Clarify why and make text and sequence streams non-seekable - #132023

Merged
jozkee merged 4 commits into
dotnet:mainfrom
jozkee:agents/copy-artifacts-and-implement-seek-tests-0dd68e98
Aug 11, 2026
Merged

Clarify why and make text and sequence streams non-seekable#132023
jozkee merged 4 commits into
dotnet:mainfrom
jozkee:agents/copy-artifacts-and-implement-seek-tests-0dd68e98

Conversation

@jozkee

@jozkeejozkee commented Aug 7, 2026

Copy link
Copy Markdown
Member

Summary

  • clarify that ReadOnlyMemoryStream and WritableMemoryStream immediately expose their backing memory contents
  • make ReadOnlySequenceStream intentionally non-seekable and remove its seek state and traversal logic
  • keep StringStream intentionally non-seekable and document why backward positioning would require rerunning the encoder
  • make Length, Position, and Seek consistently throw the standard unseekable-stream NotSupportedException
  • update stream conformance and focused unit coverage
  • For Writable memory stream, added ctor remarks suggesting users to clear rented or reused memory before constructing the stream if its existing contents should not be exposed.

Rationale

Backward positioning requires replaying work from the beginning. For ReadOnlySequenceStream, that means traversing segments whose boundaries may be indirectly controlled by an untrusted network client through packet framing. Even correct stitching can therefore produce adversarial fragmentation, and consumers must tolerate the worst technically compliant segmentation rather than assuming ASP.NET-like behavior. For StringStream, backward positioning requires rerunning the encoder. Repeated seeks can turn both cases into worst-case O(N) work.

Validation

  • checked and Release CoreLib builds
  • System.Memory build
  • 405 focused ReadOnlySequenceStream conformance tests
  • 275 focused StringStream conformance/unit tests

Note

This pull request description was generated with GitHub Copilot.

jozkeeand others added 2 commits August 7, 2026 12:28
Clarify that read-only and writable memory streams expose the existing contents of supplied memory, including guidance for rented or reused buffers.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Prevent backward positioning from repeatedly replaying segmented sequences or encoded text. Keep Length, Position, and Seek consistent with the standard non-seekable Stream contract, and update conformance coverage.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR aligns several Stream implementations with an intentionally non-seekable contract (notably ReadOnlySequenceStream, and reinforcing StringStream expectations) and updates docs/tests accordingly, including clarifying that the memory-backed streams expose existing buffer contents immediately.

Changes:

  • Make ReadOnlySequenceStream intentionally non-seekable by removing seek state/traversal and having Length/Position/Seek throw NotSupportedException consistently.
  • Clarify ReadOnlyMemoryStream / WritableMemoryStream docs that backing memory contents are immediately readable.
  • Update conformance and focused unit tests to reflect the non-seekable behavior and exception expectations.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
src/libraries/System.Runtime/tests/System.IO.Tests/StringStream/StringStreamTests_String.csExtends capability tests to assert unseekable members throw NotSupportedException.
src/libraries/System.Private.CoreLib/src/System/IO/WritableMemoryStream.csDoc updates clarifying immediate exposure of existing buffer contents.
src/libraries/System.Private.CoreLib/src/System/IO/StringStream.csAdds rationale comment for keeping the stream non-seekable.
src/libraries/System.Private.CoreLib/src/System/IO/ReadOnlyMemoryStream.csDoc updates clarifying immediate exposure (and minor wording tweak needed).
src/libraries/System.Memory/tests/ReadOnlyBuffer/ReadOnlySequenceStream.ConformanceTests.csUpdates conformance configuration to treat the stream as non-seekable; removes seek-specific override.
src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.csImplements non-seekable contract; removes seek/position bookkeeping and logic.
src/libraries/System.Memory/src/Resources/Strings.resxAdds NotSupported_UnseekableStream resource; removes no-longer-needed seek-related resource strings.

Comment threadsrc/libraries/System.Private.CoreLib/src/System/IO/ReadOnlyMemoryStream.cs Outdated
Reuse the sliced sequence in CopyToAsync and clarify stream wrapper documentation.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings August 7, 2026 19:45

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated no new comments.

Suppressed comments (3)

src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.cs:173

  • CopyToAsyncCore only assigns _position = _sequence.End after the full loop completes. If WriteAsync throws/cancels after some segments were written, the stream’s _position stays at the original value and subsequent reads can replay already-transferred bytes.

Advance _position after each successfully completed WriteAsync call.

 {
await destination.WriteAsync(segment, cancellationToken).ConfigureAwait(false);
}
_position = _sequence.End;

src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.cs:44

  • This change makes a previously-seekable public Stream (ReadOnlySequenceStream is in System.Memory ref) report CanSeek == false and throw NotSupportedException from Length/Position/Seek. That’s a behavioral breaking change for existing consumers.

The PR description doesn’t reference a breaking-change tracking issue. Per docs/project/breaking-change-process.md, please link/create an issue marked breaking-change (with before/after behavior and mitigations) and reference it from the PR so reviewers can evaluate compatibility impact.

 // segment boundaries may be indirectly controlled by an untrusted network client through
// packet framing, so even correct stitching logic can produce adversarial fragmentation.
// Consumers must remain resilient against the worst technically compliant implementation
// rather than assuming ASP.NET-like segmentation.
public override bool CanSeek => false;

src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.cs:143

  • CopyTo writes multiple segments but only updates _position after the loop completes. If destination.Write(...) throws after some segments were successfully written, the stream will keep its old _position even though bytes were already consumed, so subsequent reads / retries can duplicate data.

Update _position after each successfully-written segment so the stream’s internal read position always reflects the bytes already transferred.

This issue also appears on line 169 of the same file.

 {
destination.Write(segment.Span);
}
_position = _sequence.End;

@adamsitnikadamsitnik left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Overall it LGTM, but I wonder if we should improve the XML doc comments before merging. Thank you for fixing it before the .NET 11 release @jozkee !

CopilotAI review requested due to automatic review settings August 10, 2026 16:37

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated no new comments.

Suppressed comments (1)

src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.cs:45

  • Changing ReadOnlySequenceStream to be non-seekable (CanSeek=false, and Length/Position/Seek throwing NotSupportedException) is a behavioral breaking change for a public type (see ref/System.Memory.cs). Per repo guidelines, this should go through the breaking-change process and include the required documentation/metadata updates (e.g., add the appropriate breaking-change entry per docs/project/breaking-change-process.md).
 /// <summary>Gets a value indicating whether the <see cref="ReadOnlySequenceStream"/> supports seeking.</summary>
// Keep this intentionally non-seekable: backward positioning requires traversing segments
// again from the beginning, making repeated seeks worst-case O(N). ReadOnlySequence<T>
// segment boundaries may be indirectly controlled by an untrusted network client through
// packet framing, so even correct stitching logic can produce adversarial fragmentation.
// Consumers must remain resilient against the worst technically compliant implementation
// rather than assuming ASP.NET-like segmentation.
public override bool CanSeek => false;

@adamsitnikadamsitnik left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I left a comment, PTAL @jozkee

@jozkee
jozkee requested a review from adamsitnikAugust 11, 2026 17:53

@ViveliDuChViveliDuCh left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks for the documentation effort!

@jozkee
jozkee merged commit 4b61662 into dotnet:mainAug 11, 2026
125 of 128 checks passed
@jozkee
jozkee deleted the agents/copy-artifacts-and-implement-seek-tests-0dd68e98 branch August 11, 2026 21:37
@jozkeejozkee changed the title System.IO: Make text and sequence streams non-seekableClarify why and make text and sequence streams non-seekableAug 12, 2026
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-rc1 milestone Aug 12, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@jozkee@adamsitnik@ViveliDuCh
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Clarify why and make text and sequence streams non-seekable - #132023

Merged
jozkee merged 4 commits into
dotnet:mainfrom
jozkee:agents/copy-artifacts-and-implement-seek-tests-0dd68e98
Aug 11, 2026
Merged

Clarify why and make text and sequence streams non-seekable#132023
jozkee merged 4 commits into
dotnet:mainfrom
jozkee:agents/copy-artifacts-and-implement-seek-tests-0dd68e98

Conversation

@jozkee

@jozkeejozkee commented Aug 7, 2026

Copy link
Copy Markdown
Member

Summary

  • clarify that ReadOnlyMemoryStream and WritableMemoryStream immediately expose their backing memory contents
  • make ReadOnlySequenceStream intentionally non-seekable and remove its seek state and traversal logic
  • keep StringStream intentionally non-seekable and document why backward positioning would require rerunning the encoder
  • make Length, Position, and Seek consistently throw the standard unseekable-stream NotSupportedException
  • update stream conformance and focused unit coverage
  • For Writable memory stream, added ctor remarks suggesting users to clear rented or reused memory before constructing the stream if its existing contents should not be exposed.

Rationale

Backward positioning requires replaying work from the beginning. For ReadOnlySequenceStream, that means traversing segments whose boundaries may be indirectly controlled by an untrusted network client through packet framing. Even correct stitching can therefore produce adversarial fragmentation, and consumers must tolerate the worst technically compliant segmentation rather than assuming ASP.NET-like behavior. For StringStream, backward positioning requires rerunning the encoder. Repeated seeks can turn both cases into worst-case O(N) work.

Validation

  • checked and Release CoreLib builds
  • System.Memory build
  • 405 focused ReadOnlySequenceStream conformance tests
  • 275 focused StringStream conformance/unit tests

Note

This pull request description was generated with GitHub Copilot.

jozkeeand others added 2 commits August 7, 2026 12:28
Clarify that read-only and writable memory streams expose the existing contents of supplied memory, including guidance for rented or reused buffers.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Prevent backward positioning from repeatedly replaying segmented sequences or encoded text. Keep Length, Position, and Seek consistent with the standard non-seekable Stream contract, and update conformance coverage.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR aligns several Stream implementations with an intentionally non-seekable contract (notably ReadOnlySequenceStream, and reinforcing StringStream expectations) and updates docs/tests accordingly, including clarifying that the memory-backed streams expose existing buffer contents immediately.

Changes:

  • Make ReadOnlySequenceStream intentionally non-seekable by removing seek state/traversal and having Length/Position/Seek throw NotSupportedException consistently.
  • Clarify ReadOnlyMemoryStream / WritableMemoryStream docs that backing memory contents are immediately readable.
  • Update conformance and focused unit tests to reflect the non-seekable behavior and exception expectations.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
src/libraries/System.Runtime/tests/System.IO.Tests/StringStream/StringStreamTests_String.csExtends capability tests to assert unseekable members throw NotSupportedException.
src/libraries/System.Private.CoreLib/src/System/IO/WritableMemoryStream.csDoc updates clarifying immediate exposure of existing buffer contents.
src/libraries/System.Private.CoreLib/src/System/IO/StringStream.csAdds rationale comment for keeping the stream non-seekable.
src/libraries/System.Private.CoreLib/src/System/IO/ReadOnlyMemoryStream.csDoc updates clarifying immediate exposure (and minor wording tweak needed).
src/libraries/System.Memory/tests/ReadOnlyBuffer/ReadOnlySequenceStream.ConformanceTests.csUpdates conformance configuration to treat the stream as non-seekable; removes seek-specific override.
src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.csImplements non-seekable contract; removes seek/position bookkeeping and logic.
src/libraries/System.Memory/src/Resources/Strings.resxAdds NotSupported_UnseekableStream resource; removes no-longer-needed seek-related resource strings.

Comment threadsrc/libraries/System.Private.CoreLib/src/System/IO/ReadOnlyMemoryStream.cs Outdated
Reuse the sliced sequence in CopyToAsync and clarify stream wrapper documentation.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings August 7, 2026 19:45

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated no new comments.

Suppressed comments (3)

src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.cs:173

  • CopyToAsyncCore only assigns _position = _sequence.End after the full loop completes. If WriteAsync throws/cancels after some segments were written, the stream’s _position stays at the original value and subsequent reads can replay already-transferred bytes.

Advance _position after each successfully completed WriteAsync call.

 {
await destination.WriteAsync(segment, cancellationToken).ConfigureAwait(false);
}
_position = _sequence.End;

src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.cs:44

  • This change makes a previously-seekable public Stream (ReadOnlySequenceStream is in System.Memory ref) report CanSeek == false and throw NotSupportedException from Length/Position/Seek. That’s a behavioral breaking change for existing consumers.

The PR description doesn’t reference a breaking-change tracking issue. Per docs/project/breaking-change-process.md, please link/create an issue marked breaking-change (with before/after behavior and mitigations) and reference it from the PR so reviewers can evaluate compatibility impact.

 // segment boundaries may be indirectly controlled by an untrusted network client through
// packet framing, so even correct stitching logic can produce adversarial fragmentation.
// Consumers must remain resilient against the worst technically compliant implementation
// rather than assuming ASP.NET-like segmentation.
public override bool CanSeek => false;

src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.cs:143

  • CopyTo writes multiple segments but only updates _position after the loop completes. If destination.Write(...) throws after some segments were successfully written, the stream will keep its old _position even though bytes were already consumed, so subsequent reads / retries can duplicate data.

Update _position after each successfully-written segment so the stream’s internal read position always reflects the bytes already transferred.

This issue also appears on line 169 of the same file.

 {
destination.Write(segment.Span);
}
_position = _sequence.End;

@adamsitnikadamsitnik left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Overall it LGTM, but I wonder if we should improve the XML doc comments before merging. Thank you for fixing it before the .NET 11 release @jozkee !

CopilotAI review requested due to automatic review settings August 10, 2026 16:37

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated no new comments.

Suppressed comments (1)

src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.cs:45

  • Changing ReadOnlySequenceStream to be non-seekable (CanSeek=false, and Length/Position/Seek throwing NotSupportedException) is a behavioral breaking change for a public type (see ref/System.Memory.cs). Per repo guidelines, this should go through the breaking-change process and include the required documentation/metadata updates (e.g., add the appropriate breaking-change entry per docs/project/breaking-change-process.md).
 /// <summary>Gets a value indicating whether the <see cref="ReadOnlySequenceStream"/> supports seeking.</summary>
// Keep this intentionally non-seekable: backward positioning requires traversing segments
// again from the beginning, making repeated seeks worst-case O(N). ReadOnlySequence<T>
// segment boundaries may be indirectly controlled by an untrusted network client through
// packet framing, so even correct stitching logic can produce adversarial fragmentation.
// Consumers must remain resilient against the worst technically compliant implementation
// rather than assuming ASP.NET-like segmentation.
public override bool CanSeek => false;

@adamsitnikadamsitnik left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I left a comment, PTAL @jozkee

@jozkee
jozkee requested a review from adamsitnikAugust 11, 2026 17:53

@ViveliDuChViveliDuCh left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks for the documentation effort!

@jozkee
jozkee merged commit 4b61662 into dotnet:mainAug 11, 2026
125 of 128 checks passed
@jozkee
jozkee deleted the agents/copy-artifacts-and-implement-seek-tests-0dd68e98 branch August 11, 2026 21:37
@jozkeejozkee changed the title System.IO: Make text and sequence streams non-seekableClarify why and make text and sequence streams non-seekableAug 12, 2026
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-rc1 milestone Aug 12, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@jozkee@adamsitnik@ViveliDuCh
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Clarify why and make text and sequence streams non-seekable - #132023

Merged
jozkee merged 4 commits into
dotnet:mainfrom
jozkee:agents/copy-artifacts-and-implement-seek-tests-0dd68e98
Aug 11, 2026
Merged

Clarify why and make text and sequence streams non-seekable#132023
jozkee merged 4 commits into
dotnet:mainfrom
jozkee:agents/copy-artifacts-and-implement-seek-tests-0dd68e98

Conversation

@jozkee

@jozkeejozkee commented Aug 7, 2026

Copy link
Copy Markdown
Member

Summary

  • clarify that ReadOnlyMemoryStream and WritableMemoryStream immediately expose their backing memory contents
  • make ReadOnlySequenceStream intentionally non-seekable and remove its seek state and traversal logic
  • keep StringStream intentionally non-seekable and document why backward positioning would require rerunning the encoder
  • make Length, Position, and Seek consistently throw the standard unseekable-stream NotSupportedException
  • update stream conformance and focused unit coverage
  • For Writable memory stream, added ctor remarks suggesting users to clear rented or reused memory before constructing the stream if its existing contents should not be exposed.

Rationale

Backward positioning requires replaying work from the beginning. For ReadOnlySequenceStream, that means traversing segments whose boundaries may be indirectly controlled by an untrusted network client through packet framing. Even correct stitching can therefore produce adversarial fragmentation, and consumers must tolerate the worst technically compliant segmentation rather than assuming ASP.NET-like behavior. For StringStream, backward positioning requires rerunning the encoder. Repeated seeks can turn both cases into worst-case O(N) work.

Validation

  • checked and Release CoreLib builds
  • System.Memory build
  • 405 focused ReadOnlySequenceStream conformance tests
  • 275 focused StringStream conformance/unit tests

Note

This pull request description was generated with GitHub Copilot.

jozkeeand others added 2 commits August 7, 2026 12:28
Clarify that read-only and writable memory streams expose the existing contents of supplied memory, including guidance for rented or reused buffers.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Prevent backward positioning from repeatedly replaying segmented sequences or encoded text. Keep Length, Position, and Seek consistent with the standard non-seekable Stream contract, and update conformance coverage.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR aligns several Stream implementations with an intentionally non-seekable contract (notably ReadOnlySequenceStream, and reinforcing StringStream expectations) and updates docs/tests accordingly, including clarifying that the memory-backed streams expose existing buffer contents immediately.

Changes:

  • Make ReadOnlySequenceStream intentionally non-seekable by removing seek state/traversal and having Length/Position/Seek throw NotSupportedException consistently.
  • Clarify ReadOnlyMemoryStream / WritableMemoryStream docs that backing memory contents are immediately readable.
  • Update conformance and focused unit tests to reflect the non-seekable behavior and exception expectations.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
src/libraries/System.Runtime/tests/System.IO.Tests/StringStream/StringStreamTests_String.csExtends capability tests to assert unseekable members throw NotSupportedException.
src/libraries/System.Private.CoreLib/src/System/IO/WritableMemoryStream.csDoc updates clarifying immediate exposure of existing buffer contents.
src/libraries/System.Private.CoreLib/src/System/IO/StringStream.csAdds rationale comment for keeping the stream non-seekable.
src/libraries/System.Private.CoreLib/src/System/IO/ReadOnlyMemoryStream.csDoc updates clarifying immediate exposure (and minor wording tweak needed).
src/libraries/System.Memory/tests/ReadOnlyBuffer/ReadOnlySequenceStream.ConformanceTests.csUpdates conformance configuration to treat the stream as non-seekable; removes seek-specific override.
src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.csImplements non-seekable contract; removes seek/position bookkeeping and logic.
src/libraries/System.Memory/src/Resources/Strings.resxAdds NotSupported_UnseekableStream resource; removes no-longer-needed seek-related resource strings.

Comment threadsrc/libraries/System.Private.CoreLib/src/System/IO/ReadOnlyMemoryStream.cs Outdated
Reuse the sliced sequence in CopyToAsync and clarify stream wrapper documentation.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings August 7, 2026 19:45

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated no new comments.

Suppressed comments (3)

src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.cs:173

  • CopyToAsyncCore only assigns _position = _sequence.End after the full loop completes. If WriteAsync throws/cancels after some segments were written, the stream’s _position stays at the original value and subsequent reads can replay already-transferred bytes.

Advance _position after each successfully completed WriteAsync call.

 {
await destination.WriteAsync(segment, cancellationToken).ConfigureAwait(false);
}
_position = _sequence.End;

src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.cs:44

  • This change makes a previously-seekable public Stream (ReadOnlySequenceStream is in System.Memory ref) report CanSeek == false and throw NotSupportedException from Length/Position/Seek. That’s a behavioral breaking change for existing consumers.

The PR description doesn’t reference a breaking-change tracking issue. Per docs/project/breaking-change-process.md, please link/create an issue marked breaking-change (with before/after behavior and mitigations) and reference it from the PR so reviewers can evaluate compatibility impact.

 // segment boundaries may be indirectly controlled by an untrusted network client through
// packet framing, so even correct stitching logic can produce adversarial fragmentation.
// Consumers must remain resilient against the worst technically compliant implementation
// rather than assuming ASP.NET-like segmentation.
public override bool CanSeek => false;

src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.cs:143

  • CopyTo writes multiple segments but only updates _position after the loop completes. If destination.Write(...) throws after some segments were successfully written, the stream will keep its old _position even though bytes were already consumed, so subsequent reads / retries can duplicate data.

Update _position after each successfully-written segment so the stream’s internal read position always reflects the bytes already transferred.

This issue also appears on line 169 of the same file.

 {
destination.Write(segment.Span);
}
_position = _sequence.End;

@adamsitnikadamsitnik left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Overall it LGTM, but I wonder if we should improve the XML doc comments before merging. Thank you for fixing it before the .NET 11 release @jozkee !

CopilotAI review requested due to automatic review settings August 10, 2026 16:37

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated no new comments.

Suppressed comments (1)

src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.cs:45

  • Changing ReadOnlySequenceStream to be non-seekable (CanSeek=false, and Length/Position/Seek throwing NotSupportedException) is a behavioral breaking change for a public type (see ref/System.Memory.cs). Per repo guidelines, this should go through the breaking-change process and include the required documentation/metadata updates (e.g., add the appropriate breaking-change entry per docs/project/breaking-change-process.md).
 /// <summary>Gets a value indicating whether the <see cref="ReadOnlySequenceStream"/> supports seeking.</summary>
// Keep this intentionally non-seekable: backward positioning requires traversing segments
// again from the beginning, making repeated seeks worst-case O(N). ReadOnlySequence<T>
// segment boundaries may be indirectly controlled by an untrusted network client through
// packet framing, so even correct stitching logic can produce adversarial fragmentation.
// Consumers must remain resilient against the worst technically compliant implementation
// rather than assuming ASP.NET-like segmentation.
public override bool CanSeek => false;

@adamsitnikadamsitnik left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I left a comment, PTAL @jozkee

@jozkee
jozkee requested a review from adamsitnikAugust 11, 2026 17:53

@ViveliDuChViveliDuCh left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks for the documentation effort!

@jozkee
jozkee merged commit 4b61662 into dotnet:mainAug 11, 2026
125 of 128 checks passed
@jozkee
jozkee deleted the agents/copy-artifacts-and-implement-seek-tests-0dd68e98 branch August 11, 2026 21:37
@jozkeejozkee changed the title System.IO: Make text and sequence streams non-seekableClarify why and make text and sequence streams non-seekableAug 12, 2026
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-rc1 milestone Aug 12, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@jozkee@adamsitnik@ViveliDuCh
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Clarify why and make text and sequence streams non-seekable - #132023

Merged
jozkee merged 4 commits into
dotnet:mainfrom
jozkee:agents/copy-artifacts-and-implement-seek-tests-0dd68e98
Aug 11, 2026
Merged

Clarify why and make text and sequence streams non-seekable#132023
jozkee merged 4 commits into
dotnet:mainfrom
jozkee:agents/copy-artifacts-and-implement-seek-tests-0dd68e98

Conversation

@jozkee

@jozkeejozkee commented Aug 7, 2026

Copy link
Copy Markdown
Member

Summary

  • clarify that ReadOnlyMemoryStream and WritableMemoryStream immediately expose their backing memory contents
  • make ReadOnlySequenceStream intentionally non-seekable and remove its seek state and traversal logic
  • keep StringStream intentionally non-seekable and document why backward positioning would require rerunning the encoder
  • make Length, Position, and Seek consistently throw the standard unseekable-stream NotSupportedException
  • update stream conformance and focused unit coverage
  • For Writable memory stream, added ctor remarks suggesting users to clear rented or reused memory before constructing the stream if its existing contents should not be exposed.

Rationale

Backward positioning requires replaying work from the beginning. For ReadOnlySequenceStream, that means traversing segments whose boundaries may be indirectly controlled by an untrusted network client through packet framing. Even correct stitching can therefore produce adversarial fragmentation, and consumers must tolerate the worst technically compliant segmentation rather than assuming ASP.NET-like behavior. For StringStream, backward positioning requires rerunning the encoder. Repeated seeks can turn both cases into worst-case O(N) work.

Validation

  • checked and Release CoreLib builds
  • System.Memory build
  • 405 focused ReadOnlySequenceStream conformance tests
  • 275 focused StringStream conformance/unit tests

Note

This pull request description was generated with GitHub Copilot.

jozkeeand others added 2 commits August 7, 2026 12:28
Clarify that read-only and writable memory streams expose the existing contents of supplied memory, including guidance for rented or reused buffers.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Prevent backward positioning from repeatedly replaying segmented sequences or encoded text. Keep Length, Position, and Seek consistent with the standard non-seekable Stream contract, and update conformance coverage.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR aligns several Stream implementations with an intentionally non-seekable contract (notably ReadOnlySequenceStream, and reinforcing StringStream expectations) and updates docs/tests accordingly, including clarifying that the memory-backed streams expose existing buffer contents immediately.

Changes:

  • Make ReadOnlySequenceStream intentionally non-seekable by removing seek state/traversal and having Length/Position/Seek throw NotSupportedException consistently.
  • Clarify ReadOnlyMemoryStream / WritableMemoryStream docs that backing memory contents are immediately readable.
  • Update conformance and focused unit tests to reflect the non-seekable behavior and exception expectations.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
src/libraries/System.Runtime/tests/System.IO.Tests/StringStream/StringStreamTests_String.csExtends capability tests to assert unseekable members throw NotSupportedException.
src/libraries/System.Private.CoreLib/src/System/IO/WritableMemoryStream.csDoc updates clarifying immediate exposure of existing buffer contents.
src/libraries/System.Private.CoreLib/src/System/IO/StringStream.csAdds rationale comment for keeping the stream non-seekable.
src/libraries/System.Private.CoreLib/src/System/IO/ReadOnlyMemoryStream.csDoc updates clarifying immediate exposure (and minor wording tweak needed).
src/libraries/System.Memory/tests/ReadOnlyBuffer/ReadOnlySequenceStream.ConformanceTests.csUpdates conformance configuration to treat the stream as non-seekable; removes seek-specific override.
src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.csImplements non-seekable contract; removes seek/position bookkeeping and logic.
src/libraries/System.Memory/src/Resources/Strings.resxAdds NotSupported_UnseekableStream resource; removes no-longer-needed seek-related resource strings.

Comment threadsrc/libraries/System.Private.CoreLib/src/System/IO/ReadOnlyMemoryStream.cs Outdated
Reuse the sliced sequence in CopyToAsync and clarify stream wrapper documentation.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings August 7, 2026 19:45

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated no new comments.

Suppressed comments (3)

src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.cs:173

  • CopyToAsyncCore only assigns _position = _sequence.End after the full loop completes. If WriteAsync throws/cancels after some segments were written, the stream’s _position stays at the original value and subsequent reads can replay already-transferred bytes.

Advance _position after each successfully completed WriteAsync call.

 {
await destination.WriteAsync(segment, cancellationToken).ConfigureAwait(false);
}
_position = _sequence.End;

src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.cs:44

  • This change makes a previously-seekable public Stream (ReadOnlySequenceStream is in System.Memory ref) report CanSeek == false and throw NotSupportedException from Length/Position/Seek. That’s a behavioral breaking change for existing consumers.

The PR description doesn’t reference a breaking-change tracking issue. Per docs/project/breaking-change-process.md, please link/create an issue marked breaking-change (with before/after behavior and mitigations) and reference it from the PR so reviewers can evaluate compatibility impact.

 // segment boundaries may be indirectly controlled by an untrusted network client through
// packet framing, so even correct stitching logic can produce adversarial fragmentation.
// Consumers must remain resilient against the worst technically compliant implementation
// rather than assuming ASP.NET-like segmentation.
public override bool CanSeek => false;

src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.cs:143

  • CopyTo writes multiple segments but only updates _position after the loop completes. If destination.Write(...) throws after some segments were successfully written, the stream will keep its old _position even though bytes were already consumed, so subsequent reads / retries can duplicate data.

Update _position after each successfully-written segment so the stream’s internal read position always reflects the bytes already transferred.

This issue also appears on line 169 of the same file.

 {
destination.Write(segment.Span);
}
_position = _sequence.End;

@adamsitnikadamsitnik left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Overall it LGTM, but I wonder if we should improve the XML doc comments before merging. Thank you for fixing it before the .NET 11 release @jozkee !

CopilotAI review requested due to automatic review settings August 10, 2026 16:37

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated no new comments.

Suppressed comments (1)

src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.cs:45

  • Changing ReadOnlySequenceStream to be non-seekable (CanSeek=false, and Length/Position/Seek throwing NotSupportedException) is a behavioral breaking change for a public type (see ref/System.Memory.cs). Per repo guidelines, this should go through the breaking-change process and include the required documentation/metadata updates (e.g., add the appropriate breaking-change entry per docs/project/breaking-change-process.md).
 /// <summary>Gets a value indicating whether the <see cref="ReadOnlySequenceStream"/> supports seeking.</summary>
// Keep this intentionally non-seekable: backward positioning requires traversing segments
// again from the beginning, making repeated seeks worst-case O(N). ReadOnlySequence<T>
// segment boundaries may be indirectly controlled by an untrusted network client through
// packet framing, so even correct stitching logic can produce adversarial fragmentation.
// Consumers must remain resilient against the worst technically compliant implementation
// rather than assuming ASP.NET-like segmentation.
public override bool CanSeek => false;

@adamsitnikadamsitnik left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I left a comment, PTAL @jozkee

@jozkee
jozkee requested a review from adamsitnikAugust 11, 2026 17:53

@ViveliDuChViveliDuCh left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks for the documentation effort!

@jozkee
jozkee merged commit 4b61662 into dotnet:mainAug 11, 2026
125 of 128 checks passed
@jozkee
jozkee deleted the agents/copy-artifacts-and-implement-seek-tests-0dd68e98 branch August 11, 2026 21:37
@jozkeejozkee changed the title System.IO: Make text and sequence streams non-seekableClarify why and make text and sequence streams non-seekableAug 12, 2026
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-rc1 milestone Aug 12, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@jozkee@adamsitnik@ViveliDuCh
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Clarify why and make text and sequence streams non-seekable - #132023

Merged
jozkee merged 4 commits into
dotnet:mainfrom
jozkee:agents/copy-artifacts-and-implement-seek-tests-0dd68e98
Aug 11, 2026
Merged

Clarify why and make text and sequence streams non-seekable#132023
jozkee merged 4 commits into
dotnet:mainfrom
jozkee:agents/copy-artifacts-and-implement-seek-tests-0dd68e98

Conversation

@jozkee

@jozkeejozkee commented Aug 7, 2026

Copy link
Copy Markdown
Member

Summary

  • clarify that ReadOnlyMemoryStream and WritableMemoryStream immediately expose their backing memory contents
  • make ReadOnlySequenceStream intentionally non-seekable and remove its seek state and traversal logic
  • keep StringStream intentionally non-seekable and document why backward positioning would require rerunning the encoder
  • make Length, Position, and Seek consistently throw the standard unseekable-stream NotSupportedException
  • update stream conformance and focused unit coverage
  • For Writable memory stream, added ctor remarks suggesting users to clear rented or reused memory before constructing the stream if its existing contents should not be exposed.

Rationale

Backward positioning requires replaying work from the beginning. For ReadOnlySequenceStream, that means traversing segments whose boundaries may be indirectly controlled by an untrusted network client through packet framing. Even correct stitching can therefore produce adversarial fragmentation, and consumers must tolerate the worst technically compliant segmentation rather than assuming ASP.NET-like behavior. For StringStream, backward positioning requires rerunning the encoder. Repeated seeks can turn both cases into worst-case O(N) work.

Validation

  • checked and Release CoreLib builds
  • System.Memory build
  • 405 focused ReadOnlySequenceStream conformance tests
  • 275 focused StringStream conformance/unit tests

Note

This pull request description was generated with GitHub Copilot.

jozkeeand others added 2 commits August 7, 2026 12:28
Clarify that read-only and writable memory streams expose the existing contents of supplied memory, including guidance for rented or reused buffers.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Prevent backward positioning from repeatedly replaying segmented sequences or encoded text. Keep Length, Position, and Seek consistent with the standard non-seekable Stream contract, and update conformance coverage.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR aligns several Stream implementations with an intentionally non-seekable contract (notably ReadOnlySequenceStream, and reinforcing StringStream expectations) and updates docs/tests accordingly, including clarifying that the memory-backed streams expose existing buffer contents immediately.

Changes:

  • Make ReadOnlySequenceStream intentionally non-seekable by removing seek state/traversal and having Length/Position/Seek throw NotSupportedException consistently.
  • Clarify ReadOnlyMemoryStream / WritableMemoryStream docs that backing memory contents are immediately readable.
  • Update conformance and focused unit tests to reflect the non-seekable behavior and exception expectations.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
src/libraries/System.Runtime/tests/System.IO.Tests/StringStream/StringStreamTests_String.csExtends capability tests to assert unseekable members throw NotSupportedException.
src/libraries/System.Private.CoreLib/src/System/IO/WritableMemoryStream.csDoc updates clarifying immediate exposure of existing buffer contents.
src/libraries/System.Private.CoreLib/src/System/IO/StringStream.csAdds rationale comment for keeping the stream non-seekable.
src/libraries/System.Private.CoreLib/src/System/IO/ReadOnlyMemoryStream.csDoc updates clarifying immediate exposure (and minor wording tweak needed).
src/libraries/System.Memory/tests/ReadOnlyBuffer/ReadOnlySequenceStream.ConformanceTests.csUpdates conformance configuration to treat the stream as non-seekable; removes seek-specific override.
src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.csImplements non-seekable contract; removes seek/position bookkeeping and logic.
src/libraries/System.Memory/src/Resources/Strings.resxAdds NotSupported_UnseekableStream resource; removes no-longer-needed seek-related resource strings.

Comment threadsrc/libraries/System.Private.CoreLib/src/System/IO/ReadOnlyMemoryStream.cs Outdated
Reuse the sliced sequence in CopyToAsync and clarify stream wrapper documentation.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings August 7, 2026 19:45

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated no new comments.

Suppressed comments (3)

src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.cs:173

  • CopyToAsyncCore only assigns _position = _sequence.End after the full loop completes. If WriteAsync throws/cancels after some segments were written, the stream’s _position stays at the original value and subsequent reads can replay already-transferred bytes.

Advance _position after each successfully completed WriteAsync call.

 {
await destination.WriteAsync(segment, cancellationToken).ConfigureAwait(false);
}
_position = _sequence.End;

src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.cs:44

  • This change makes a previously-seekable public Stream (ReadOnlySequenceStream is in System.Memory ref) report CanSeek == false and throw NotSupportedException from Length/Position/Seek. That’s a behavioral breaking change for existing consumers.

The PR description doesn’t reference a breaking-change tracking issue. Per docs/project/breaking-change-process.md, please link/create an issue marked breaking-change (with before/after behavior and mitigations) and reference it from the PR so reviewers can evaluate compatibility impact.

 // segment boundaries may be indirectly controlled by an untrusted network client through
// packet framing, so even correct stitching logic can produce adversarial fragmentation.
// Consumers must remain resilient against the worst technically compliant implementation
// rather than assuming ASP.NET-like segmentation.
public override bool CanSeek => false;

src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.cs:143

  • CopyTo writes multiple segments but only updates _position after the loop completes. If destination.Write(...) throws after some segments were successfully written, the stream will keep its old _position even though bytes were already consumed, so subsequent reads / retries can duplicate data.

Update _position after each successfully-written segment so the stream’s internal read position always reflects the bytes already transferred.

This issue also appears on line 169 of the same file.

 {
destination.Write(segment.Span);
}
_position = _sequence.End;

@adamsitnikadamsitnik left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Overall it LGTM, but I wonder if we should improve the XML doc comments before merging. Thank you for fixing it before the .NET 11 release @jozkee !

CopilotAI review requested due to automatic review settings August 10, 2026 16:37

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated no new comments.

Suppressed comments (1)

src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.cs:45

  • Changing ReadOnlySequenceStream to be non-seekable (CanSeek=false, and Length/Position/Seek throwing NotSupportedException) is a behavioral breaking change for a public type (see ref/System.Memory.cs). Per repo guidelines, this should go through the breaking-change process and include the required documentation/metadata updates (e.g., add the appropriate breaking-change entry per docs/project/breaking-change-process.md).
 /// <summary>Gets a value indicating whether the <see cref="ReadOnlySequenceStream"/> supports seeking.</summary>
// Keep this intentionally non-seekable: backward positioning requires traversing segments
// again from the beginning, making repeated seeks worst-case O(N). ReadOnlySequence<T>
// segment boundaries may be indirectly controlled by an untrusted network client through
// packet framing, so even correct stitching logic can produce adversarial fragmentation.
// Consumers must remain resilient against the worst technically compliant implementation
// rather than assuming ASP.NET-like segmentation.
public override bool CanSeek => false;

@adamsitnikadamsitnik left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I left a comment, PTAL @jozkee

@jozkee
jozkee requested a review from adamsitnikAugust 11, 2026 17:53

@ViveliDuChViveliDuCh left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks for the documentation effort!

@jozkee
jozkee merged commit 4b61662 into dotnet:mainAug 11, 2026
125 of 128 checks passed
@jozkee
jozkee deleted the agents/copy-artifacts-and-implement-seek-tests-0dd68e98 branch August 11, 2026 21:37
@jozkeejozkee changed the title System.IO: Make text and sequence streams non-seekableClarify why and make text and sequence streams non-seekableAug 12, 2026
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-rc1 milestone Aug 12, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@jozkee@adamsitnik@ViveliDuCh
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Clarify why and make text and sequence streams non-seekable - #132023

Merged
jozkee merged 4 commits into
dotnet:mainfrom
jozkee:agents/copy-artifacts-and-implement-seek-tests-0dd68e98
Aug 11, 2026
Merged

Clarify why and make text and sequence streams non-seekable#132023
jozkee merged 4 commits into
dotnet:mainfrom
jozkee:agents/copy-artifacts-and-implement-seek-tests-0dd68e98

Conversation

@jozkee

@jozkeejozkee commented Aug 7, 2026

Copy link
Copy Markdown
Member

Summary

  • clarify that ReadOnlyMemoryStream and WritableMemoryStream immediately expose their backing memory contents
  • make ReadOnlySequenceStream intentionally non-seekable and remove its seek state and traversal logic
  • keep StringStream intentionally non-seekable and document why backward positioning would require rerunning the encoder
  • make Length, Position, and Seek consistently throw the standard unseekable-stream NotSupportedException
  • update stream conformance and focused unit coverage
  • For Writable memory stream, added ctor remarks suggesting users to clear rented or reused memory before constructing the stream if its existing contents should not be exposed.

Rationale

Backward positioning requires replaying work from the beginning. For ReadOnlySequenceStream, that means traversing segments whose boundaries may be indirectly controlled by an untrusted network client through packet framing. Even correct stitching can therefore produce adversarial fragmentation, and consumers must tolerate the worst technically compliant segmentation rather than assuming ASP.NET-like behavior. For StringStream, backward positioning requires rerunning the encoder. Repeated seeks can turn both cases into worst-case O(N) work.

Validation

  • checked and Release CoreLib builds
  • System.Memory build
  • 405 focused ReadOnlySequenceStream conformance tests
  • 275 focused StringStream conformance/unit tests

Note

This pull request description was generated with GitHub Copilot.

jozkeeand others added 2 commits August 7, 2026 12:28
Clarify that read-only and writable memory streams expose the existing contents of supplied memory, including guidance for rented or reused buffers.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Prevent backward positioning from repeatedly replaying segmented sequences or encoded text. Keep Length, Position, and Seek consistent with the standard non-seekable Stream contract, and update conformance coverage.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR aligns several Stream implementations with an intentionally non-seekable contract (notably ReadOnlySequenceStream, and reinforcing StringStream expectations) and updates docs/tests accordingly, including clarifying that the memory-backed streams expose existing buffer contents immediately.

Changes:

  • Make ReadOnlySequenceStream intentionally non-seekable by removing seek state/traversal and having Length/Position/Seek throw NotSupportedException consistently.
  • Clarify ReadOnlyMemoryStream / WritableMemoryStream docs that backing memory contents are immediately readable.
  • Update conformance and focused unit tests to reflect the non-seekable behavior and exception expectations.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
src/libraries/System.Runtime/tests/System.IO.Tests/StringStream/StringStreamTests_String.csExtends capability tests to assert unseekable members throw NotSupportedException.
src/libraries/System.Private.CoreLib/src/System/IO/WritableMemoryStream.csDoc updates clarifying immediate exposure of existing buffer contents.
src/libraries/System.Private.CoreLib/src/System/IO/StringStream.csAdds rationale comment for keeping the stream non-seekable.
src/libraries/System.Private.CoreLib/src/System/IO/ReadOnlyMemoryStream.csDoc updates clarifying immediate exposure (and minor wording tweak needed).
src/libraries/System.Memory/tests/ReadOnlyBuffer/ReadOnlySequenceStream.ConformanceTests.csUpdates conformance configuration to treat the stream as non-seekable; removes seek-specific override.
src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.csImplements non-seekable contract; removes seek/position bookkeeping and logic.
src/libraries/System.Memory/src/Resources/Strings.resxAdds NotSupported_UnseekableStream resource; removes no-longer-needed seek-related resource strings.

Comment threadsrc/libraries/System.Private.CoreLib/src/System/IO/ReadOnlyMemoryStream.cs Outdated
Reuse the sliced sequence in CopyToAsync and clarify stream wrapper documentation.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings August 7, 2026 19:45

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated no new comments.

Suppressed comments (3)

src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.cs:173

  • CopyToAsyncCore only assigns _position = _sequence.End after the full loop completes. If WriteAsync throws/cancels after some segments were written, the stream’s _position stays at the original value and subsequent reads can replay already-transferred bytes.

Advance _position after each successfully completed WriteAsync call.

 {
await destination.WriteAsync(segment, cancellationToken).ConfigureAwait(false);
}
_position = _sequence.End;

src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.cs:44

  • This change makes a previously-seekable public Stream (ReadOnlySequenceStream is in System.Memory ref) report CanSeek == false and throw NotSupportedException from Length/Position/Seek. That’s a behavioral breaking change for existing consumers.

The PR description doesn’t reference a breaking-change tracking issue. Per docs/project/breaking-change-process.md, please link/create an issue marked breaking-change (with before/after behavior and mitigations) and reference it from the PR so reviewers can evaluate compatibility impact.

 // segment boundaries may be indirectly controlled by an untrusted network client through
// packet framing, so even correct stitching logic can produce adversarial fragmentation.
// Consumers must remain resilient against the worst technically compliant implementation
// rather than assuming ASP.NET-like segmentation.
public override bool CanSeek => false;

src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.cs:143

  • CopyTo writes multiple segments but only updates _position after the loop completes. If destination.Write(...) throws after some segments were successfully written, the stream will keep its old _position even though bytes were already consumed, so subsequent reads / retries can duplicate data.

Update _position after each successfully-written segment so the stream’s internal read position always reflects the bytes already transferred.

This issue also appears on line 169 of the same file.

 {
destination.Write(segment.Span);
}
_position = _sequence.End;

@adamsitnikadamsitnik left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Overall it LGTM, but I wonder if we should improve the XML doc comments before merging. Thank you for fixing it before the .NET 11 release @jozkee !

CopilotAI review requested due to automatic review settings August 10, 2026 16:37

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated no new comments.

Suppressed comments (1)

src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.cs:45

  • Changing ReadOnlySequenceStream to be non-seekable (CanSeek=false, and Length/Position/Seek throwing NotSupportedException) is a behavioral breaking change for a public type (see ref/System.Memory.cs). Per repo guidelines, this should go through the breaking-change process and include the required documentation/metadata updates (e.g., add the appropriate breaking-change entry per docs/project/breaking-change-process.md).
 /// <summary>Gets a value indicating whether the <see cref="ReadOnlySequenceStream"/> supports seeking.</summary>
// Keep this intentionally non-seekable: backward positioning requires traversing segments
// again from the beginning, making repeated seeks worst-case O(N). ReadOnlySequence<T>
// segment boundaries may be indirectly controlled by an untrusted network client through
// packet framing, so even correct stitching logic can produce adversarial fragmentation.
// Consumers must remain resilient against the worst technically compliant implementation
// rather than assuming ASP.NET-like segmentation.
public override bool CanSeek => false;

@adamsitnikadamsitnik left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I left a comment, PTAL @jozkee

@jozkee
jozkee requested a review from adamsitnikAugust 11, 2026 17:53

@ViveliDuChViveliDuCh left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks for the documentation effort!

@jozkee
jozkee merged commit 4b61662 into dotnet:mainAug 11, 2026
125 of 128 checks passed
@jozkee
jozkee deleted the agents/copy-artifacts-and-implement-seek-tests-0dd68e98 branch August 11, 2026 21:37
@jozkeejozkee changed the title System.IO: Make text and sequence streams non-seekableClarify why and make text and sequence streams non-seekableAug 12, 2026
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-rc1 milestone Aug 12, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@jozkee@adamsitnik@ViveliDuCh
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Clarify why and make text and sequence streams non-seekable - #132023

Merged
jozkee merged 4 commits into
dotnet:mainfrom
jozkee:agents/copy-artifacts-and-implement-seek-tests-0dd68e98
Aug 11, 2026
Merged

Clarify why and make text and sequence streams non-seekable#132023
jozkee merged 4 commits into
dotnet:mainfrom
jozkee:agents/copy-artifacts-and-implement-seek-tests-0dd68e98

Conversation

@jozkee

@jozkeejozkee commented Aug 7, 2026

Copy link
Copy Markdown
Member

Summary

  • clarify that ReadOnlyMemoryStream and WritableMemoryStream immediately expose their backing memory contents
  • make ReadOnlySequenceStream intentionally non-seekable and remove its seek state and traversal logic
  • keep StringStream intentionally non-seekable and document why backward positioning would require rerunning the encoder
  • make Length, Position, and Seek consistently throw the standard unseekable-stream NotSupportedException
  • update stream conformance and focused unit coverage
  • For Writable memory stream, added ctor remarks suggesting users to clear rented or reused memory before constructing the stream if its existing contents should not be exposed.

Rationale

Backward positioning requires replaying work from the beginning. For ReadOnlySequenceStream, that means traversing segments whose boundaries may be indirectly controlled by an untrusted network client through packet framing. Even correct stitching can therefore produce adversarial fragmentation, and consumers must tolerate the worst technically compliant segmentation rather than assuming ASP.NET-like behavior. For StringStream, backward positioning requires rerunning the encoder. Repeated seeks can turn both cases into worst-case O(N) work.

Validation

  • checked and Release CoreLib builds
  • System.Memory build
  • 405 focused ReadOnlySequenceStream conformance tests
  • 275 focused StringStream conformance/unit tests

Note

This pull request description was generated with GitHub Copilot.

jozkeeand others added 2 commits August 7, 2026 12:28
Clarify that read-only and writable memory streams expose the existing contents of supplied memory, including guidance for rented or reused buffers.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Prevent backward positioning from repeatedly replaying segmented sequences or encoded text. Keep Length, Position, and Seek consistent with the standard non-seekable Stream contract, and update conformance coverage.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR aligns several Stream implementations with an intentionally non-seekable contract (notably ReadOnlySequenceStream, and reinforcing StringStream expectations) and updates docs/tests accordingly, including clarifying that the memory-backed streams expose existing buffer contents immediately.

Changes:

  • Make ReadOnlySequenceStream intentionally non-seekable by removing seek state/traversal and having Length/Position/Seek throw NotSupportedException consistently.
  • Clarify ReadOnlyMemoryStream / WritableMemoryStream docs that backing memory contents are immediately readable.
  • Update conformance and focused unit tests to reflect the non-seekable behavior and exception expectations.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
src/libraries/System.Runtime/tests/System.IO.Tests/StringStream/StringStreamTests_String.csExtends capability tests to assert unseekable members throw NotSupportedException.
src/libraries/System.Private.CoreLib/src/System/IO/WritableMemoryStream.csDoc updates clarifying immediate exposure of existing buffer contents.
src/libraries/System.Private.CoreLib/src/System/IO/StringStream.csAdds rationale comment for keeping the stream non-seekable.
src/libraries/System.Private.CoreLib/src/System/IO/ReadOnlyMemoryStream.csDoc updates clarifying immediate exposure (and minor wording tweak needed).
src/libraries/System.Memory/tests/ReadOnlyBuffer/ReadOnlySequenceStream.ConformanceTests.csUpdates conformance configuration to treat the stream as non-seekable; removes seek-specific override.
src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.csImplements non-seekable contract; removes seek/position bookkeeping and logic.
src/libraries/System.Memory/src/Resources/Strings.resxAdds NotSupported_UnseekableStream resource; removes no-longer-needed seek-related resource strings.

Comment threadsrc/libraries/System.Private.CoreLib/src/System/IO/ReadOnlyMemoryStream.cs Outdated
Reuse the sliced sequence in CopyToAsync and clarify stream wrapper documentation.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings August 7, 2026 19:45

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated no new comments.

Suppressed comments (3)

src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.cs:173

  • CopyToAsyncCore only assigns _position = _sequence.End after the full loop completes. If WriteAsync throws/cancels after some segments were written, the stream’s _position stays at the original value and subsequent reads can replay already-transferred bytes.

Advance _position after each successfully completed WriteAsync call.

 {
await destination.WriteAsync(segment, cancellationToken).ConfigureAwait(false);
}
_position = _sequence.End;

src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.cs:44

  • This change makes a previously-seekable public Stream (ReadOnlySequenceStream is in System.Memory ref) report CanSeek == false and throw NotSupportedException from Length/Position/Seek. That’s a behavioral breaking change for existing consumers.

The PR description doesn’t reference a breaking-change tracking issue. Per docs/project/breaking-change-process.md, please link/create an issue marked breaking-change (with before/after behavior and mitigations) and reference it from the PR so reviewers can evaluate compatibility impact.

 // segment boundaries may be indirectly controlled by an untrusted network client through
// packet framing, so even correct stitching logic can produce adversarial fragmentation.
// Consumers must remain resilient against the worst technically compliant implementation
// rather than assuming ASP.NET-like segmentation.
public override bool CanSeek => false;

src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.cs:143

  • CopyTo writes multiple segments but only updates _position after the loop completes. If destination.Write(...) throws after some segments were successfully written, the stream will keep its old _position even though bytes were already consumed, so subsequent reads / retries can duplicate data.

Update _position after each successfully-written segment so the stream’s internal read position always reflects the bytes already transferred.

This issue also appears on line 169 of the same file.

 {
destination.Write(segment.Span);
}
_position = _sequence.End;

@adamsitnikadamsitnik left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Overall it LGTM, but I wonder if we should improve the XML doc comments before merging. Thank you for fixing it before the .NET 11 release @jozkee !

CopilotAI review requested due to automatic review settings August 10, 2026 16:37

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated no new comments.

Suppressed comments (1)

src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.cs:45

  • Changing ReadOnlySequenceStream to be non-seekable (CanSeek=false, and Length/Position/Seek throwing NotSupportedException) is a behavioral breaking change for a public type (see ref/System.Memory.cs). Per repo guidelines, this should go through the breaking-change process and include the required documentation/metadata updates (e.g., add the appropriate breaking-change entry per docs/project/breaking-change-process.md).
 /// <summary>Gets a value indicating whether the <see cref="ReadOnlySequenceStream"/> supports seeking.</summary>
// Keep this intentionally non-seekable: backward positioning requires traversing segments
// again from the beginning, making repeated seeks worst-case O(N). ReadOnlySequence<T>
// segment boundaries may be indirectly controlled by an untrusted network client through
// packet framing, so even correct stitching logic can produce adversarial fragmentation.
// Consumers must remain resilient against the worst technically compliant implementation
// rather than assuming ASP.NET-like segmentation.
public override bool CanSeek => false;

@adamsitnikadamsitnik left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I left a comment, PTAL @jozkee

@jozkee
jozkee requested a review from adamsitnikAugust 11, 2026 17:53

@ViveliDuChViveliDuCh left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks for the documentation effort!

@jozkee
jozkee merged commit 4b61662 into dotnet:mainAug 11, 2026
125 of 128 checks passed
@jozkee
jozkee deleted the agents/copy-artifacts-and-implement-seek-tests-0dd68e98 branch August 11, 2026 21:37
@jozkeejozkee changed the title System.IO: Make text and sequence streams non-seekableClarify why and make text and sequence streams non-seekableAug 12, 2026
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-rc1 milestone Aug 12, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@jozkee@adamsitnik@ViveliDuCh
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Clarify why and make text and sequence streams non-seekable - #132023

Merged
jozkee merged 4 commits into
dotnet:mainfrom
jozkee:agents/copy-artifacts-and-implement-seek-tests-0dd68e98
Aug 11, 2026
Merged

Clarify why and make text and sequence streams non-seekable#132023
jozkee merged 4 commits into
dotnet:mainfrom
jozkee:agents/copy-artifacts-and-implement-seek-tests-0dd68e98

Conversation

@jozkee

@jozkeejozkee commented Aug 7, 2026

Copy link
Copy Markdown
Member

Summary

  • clarify that ReadOnlyMemoryStream and WritableMemoryStream immediately expose their backing memory contents
  • make ReadOnlySequenceStream intentionally non-seekable and remove its seek state and traversal logic
  • keep StringStream intentionally non-seekable and document why backward positioning would require rerunning the encoder
  • make Length, Position, and Seek consistently throw the standard unseekable-stream NotSupportedException
  • update stream conformance and focused unit coverage
  • For Writable memory stream, added ctor remarks suggesting users to clear rented or reused memory before constructing the stream if its existing contents should not be exposed.

Rationale

Backward positioning requires replaying work from the beginning. For ReadOnlySequenceStream, that means traversing segments whose boundaries may be indirectly controlled by an untrusted network client through packet framing. Even correct stitching can therefore produce adversarial fragmentation, and consumers must tolerate the worst technically compliant segmentation rather than assuming ASP.NET-like behavior. For StringStream, backward positioning requires rerunning the encoder. Repeated seeks can turn both cases into worst-case O(N) work.

Validation

  • checked and Release CoreLib builds
  • System.Memory build
  • 405 focused ReadOnlySequenceStream conformance tests
  • 275 focused StringStream conformance/unit tests

Note

This pull request description was generated with GitHub Copilot.

jozkeeand others added 2 commits August 7, 2026 12:28
Clarify that read-only and writable memory streams expose the existing contents of supplied memory, including guidance for rented or reused buffers.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Prevent backward positioning from repeatedly replaying segmented sequences or encoded text. Keep Length, Position, and Seek consistent with the standard non-seekable Stream contract, and update conformance coverage.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR aligns several Stream implementations with an intentionally non-seekable contract (notably ReadOnlySequenceStream, and reinforcing StringStream expectations) and updates docs/tests accordingly, including clarifying that the memory-backed streams expose existing buffer contents immediately.

Changes:

  • Make ReadOnlySequenceStream intentionally non-seekable by removing seek state/traversal and having Length/Position/Seek throw NotSupportedException consistently.
  • Clarify ReadOnlyMemoryStream / WritableMemoryStream docs that backing memory contents are immediately readable.
  • Update conformance and focused unit tests to reflect the non-seekable behavior and exception expectations.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated 2 comments.

Show a summary per file
FileDescription
src/libraries/System.Runtime/tests/System.IO.Tests/StringStream/StringStreamTests_String.csExtends capability tests to assert unseekable members throw NotSupportedException.
src/libraries/System.Private.CoreLib/src/System/IO/WritableMemoryStream.csDoc updates clarifying immediate exposure of existing buffer contents.
src/libraries/System.Private.CoreLib/src/System/IO/StringStream.csAdds rationale comment for keeping the stream non-seekable.
src/libraries/System.Private.CoreLib/src/System/IO/ReadOnlyMemoryStream.csDoc updates clarifying immediate exposure (and minor wording tweak needed).
src/libraries/System.Memory/tests/ReadOnlyBuffer/ReadOnlySequenceStream.ConformanceTests.csUpdates conformance configuration to treat the stream as non-seekable; removes seek-specific override.
src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.csImplements non-seekable contract; removes seek/position bookkeeping and logic.
src/libraries/System.Memory/src/Resources/Strings.resxAdds NotSupported_UnseekableStream resource; removes no-longer-needed seek-related resource strings.

Comment threadsrc/libraries/System.Private.CoreLib/src/System/IO/ReadOnlyMemoryStream.cs Outdated
Reuse the sliced sequence in CopyToAsync and clarify stream wrapper documentation.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings August 7, 2026 19:45

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated no new comments.

Suppressed comments (3)

src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.cs:173

  • CopyToAsyncCore only assigns _position = _sequence.End after the full loop completes. If WriteAsync throws/cancels after some segments were written, the stream’s _position stays at the original value and subsequent reads can replay already-transferred bytes.

Advance _position after each successfully completed WriteAsync call.

 {
await destination.WriteAsync(segment, cancellationToken).ConfigureAwait(false);
}
_position = _sequence.End;

src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.cs:44

  • This change makes a previously-seekable public Stream (ReadOnlySequenceStream is in System.Memory ref) report CanSeek == false and throw NotSupportedException from Length/Position/Seek. That’s a behavioral breaking change for existing consumers.

The PR description doesn’t reference a breaking-change tracking issue. Per docs/project/breaking-change-process.md, please link/create an issue marked breaking-change (with before/after behavior and mitigations) and reference it from the PR so reviewers can evaluate compatibility impact.

 // segment boundaries may be indirectly controlled by an untrusted network client through
// packet framing, so even correct stitching logic can produce adversarial fragmentation.
// Consumers must remain resilient against the worst technically compliant implementation
// rather than assuming ASP.NET-like segmentation.
public override bool CanSeek => false;

src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.cs:143

  • CopyTo writes multiple segments but only updates _position after the loop completes. If destination.Write(...) throws after some segments were successfully written, the stream will keep its old _position even though bytes were already consumed, so subsequent reads / retries can duplicate data.

Update _position after each successfully-written segment so the stream’s internal read position always reflects the bytes already transferred.

This issue also appears on line 169 of the same file.

 {
destination.Write(segment.Span);
}
_position = _sequence.End;

@adamsitnikadamsitnik left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Overall it LGTM, but I wonder if we should improve the XML doc comments before merging. Thank you for fixing it before the .NET 11 release @jozkee !

CopilotAI review requested due to automatic review settings August 10, 2026 16:37

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated no new comments.

Suppressed comments (1)

src/libraries/System.Memory/src/System/Buffers/ReadOnlySequenceStream.cs:45

  • Changing ReadOnlySequenceStream to be non-seekable (CanSeek=false, and Length/Position/Seek throwing NotSupportedException) is a behavioral breaking change for a public type (see ref/System.Memory.cs). Per repo guidelines, this should go through the breaking-change process and include the required documentation/metadata updates (e.g., add the appropriate breaking-change entry per docs/project/breaking-change-process.md).
 /// <summary>Gets a value indicating whether the <see cref="ReadOnlySequenceStream"/> supports seeking.</summary>
// Keep this intentionally non-seekable: backward positioning requires traversing segments
// again from the beginning, making repeated seeks worst-case O(N). ReadOnlySequence<T>
// segment boundaries may be indirectly controlled by an untrusted network client through
// packet framing, so even correct stitching logic can produce adversarial fragmentation.
// Consumers must remain resilient against the worst technically compliant implementation
// rather than assuming ASP.NET-like segmentation.
public override bool CanSeek => false;

@adamsitnikadamsitnik left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I left a comment, PTAL @jozkee

@jozkee
jozkee requested a review from adamsitnikAugust 11, 2026 17:53

@ViveliDuChViveliDuCh left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks for the documentation effort!

@jozkee
jozkee merged commit 4b61662 into dotnet:mainAug 11, 2026
125 of 128 checks passed
@jozkee
jozkee deleted the agents/copy-artifacts-and-implement-seek-tests-0dd68e98 branch August 11, 2026 21:37
@jozkeejozkee changed the title System.IO: Make text and sequence streams non-seekableClarify why and make text and sequence streams non-seekableAug 12, 2026
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-rc1 milestone Aug 12, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@jozkee@adamsitnik@ViveliDuCh