework in NativeAOT Unix builds
Comments suppressed due to low confidence (2)

src/native/libs/System.Security.Cryptography.Native.Apple/pal_networkframework.m:1

  • The new Network.framework integration layer is extensive but currently has no direct unit or functional tests; adding tests for handshake, send/receive, and error paths on macOS would help validate this feature.
// Licensed to the .NET Foundation under one or more agreements.

src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.OSX.cs:4

  • The using directives for System.IO, System.Threading, and System.Threading.Tasks appear unused in this file; consider removing them to reduce clutter.
using System.IO;

@build-analysisbuild-analysisBot mentioned this pull request Jul 15, 2025
Comment threadsrc/libraries/Common/tests/TestUtilities/System/PlatformDetection.cs Outdated
…networkframework.m
Co-authored-by: Adeel Mujahid <3840695+am11@users.noreply.github.com>

@wfurtwfurt left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. this is big milestone.

@rzikm

Copy link
Copy Markdown
MemberAuthor

/ba-g WASM failures are unrelated, linux failures are unrelated

Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@rzikm@vcsjones@filipnavara@am11@wfurt@liveans
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Client-side TLS 1.3 support on OSX - #117428

Merged
rzikm merged 88 commits into
dotnet:mainfrom
rzikm:osx-tls13
Jul 17, 2025
Merged

Client-side TLS 1.3 support on OSX#117428
rzikm merged 88 commits into
dotnet:mainfrom
rzikm:osx-tls13

Conversation

@rzikm

@rzikmrzikm commented Jul 8, 2025

Copy link
Copy Markdown
Member

Replaces #117016.

The goal is to integrate the new NetworkFramework to support client-side TLS 1.3 on OSX to unblock developers working on OSX. The feature is gated behind one of the following

  • System.Net.Security.UseNetworkFramework AppCtx switch
  • DOTNET_SYSTEM_NET_SECURITY_USENETWORKFRAMEWORK environment variable

Ahmet İbrahim Aksoyand others added 30 commits June 16, 2025 19:54
…amework.m
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Stephen Toub <stoub@microsoft.com>
Co-authored-by: Radek Zikmund <32671551+rzikm@users.noreply.github.com>
@rzikm

Copy link
Copy Markdown
MemberAuthor

Removing WIP status as we are getting stable. The target is to merge this PR before the end of week

@rzikmrzikm changed the title [WIP] TLS 1.3 on OSX supportClient-side TLS 1.3 support on OSXJul 14, 2025
@liveans
liveans requested a review from CopilotJuly 14, 2025 15:45

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

Integrates Network.framework for client-side TLS 1.3 on macOS, selectable via an AppContext switch or environment variable

  • Link the Network framework in build scripts (CMake, MSBuild, extra_libs.cmake)
  • Introduce a pal_networkframework native module and wire it up through new C# PAL types (SafeDeleteNwContext, interop)
  • Extend SslStream to choose between SecureTransport and Network.framework paths and update functional tests to skip or adapt when using Network.framework

Reviewed Changes

Copilot reviewed 37 out of 38 changed files in this pull request and generated no comments.

Show a summary per file
FileDescription
src/tasks/LibraryBuilder/Templates/CMakeLists.txt.templateLink Network framework for library builds
src/tasks/AppleAppBuilder/Templates/CMakeLists.txt.templateLink Network framework for app builder
src/tasks/AppleAppBuilder/Templates/CMakeLists-librarymode.txt.templateLink Network framework in library mode
src/native/libs/System.Security.Cryptography.Native.Apple/pal_ssl.hChange hostname-match API to accept a SecTrustRef
src/native/libs/System.Security.Cryptography.Native.Apple/pal_ssl.cAdapt hostname-match implementation to use the passed-in trust
src/native/libs/System.Security.Cryptography.Native.Apple/pal_networkframework.mAdd Network.framework–based TLS I/O implementation
src/native/libs/System.Security.Cryptography.Native.Apple/pal_networkframework.hDeclare PAL APIs for Network.framework
src/native/libs/System.Security.Cryptography.Native.Apple/extra_libs.cmakeInclude Network library in extra linking
src/native/libs/System.Security.Cryptography.Native.Apple/entrypoints.cExport new Network.framework entry points
src/native/libs/System.Security.Cryptography.Native.Apple/CMakeLists.txtAdd pal_networkframework.m to native sources
src/mono/msbuild/apple/build/AppleBuild.targetsLink Network framework in Mono MSBuild targets
src/libraries/System.Net.Security/tests/FunctionalTests/*.csUpdate tests to skip or adapt when Network.framework is enabled
src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.Windows.csExpose custom-alert capability on Windows
src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.Unix.csExpose custom-alert capability on Unix
src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.OSX.csExtend PAL to detect and route to Network.framework contexts
src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.Android.csExpose custom-alert capability on Android
src/libraries/System.Net.Security/src/System/Net/Security/SslStream.Protocol.csAdd gating logic and async context selection
src/libraries/System.Net.Security/src/System/Net/Security/SslStream.IO.csSupport async read/write via Network.framework context
src/libraries/System.Net.Security/src/System/Net/Security/SslConnectionInfo.OSX.csHandle connection info for both PAL contexts
src/libraries/System.Net.Security/src/System/Net/Security/Pal.OSX/SafeDeleteSslContext.csRefactor status codes to use Interop.AppleCrypto.OSStatus
src/libraries/System.Net.Security/src/System/Net/Security/Pal.OSX/SafeDeleteNwContext.csImplement SafeDeleteNwContext for Network.framework
src/libraries/System.Net.Security/src/System/Net/Security/Pal.Managed/SslProtocolsValidation.csChange ValidateContiguous to accept ReadOnlySpan<SslProtocols>
src/libraries/System.Net.Security/src/System/Net/CertificateValidationPal.OSX.csUse SecTrustRef for hostname validation in both contexts
src/libraries/System.Net.Security/src/System.Net.Security.csprojDefine TARGET_APPLE and include new interop files
src/libraries/Common/tests/TestUtilities/System/PlatformDetection.csAdd detection for Network.framework and TLS 1.3 client/server support
src/libraries/Common/src/System/Net/ReadWriteAdapter.csExtend IReadWriteAdapter with Task/ValueTask overloads
src/libraries/Common/src/Interop/OSX/System.Security.Cryptography.Native.Apple/Interop.Ssl.csUpdate p/invoke for the new hostname-match signature
src/libraries/Common/src/Interop/OSX/System.Security.Cryptography.Native.Apple/Interop.OSStatus.csAdd OSStatus constants for native error mapping
src/libraries/Common/src/Interop/OSX/Interop.NetworkFramework.csDeclare basic Network.framework interop and error handling
src/libraries/Common/src/Interop/OSX/Interop.NetworkFramework.Tls.csDeclare TLS entry points for the Network.framework shim
src/libraries/Common/src/Interop/OSX/Interop.Libraries.csAdd NetworkFramework library constant
src/coreclr/nativeaot/BuildIntegration/Microsoft.NETCore.Native.Unix.targetsLink Network framework in NativeAOT Unix builds
Comments suppressed due to low confidence (2)

src/native/libs/System.Security.Cryptography.Native.Apple/pal_networkframework.m:1

  • The new Network.framework integration layer is extensive but currently has no direct unit or functional tests; adding tests for handshake, send/receive, and error paths on macOS would help validate this feature.
// Licensed to the .NET Foundation under one or more agreements.

src/libraries/System.Net.Security/src/System/Net/Security/SslStreamPal.OSX.cs:4

  • The using directives for System.IO, System.Threading, and System.Threading.Tasks appear unused in this file; consider removing them to reduce clutter.
using System.IO;

@build-analysisbuild-analysisBot mentioned this pull request Jul 15, 2025
Comment threadsrc/libraries/Common/tests/TestUtilities/System/PlatformDetection.cs Outdated
…networkframework.m
Co-authored-by: Adeel Mujahid <3840695+am11@users.noreply.github.com>

@wfurtwfurt left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. this is big milestone.

@rzikm

Copy link
Copy Markdown
MemberAuthor

/ba-g WASM failures are unrelated, linux failures are unrelated

Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants

@rzikm@vcsjones@filipnavara@am11@wfurt@liveans