More reliably clean up more SafeHandle instances - #71991

Merged
stephentoub merged 5 commits into
dotnet:mainfrom
stephentoub:moresafehandlefinalization
Jul 13, 2022
Merged

More reliably clean up more SafeHandle instances#71991
stephentoub merged 5 commits into
dotnet:mainfrom
stephentoub:moresafehandlefinalization

Conversation

@stephentoub

Copy link
Copy Markdown
Member

This calls Dispose on SafeHandles (or things wrapping SafeHandles) that were otherwise being left for finalization:

  1. Some of these are fixing finalization happening even on success paths (typically where the implementation isn't disposing of something that directly or indirectly wraps a SafeHandle).
  2. Some of these are fixing finalization happening for invalid SafeHandles. Their IsInvalid is true, but they still get finalized.
  3. Some of these are fixing tests to finalize less. My goal with fixing the tests was to eliminate the noise in order to find instances of the other two cases.

These were found primarily via two means:

  • Debug-instrumentation in SafeHandle to log when one is finalized. This instrumentation is built into debug/checked builds of SafeHandle and requires setting the DEBUG_SAFEHANDLE_FINALIZATION environment variable to "1".
  • Auditing use of SafeHandle.IsInvalid

There's a lot more that can be cleaned up using the SafeHandle instrumentation, but I'm pausing here for now. The System.IO.Pipes, System.IO.FileSystem, and System.Security.Cryptography tests are clean on Windows (with the exception of a few tests that are purposefully leaving objects for finalization to test finalization code paths).

@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @dotnet/area-system-security, @vcsjones
See info in area-owners.md if you want to be subscribed.

Issue Details

This calls Dispose on SafeHandles (or things wrapping SafeHandles) that were otherwise being left for finalization:

  1. Some of these are fixing finalization happening even on success paths (typically where the implementation isn't disposing of something that directly or indirectly wraps a SafeHandle).
  2. Some of these are fixing finalization happening for invalid SafeHandles. Their IsInvalid is true, but they still get finalized.
  3. Some of these are fixing tests to finalize less. My goal with fixing the tests was to eliminate the noise in order to find instances of the other two cases.

These were found primarily via two means:

  • Debug-instrumentation in SafeHandle to log when one is finalized. This instrumentation is built into debug/checked builds of SafeHandle and requires setting the DEBUG_SAFEHANDLE_FINALIZATION environment variable to "1".
  • Auditing use of SafeHandle.IsInvalid

There's a lot more that can be cleaned up using the SafeHandle instrumentation, but I'm pausing here for now. The System.IO.Pipes, System.IO.FileSystem, and System.Security.Cryptography tests are clean on Windows (with the exception of a few tests that are purposefully leaving objects for finalization to test finalization code paths).

Author:stephentoub
Assignees:-
Labels:

area-System.Security

Milestone:-

@stephentoub
stephentoubforce-pushed the moresafehandlefinalization branch from 4e05508 to fd8d46dCompareJuly 12, 2022 13:38
Comment threadsrc/libraries/System.IO.FileSystem/tests/File/OpenHandle.cs Outdated
@jkotas

Copy link
Copy Markdown
Member

The runtime and SafeHandle.cs changes LGTM. I have done cursory review of the rest.

Comment threadsrc/libraries/Common/src/System/Net/ContextAwareResult.Windows.cs Outdated

@bartonjsbartonjs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, other than braceless usings in product code (which I believed we had banned in style outside of tests, but I guess not?)

@stephentoub

Copy link
Copy Markdown
MemberAuthor

other than braceless usings in product code (which I believed we had banned in style outside of tests

I don't know why we'd ban them.

@danmoseley

Copy link
Copy Markdown
Contributor

Yay, glad you added this switch. Do you plan to make an "up for grabs" issue to continue, in case folks are interested? eg., with a checkbox for each library that has hits (if you have that data gathered)?

Can you imagine us getting clean - I'm guessing there are test cases for finalizers, though.

How much slower is it to run tests when the switch is flipped? I assume it's expensive to gather stacks.

@stephentoub

Copy link
Copy Markdown
MemberAuthor

How much slower is it to run tests when the switch is flipped? I assume it's expensive to gather stacks.

A lot... starting with the fact that it's only built into a debug/checked runtime, and then layering on a stack walk for every safe handle created.

Can you imagine us getting clean - I'm guessing there are test cases for finalizers, though.

Without workarounds that'd be challenging, e.g. because of tests for finalizers as you say, tests that purposefully allow resources to not be disposed to avoid race conditions, etc.

if you have that data gathered

I don't.

This calls Dispose on SafeHandles (or things wrapping SafeHandles) that were otherwise being left for finalization:
1. Some of these are fixing finalization happening even on success paths (typically where the implementation isn't disposing of something that directly or indirectly wraps a SafeHandle).
2. Some of these are fixing finalization happening for invalid SafeHandles.
3. Some of these are fixing tests to finalize less. My goal with fixing the tests was to eliminate the noise in order to find instances of the other two cases.
These were found primarily via two means:
- Debug-instrumentation in SafeHandle to log when one is finalized. This instrumentation is built into debug/checked builds of SafeHandle and requires setting the DEBUG_SAFEHANDLE_FINALIZATION environment variable to "1".
- Auditing use of SafeHandle.IsInvalid
There's a lot more that can be cleaned up using the SafeHandle instrumentation, but I'm pausing here for now. The System.IO.Pipes, System.IO.FileSystem, and System.Security.Cryptography tests are clean on Windows.
@stephentoub
stephentoubforce-pushed the moresafehandlefinalization branch from fd8d46d to 767ee06CompareJuly 12, 2022 20:55
@danmoseley

Copy link
Copy Markdown
Contributor

Makes sense -- probably we can use this flag on rare occasions, eg., having written a new feature with non trivial use of safehandles.

@bartonjs

Copy link
Copy Markdown
Member

If you have to spin again, Steve, I'm indifferent about keeping or removing the version in

#if DEBUG
privatestaticreadonlybools_captureTrace=
Environment.GetEnvironmentVariable("DEBUG_SAFEX509HANDLE_FINALIZATION")!=null;
privatereadonlyStackTrace?_stacktrace=
s_captureTrace?newStackTrace(fNeedFileInfo:true):null;
~SafeX509Handle()
{
if(s_captureTrace)
{
Console.WriteLine($"0x{handle.ToInt64():x}{_stacktrace?.ToString()??"no stacktrace..."}");
}
}
#endif
that I left in from getting Linux PKCS7 tidy.

@stephentoub

Copy link
Copy Markdown
MemberAuthor

I'm indifferent about keeping or removing the version

Me, too. I will need to resolve a conflict, so I can remove it if you like.

@bartonjs

Copy link
Copy Markdown
Member

Eh, if you're indifferent and I'm indifferent, let's leave it, so I can have a "smaller than the whole world" experience :)

@stephentoub
stephentoub merged commit 199580b into dotnet:mainJul 13, 2022
@stephentoub
stephentoub deleted the moresafehandlefinalization branch July 13, 2022 11:09
@ghostghost locked as resolved and limited conversation to collaborators Aug 12, 2022
@AndyAyersMS

Copy link
Copy Markdown
Member

Possible regression: dotnet/perf-autofiling-issues#6973

@bartonjs

Copy link
Copy Markdown
Member

Since CryptoConfig.CreateFromName is just a lookup in ConcurrentDictionary, reflection to find a suitable ctor, and then reflection invocation of said ctor, I don't think this change was involved.

@stephentoub

stephentoub commented Aug 18, 2022

Copy link
Copy Markdown
MemberAuthor

@bartonjs, I did touch this:
https://github.com/dotnet/runtime/pull/71991/files#diff-b5e1d8d2d47fbe472dd7de0d3d5450bc58de31363bee3ae108cf295bf879b4e4R44
I guess that could have caused this (an extra non-inlineable function call, an extra generic dictionary lookup, etc.)?

That said, I'm not sure how much a few hundred nanoseconds on this particular method matters. We don't want folks using this method anyway, right?

@bartonjs

Copy link
Copy Markdown
Member

@stephentoub

Copy link
Copy Markdown
MemberAuthor

In that case, yeah, I'm not on the hook :)

Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@stephentoub@jkotas@danmoseley@bartonjs@AndyAyersMS@AaronRobinsonMSFT
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

More reliably clean up more SafeHandle instances - #71991

Merged
stephentoub merged 5 commits into
dotnet:mainfrom
stephentoub:moresafehandlefinalization
Jul 13, 2022
Merged

More reliably clean up more SafeHandle instances#71991
stephentoub merged 5 commits into
dotnet:mainfrom
stephentoub:moresafehandlefinalization

Conversation

@stephentoub

Copy link
Copy Markdown
Member

This calls Dispose on SafeHandles (or things wrapping SafeHandles) that were otherwise being left for finalization:

  1. Some of these are fixing finalization happening even on success paths (typically where the implementation isn't disposing of something that directly or indirectly wraps a SafeHandle).
  2. Some of these are fixing finalization happening for invalid SafeHandles. Their IsInvalid is true, but they still get finalized.
  3. Some of these are fixing tests to finalize less. My goal with fixing the tests was to eliminate the noise in order to find instances of the other two cases.

These were found primarily via two means:

  • Debug-instrumentation in SafeHandle to log when one is finalized. This instrumentation is built into debug/checked builds of SafeHandle and requires setting the DEBUG_SAFEHANDLE_FINALIZATION environment variable to "1".
  • Auditing use of SafeHandle.IsInvalid

There's a lot more that can be cleaned up using the SafeHandle instrumentation, but I'm pausing here for now. The System.IO.Pipes, System.IO.FileSystem, and System.Security.Cryptography tests are clean on Windows (with the exception of a few tests that are purposefully leaving objects for finalization to test finalization code paths).

@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @dotnet/area-system-security, @vcsjones
See info in area-owners.md if you want to be subscribed.

Issue Details

This calls Dispose on SafeHandles (or things wrapping SafeHandles) that were otherwise being left for finalization:

  1. Some of these are fixing finalization happening even on success paths (typically where the implementation isn't disposing of something that directly or indirectly wraps a SafeHandle).
  2. Some of these are fixing finalization happening for invalid SafeHandles. Their IsInvalid is true, but they still get finalized.
  3. Some of these are fixing tests to finalize less. My goal with fixing the tests was to eliminate the noise in order to find instances of the other two cases.

These were found primarily via two means:

  • Debug-instrumentation in SafeHandle to log when one is finalized. This instrumentation is built into debug/checked builds of SafeHandle and requires setting the DEBUG_SAFEHANDLE_FINALIZATION environment variable to "1".
  • Auditing use of SafeHandle.IsInvalid

There's a lot more that can be cleaned up using the SafeHandle instrumentation, but I'm pausing here for now. The System.IO.Pipes, System.IO.FileSystem, and System.Security.Cryptography tests are clean on Windows (with the exception of a few tests that are purposefully leaving objects for finalization to test finalization code paths).

Author:stephentoub
Assignees:-
Labels:

area-System.Security

Milestone:-

@stephentoub
stephentoubforce-pushed the moresafehandlefinalization branch from 4e05508 to fd8d46dCompareJuly 12, 2022 13:38
Comment threadsrc/libraries/System.IO.FileSystem/tests/File/OpenHandle.cs Outdated
@jkotas

Copy link
Copy Markdown
Member

The runtime and SafeHandle.cs changes LGTM. I have done cursory review of the rest.

Comment threadsrc/libraries/Common/src/System/Net/ContextAwareResult.Windows.cs Outdated

@bartonjsbartonjs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, other than braceless usings in product code (which I believed we had banned in style outside of tests, but I guess not?)

@stephentoub

Copy link
Copy Markdown
MemberAuthor

other than braceless usings in product code (which I believed we had banned in style outside of tests

I don't know why we'd ban them.

@danmoseley

Copy link
Copy Markdown
Contributor

Yay, glad you added this switch. Do you plan to make an "up for grabs" issue to continue, in case folks are interested? eg., with a checkbox for each library that has hits (if you have that data gathered)?

Can you imagine us getting clean - I'm guessing there are test cases for finalizers, though.

How much slower is it to run tests when the switch is flipped? I assume it's expensive to gather stacks.

@stephentoub

Copy link
Copy Markdown
MemberAuthor

How much slower is it to run tests when the switch is flipped? I assume it's expensive to gather stacks.

A lot... starting with the fact that it's only built into a debug/checked runtime, and then layering on a stack walk for every safe handle created.

Can you imagine us getting clean - I'm guessing there are test cases for finalizers, though.

Without workarounds that'd be challenging, e.g. because of tests for finalizers as you say, tests that purposefully allow resources to not be disposed to avoid race conditions, etc.

if you have that data gathered

I don't.

This calls Dispose on SafeHandles (or things wrapping SafeHandles) that were otherwise being left for finalization:
1. Some of these are fixing finalization happening even on success paths (typically where the implementation isn't disposing of something that directly or indirectly wraps a SafeHandle).
2. Some of these are fixing finalization happening for invalid SafeHandles.
3. Some of these are fixing tests to finalize less. My goal with fixing the tests was to eliminate the noise in order to find instances of the other two cases.
These were found primarily via two means:
- Debug-instrumentation in SafeHandle to log when one is finalized. This instrumentation is built into debug/checked builds of SafeHandle and requires setting the DEBUG_SAFEHANDLE_FINALIZATION environment variable to "1".
- Auditing use of SafeHandle.IsInvalid
There's a lot more that can be cleaned up using the SafeHandle instrumentation, but I'm pausing here for now. The System.IO.Pipes, System.IO.FileSystem, and System.Security.Cryptography tests are clean on Windows.
@stephentoub
stephentoubforce-pushed the moresafehandlefinalization branch from fd8d46d to 767ee06CompareJuly 12, 2022 20:55
@danmoseley

Copy link
Copy Markdown
Contributor

Makes sense -- probably we can use this flag on rare occasions, eg., having written a new feature with non trivial use of safehandles.

@bartonjs

Copy link
Copy Markdown
Member

If you have to spin again, Steve, I'm indifferent about keeping or removing the version in

#if DEBUG
privatestaticreadonlybools_captureTrace=
Environment.GetEnvironmentVariable("DEBUG_SAFEX509HANDLE_FINALIZATION")!=null;
privatereadonlyStackTrace?_stacktrace=
s_captureTrace?newStackTrace(fNeedFileInfo:true):null;
~SafeX509Handle()
{
if(s_captureTrace)
{
Console.WriteLine($"0x{handle.ToInt64():x}{_stacktrace?.ToString()??"no stacktrace..."}");
}
}
#endif
that I left in from getting Linux PKCS7 tidy.

@stephentoub

Copy link
Copy Markdown
MemberAuthor

I'm indifferent about keeping or removing the version

Me, too. I will need to resolve a conflict, so I can remove it if you like.

@bartonjs

Copy link
Copy Markdown
Member

Eh, if you're indifferent and I'm indifferent, let's leave it, so I can have a "smaller than the whole world" experience :)

@stephentoub
stephentoub merged commit 199580b into dotnet:mainJul 13, 2022
@stephentoub
stephentoub deleted the moresafehandlefinalization branch July 13, 2022 11:09
@ghostghost locked as resolved and limited conversation to collaborators Aug 12, 2022
@AndyAyersMS

Copy link
Copy Markdown
Member

Possible regression: dotnet/perf-autofiling-issues#6973

@bartonjs

Copy link
Copy Markdown
Member

Since CryptoConfig.CreateFromName is just a lookup in ConcurrentDictionary, reflection to find a suitable ctor, and then reflection invocation of said ctor, I don't think this change was involved.

@stephentoub

stephentoub commented Aug 18, 2022

Copy link
Copy Markdown
MemberAuthor

@bartonjs, I did touch this:
https://github.com/dotnet/runtime/pull/71991/files#diff-b5e1d8d2d47fbe472dd7de0d3d5450bc58de31363bee3ae108cf295bf879b4e4R44
I guess that could have caused this (an extra non-inlineable function call, an extra generic dictionary lookup, etc.)?

That said, I'm not sure how much a few hundred nanoseconds on this particular method matters. We don't want folks using this method anyway, right?

@bartonjs

Copy link
Copy Markdown
Member

@stephentoub

Copy link
Copy Markdown
MemberAuthor

In that case, yeah, I'm not on the hook :)

Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@stephentoub@jkotas@danmoseley@bartonjs@AndyAyersMS@AaronRobinsonMSFT
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

More reliably clean up more SafeHandle instances - #71991

Merged
stephentoub merged 5 commits into
dotnet:mainfrom
stephentoub:moresafehandlefinalization
Jul 13, 2022
Merged

More reliably clean up more SafeHandle instances#71991
stephentoub merged 5 commits into
dotnet:mainfrom
stephentoub:moresafehandlefinalization

Conversation

@stephentoub

Copy link
Copy Markdown
Member

This calls Dispose on SafeHandles (or things wrapping SafeHandles) that were otherwise being left for finalization:

  1. Some of these are fixing finalization happening even on success paths (typically where the implementation isn't disposing of something that directly or indirectly wraps a SafeHandle).
  2. Some of these are fixing finalization happening for invalid SafeHandles. Their IsInvalid is true, but they still get finalized.
  3. Some of these are fixing tests to finalize less. My goal with fixing the tests was to eliminate the noise in order to find instances of the other two cases.

These were found primarily via two means:

  • Debug-instrumentation in SafeHandle to log when one is finalized. This instrumentation is built into debug/checked builds of SafeHandle and requires setting the DEBUG_SAFEHANDLE_FINALIZATION environment variable to "1".
  • Auditing use of SafeHandle.IsInvalid

There's a lot more that can be cleaned up using the SafeHandle instrumentation, but I'm pausing here for now. The System.IO.Pipes, System.IO.FileSystem, and System.Security.Cryptography tests are clean on Windows (with the exception of a few tests that are purposefully leaving objects for finalization to test finalization code paths).

@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @dotnet/area-system-security, @vcsjones
See info in area-owners.md if you want to be subscribed.

Issue Details

This calls Dispose on SafeHandles (or things wrapping SafeHandles) that were otherwise being left for finalization:

  1. Some of these are fixing finalization happening even on success paths (typically where the implementation isn't disposing of something that directly or indirectly wraps a SafeHandle).
  2. Some of these are fixing finalization happening for invalid SafeHandles. Their IsInvalid is true, but they still get finalized.
  3. Some of these are fixing tests to finalize less. My goal with fixing the tests was to eliminate the noise in order to find instances of the other two cases.

These were found primarily via two means:

  • Debug-instrumentation in SafeHandle to log when one is finalized. This instrumentation is built into debug/checked builds of SafeHandle and requires setting the DEBUG_SAFEHANDLE_FINALIZATION environment variable to "1".
  • Auditing use of SafeHandle.IsInvalid

There's a lot more that can be cleaned up using the SafeHandle instrumentation, but I'm pausing here for now. The System.IO.Pipes, System.IO.FileSystem, and System.Security.Cryptography tests are clean on Windows (with the exception of a few tests that are purposefully leaving objects for finalization to test finalization code paths).

Author:stephentoub
Assignees:-
Labels:

area-System.Security

Milestone:-

@stephentoub
stephentoubforce-pushed the moresafehandlefinalization branch from 4e05508 to fd8d46dCompareJuly 12, 2022 13:38
Comment threadsrc/libraries/System.IO.FileSystem/tests/File/OpenHandle.cs Outdated
@jkotas

Copy link
Copy Markdown
Member

The runtime and SafeHandle.cs changes LGTM. I have done cursory review of the rest.

Comment threadsrc/libraries/Common/src/System/Net/ContextAwareResult.Windows.cs Outdated

@bartonjsbartonjs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, other than braceless usings in product code (which I believed we had banned in style outside of tests, but I guess not?)

@stephentoub

Copy link
Copy Markdown
MemberAuthor

other than braceless usings in product code (which I believed we had banned in style outside of tests

I don't know why we'd ban them.

@danmoseley

Copy link
Copy Markdown
Contributor

Yay, glad you added this switch. Do you plan to make an "up for grabs" issue to continue, in case folks are interested? eg., with a checkbox for each library that has hits (if you have that data gathered)?

Can you imagine us getting clean - I'm guessing there are test cases for finalizers, though.

How much slower is it to run tests when the switch is flipped? I assume it's expensive to gather stacks.

@stephentoub

Copy link
Copy Markdown
MemberAuthor

How much slower is it to run tests when the switch is flipped? I assume it's expensive to gather stacks.

A lot... starting with the fact that it's only built into a debug/checked runtime, and then layering on a stack walk for every safe handle created.

Can you imagine us getting clean - I'm guessing there are test cases for finalizers, though.

Without workarounds that'd be challenging, e.g. because of tests for finalizers as you say, tests that purposefully allow resources to not be disposed to avoid race conditions, etc.

if you have that data gathered

I don't.

This calls Dispose on SafeHandles (or things wrapping SafeHandles) that were otherwise being left for finalization:
1. Some of these are fixing finalization happening even on success paths (typically where the implementation isn't disposing of something that directly or indirectly wraps a SafeHandle).
2. Some of these are fixing finalization happening for invalid SafeHandles.
3. Some of these are fixing tests to finalize less. My goal with fixing the tests was to eliminate the noise in order to find instances of the other two cases.
These were found primarily via two means:
- Debug-instrumentation in SafeHandle to log when one is finalized. This instrumentation is built into debug/checked builds of SafeHandle and requires setting the DEBUG_SAFEHANDLE_FINALIZATION environment variable to "1".
- Auditing use of SafeHandle.IsInvalid
There's a lot more that can be cleaned up using the SafeHandle instrumentation, but I'm pausing here for now. The System.IO.Pipes, System.IO.FileSystem, and System.Security.Cryptography tests are clean on Windows.
@stephentoub
stephentoubforce-pushed the moresafehandlefinalization branch from fd8d46d to 767ee06CompareJuly 12, 2022 20:55
@danmoseley

Copy link
Copy Markdown
Contributor

Makes sense -- probably we can use this flag on rare occasions, eg., having written a new feature with non trivial use of safehandles.

@bartonjs

Copy link
Copy Markdown
Member

If you have to spin again, Steve, I'm indifferent about keeping or removing the version in

#if DEBUG
privatestaticreadonlybools_captureTrace=
Environment.GetEnvironmentVariable("DEBUG_SAFEX509HANDLE_FINALIZATION")!=null;
privatereadonlyStackTrace?_stacktrace=
s_captureTrace?newStackTrace(fNeedFileInfo:true):null;
~SafeX509Handle()
{
if(s_captureTrace)
{
Console.WriteLine($"0x{handle.ToInt64():x}{_stacktrace?.ToString()??"no stacktrace..."}");
}
}
#endif
that I left in from getting Linux PKCS7 tidy.

@stephentoub

Copy link
Copy Markdown
MemberAuthor

I'm indifferent about keeping or removing the version

Me, too. I will need to resolve a conflict, so I can remove it if you like.

@bartonjs

Copy link
Copy Markdown
Member

Eh, if you're indifferent and I'm indifferent, let's leave it, so I can have a "smaller than the whole world" experience :)

@stephentoub
stephentoub merged commit 199580b into dotnet:mainJul 13, 2022
@stephentoub
stephentoub deleted the moresafehandlefinalization branch July 13, 2022 11:09
@ghostghost locked as resolved and limited conversation to collaborators Aug 12, 2022
@AndyAyersMS

Copy link
Copy Markdown
Member

Possible regression: dotnet/perf-autofiling-issues#6973

@bartonjs

Copy link
Copy Markdown
Member

Since CryptoConfig.CreateFromName is just a lookup in ConcurrentDictionary, reflection to find a suitable ctor, and then reflection invocation of said ctor, I don't think this change was involved.

@stephentoub

stephentoub commented Aug 18, 2022

Copy link
Copy Markdown
MemberAuthor

@bartonjs, I did touch this:
https://github.com/dotnet/runtime/pull/71991/files#diff-b5e1d8d2d47fbe472dd7de0d3d5450bc58de31363bee3ae108cf295bf879b4e4R44
I guess that could have caused this (an extra non-inlineable function call, an extra generic dictionary lookup, etc.)?

That said, I'm not sure how much a few hundred nanoseconds on this particular method matters. We don't want folks using this method anyway, right?

@bartonjs

Copy link
Copy Markdown
Member

@stephentoub

Copy link
Copy Markdown
MemberAuthor

In that case, yeah, I'm not on the hook :)

Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@stephentoub@jkotas@danmoseley@bartonjs@AndyAyersMS@AaronRobinsonMSFT
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

More reliably clean up more SafeHandle instances - #71991

Merged
stephentoub merged 5 commits into
dotnet:mainfrom
stephentoub:moresafehandlefinalization
Jul 13, 2022
Merged

More reliably clean up more SafeHandle instances#71991
stephentoub merged 5 commits into
dotnet:mainfrom
stephentoub:moresafehandlefinalization

Conversation

@stephentoub

Copy link
Copy Markdown
Member

This calls Dispose on SafeHandles (or things wrapping SafeHandles) that were otherwise being left for finalization:

  1. Some of these are fixing finalization happening even on success paths (typically where the implementation isn't disposing of something that directly or indirectly wraps a SafeHandle).
  2. Some of these are fixing finalization happening for invalid SafeHandles. Their IsInvalid is true, but they still get finalized.
  3. Some of these are fixing tests to finalize less. My goal with fixing the tests was to eliminate the noise in order to find instances of the other two cases.

These were found primarily via two means:

  • Debug-instrumentation in SafeHandle to log when one is finalized. This instrumentation is built into debug/checked builds of SafeHandle and requires setting the DEBUG_SAFEHANDLE_FINALIZATION environment variable to "1".
  • Auditing use of SafeHandle.IsInvalid

There's a lot more that can be cleaned up using the SafeHandle instrumentation, but I'm pausing here for now. The System.IO.Pipes, System.IO.FileSystem, and System.Security.Cryptography tests are clean on Windows (with the exception of a few tests that are purposefully leaving objects for finalization to test finalization code paths).

@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @dotnet/area-system-security, @vcsjones
See info in area-owners.md if you want to be subscribed.

Issue Details

This calls Dispose on SafeHandles (or things wrapping SafeHandles) that were otherwise being left for finalization:

  1. Some of these are fixing finalization happening even on success paths (typically where the implementation isn't disposing of something that directly or indirectly wraps a SafeHandle).
  2. Some of these are fixing finalization happening for invalid SafeHandles. Their IsInvalid is true, but they still get finalized.
  3. Some of these are fixing tests to finalize less. My goal with fixing the tests was to eliminate the noise in order to find instances of the other two cases.

These were found primarily via two means:

  • Debug-instrumentation in SafeHandle to log when one is finalized. This instrumentation is built into debug/checked builds of SafeHandle and requires setting the DEBUG_SAFEHANDLE_FINALIZATION environment variable to "1".
  • Auditing use of SafeHandle.IsInvalid

There's a lot more that can be cleaned up using the SafeHandle instrumentation, but I'm pausing here for now. The System.IO.Pipes, System.IO.FileSystem, and System.Security.Cryptography tests are clean on Windows (with the exception of a few tests that are purposefully leaving objects for finalization to test finalization code paths).

Author:stephentoub
Assignees:-
Labels:

area-System.Security

Milestone:-

@stephentoub
stephentoubforce-pushed the moresafehandlefinalization branch from 4e05508 to fd8d46dCompareJuly 12, 2022 13:38
Comment threadsrc/libraries/System.IO.FileSystem/tests/File/OpenHandle.cs Outdated
@jkotas

Copy link
Copy Markdown
Member

The runtime and SafeHandle.cs changes LGTM. I have done cursory review of the rest.

Comment threadsrc/libraries/Common/src/System/Net/ContextAwareResult.Windows.cs Outdated

@bartonjsbartonjs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, other than braceless usings in product code (which I believed we had banned in style outside of tests, but I guess not?)

@stephentoub

Copy link
Copy Markdown
MemberAuthor

other than braceless usings in product code (which I believed we had banned in style outside of tests

I don't know why we'd ban them.

@danmoseley

Copy link
Copy Markdown
Contributor

Yay, glad you added this switch. Do you plan to make an "up for grabs" issue to continue, in case folks are interested? eg., with a checkbox for each library that has hits (if you have that data gathered)?

Can you imagine us getting clean - I'm guessing there are test cases for finalizers, though.

How much slower is it to run tests when the switch is flipped? I assume it's expensive to gather stacks.

@stephentoub

Copy link
Copy Markdown
MemberAuthor

How much slower is it to run tests when the switch is flipped? I assume it's expensive to gather stacks.

A lot... starting with the fact that it's only built into a debug/checked runtime, and then layering on a stack walk for every safe handle created.

Can you imagine us getting clean - I'm guessing there are test cases for finalizers, though.

Without workarounds that'd be challenging, e.g. because of tests for finalizers as you say, tests that purposefully allow resources to not be disposed to avoid race conditions, etc.

if you have that data gathered

I don't.

This calls Dispose on SafeHandles (or things wrapping SafeHandles) that were otherwise being left for finalization:
1. Some of these are fixing finalization happening even on success paths (typically where the implementation isn't disposing of something that directly or indirectly wraps a SafeHandle).
2. Some of these are fixing finalization happening for invalid SafeHandles.
3. Some of these are fixing tests to finalize less. My goal with fixing the tests was to eliminate the noise in order to find instances of the other two cases.
These were found primarily via two means:
- Debug-instrumentation in SafeHandle to log when one is finalized. This instrumentation is built into debug/checked builds of SafeHandle and requires setting the DEBUG_SAFEHANDLE_FINALIZATION environment variable to "1".
- Auditing use of SafeHandle.IsInvalid
There's a lot more that can be cleaned up using the SafeHandle instrumentation, but I'm pausing here for now. The System.IO.Pipes, System.IO.FileSystem, and System.Security.Cryptography tests are clean on Windows.
@stephentoub
stephentoubforce-pushed the moresafehandlefinalization branch from fd8d46d to 767ee06CompareJuly 12, 2022 20:55
@danmoseley

Copy link
Copy Markdown
Contributor

Makes sense -- probably we can use this flag on rare occasions, eg., having written a new feature with non trivial use of safehandles.

@bartonjs

Copy link
Copy Markdown
Member

If you have to spin again, Steve, I'm indifferent about keeping or removing the version in

#if DEBUG
privatestaticreadonlybools_captureTrace=
Environment.GetEnvironmentVariable("DEBUG_SAFEX509HANDLE_FINALIZATION")!=null;
privatereadonlyStackTrace?_stacktrace=
s_captureTrace?newStackTrace(fNeedFileInfo:true):null;
~SafeX509Handle()
{
if(s_captureTrace)
{
Console.WriteLine($"0x{handle.ToInt64():x}{_stacktrace?.ToString()??"no stacktrace..."}");
}
}
#endif
that I left in from getting Linux PKCS7 tidy.

@stephentoub

Copy link
Copy Markdown
MemberAuthor

I'm indifferent about keeping or removing the version

Me, too. I will need to resolve a conflict, so I can remove it if you like.

@bartonjs

Copy link
Copy Markdown
Member

Eh, if you're indifferent and I'm indifferent, let's leave it, so I can have a "smaller than the whole world" experience :)

@stephentoub
stephentoub merged commit 199580b into dotnet:mainJul 13, 2022
@stephentoub
stephentoub deleted the moresafehandlefinalization branch July 13, 2022 11:09
@ghostghost locked as resolved and limited conversation to collaborators Aug 12, 2022
@AndyAyersMS

Copy link
Copy Markdown
Member

Possible regression: dotnet/perf-autofiling-issues#6973

@bartonjs

Copy link
Copy Markdown
Member

Since CryptoConfig.CreateFromName is just a lookup in ConcurrentDictionary, reflection to find a suitable ctor, and then reflection invocation of said ctor, I don't think this change was involved.

@stephentoub

stephentoub commented Aug 18, 2022

Copy link
Copy Markdown
MemberAuthor

@bartonjs, I did touch this:
https://github.com/dotnet/runtime/pull/71991/files#diff-b5e1d8d2d47fbe472dd7de0d3d5450bc58de31363bee3ae108cf295bf879b4e4R44
I guess that could have caused this (an extra non-inlineable function call, an extra generic dictionary lookup, etc.)?

That said, I'm not sure how much a few hundred nanoseconds on this particular method matters. We don't want folks using this method anyway, right?

@bartonjs

Copy link
Copy Markdown
Member

@stephentoub

Copy link
Copy Markdown
MemberAuthor

In that case, yeah, I'm not on the hook :)

Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@stephentoub@jkotas@danmoseley@bartonjs@AndyAyersMS@AaronRobinsonMSFT
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

More reliably clean up more SafeHandle instances - #71991

Merged
stephentoub merged 5 commits into
dotnet:mainfrom
stephentoub:moresafehandlefinalization
Jul 13, 2022
Merged

More reliably clean up more SafeHandle instances#71991
stephentoub merged 5 commits into
dotnet:mainfrom
stephentoub:moresafehandlefinalization

Conversation

@stephentoub

Copy link
Copy Markdown
Member

This calls Dispose on SafeHandles (or things wrapping SafeHandles) that were otherwise being left for finalization:

  1. Some of these are fixing finalization happening even on success paths (typically where the implementation isn't disposing of something that directly or indirectly wraps a SafeHandle).
  2. Some of these are fixing finalization happening for invalid SafeHandles. Their IsInvalid is true, but they still get finalized.
  3. Some of these are fixing tests to finalize less. My goal with fixing the tests was to eliminate the noise in order to find instances of the other two cases.

These were found primarily via two means:

  • Debug-instrumentation in SafeHandle to log when one is finalized. This instrumentation is built into debug/checked builds of SafeHandle and requires setting the DEBUG_SAFEHANDLE_FINALIZATION environment variable to "1".
  • Auditing use of SafeHandle.IsInvalid

There's a lot more that can be cleaned up using the SafeHandle instrumentation, but I'm pausing here for now. The System.IO.Pipes, System.IO.FileSystem, and System.Security.Cryptography tests are clean on Windows (with the exception of a few tests that are purposefully leaving objects for finalization to test finalization code paths).

@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @dotnet/area-system-security, @vcsjones
See info in area-owners.md if you want to be subscribed.

Issue Details

This calls Dispose on SafeHandles (or things wrapping SafeHandles) that were otherwise being left for finalization:

  1. Some of these are fixing finalization happening even on success paths (typically where the implementation isn't disposing of something that directly or indirectly wraps a SafeHandle).
  2. Some of these are fixing finalization happening for invalid SafeHandles. Their IsInvalid is true, but they still get finalized.
  3. Some of these are fixing tests to finalize less. My goal with fixing the tests was to eliminate the noise in order to find instances of the other two cases.

These were found primarily via two means:

  • Debug-instrumentation in SafeHandle to log when one is finalized. This instrumentation is built into debug/checked builds of SafeHandle and requires setting the DEBUG_SAFEHANDLE_FINALIZATION environment variable to "1".
  • Auditing use of SafeHandle.IsInvalid

There's a lot more that can be cleaned up using the SafeHandle instrumentation, but I'm pausing here for now. The System.IO.Pipes, System.IO.FileSystem, and System.Security.Cryptography tests are clean on Windows (with the exception of a few tests that are purposefully leaving objects for finalization to test finalization code paths).

Author:stephentoub
Assignees:-
Labels:

area-System.Security

Milestone:-

@stephentoub
stephentoubforce-pushed the moresafehandlefinalization branch from 4e05508 to fd8d46dCompareJuly 12, 2022 13:38
Comment threadsrc/libraries/System.IO.FileSystem/tests/File/OpenHandle.cs Outdated
@jkotas

Copy link
Copy Markdown
Member

The runtime and SafeHandle.cs changes LGTM. I have done cursory review of the rest.

Comment threadsrc/libraries/Common/src/System/Net/ContextAwareResult.Windows.cs Outdated

@bartonjsbartonjs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, other than braceless usings in product code (which I believed we had banned in style outside of tests, but I guess not?)

@stephentoub

Copy link
Copy Markdown
MemberAuthor

other than braceless usings in product code (which I believed we had banned in style outside of tests

I don't know why we'd ban them.

@danmoseley

Copy link
Copy Markdown
Contributor

Yay, glad you added this switch. Do you plan to make an "up for grabs" issue to continue, in case folks are interested? eg., with a checkbox for each library that has hits (if you have that data gathered)?

Can you imagine us getting clean - I'm guessing there are test cases for finalizers, though.

How much slower is it to run tests when the switch is flipped? I assume it's expensive to gather stacks.

@stephentoub

Copy link
Copy Markdown
MemberAuthor

How much slower is it to run tests when the switch is flipped? I assume it's expensive to gather stacks.

A lot... starting with the fact that it's only built into a debug/checked runtime, and then layering on a stack walk for every safe handle created.

Can you imagine us getting clean - I'm guessing there are test cases for finalizers, though.

Without workarounds that'd be challenging, e.g. because of tests for finalizers as you say, tests that purposefully allow resources to not be disposed to avoid race conditions, etc.

if you have that data gathered

I don't.

This calls Dispose on SafeHandles (or things wrapping SafeHandles) that were otherwise being left for finalization:
1. Some of these are fixing finalization happening even on success paths (typically where the implementation isn't disposing of something that directly or indirectly wraps a SafeHandle).
2. Some of these are fixing finalization happening for invalid SafeHandles.
3. Some of these are fixing tests to finalize less. My goal with fixing the tests was to eliminate the noise in order to find instances of the other two cases.
These were found primarily via two means:
- Debug-instrumentation in SafeHandle to log when one is finalized. This instrumentation is built into debug/checked builds of SafeHandle and requires setting the DEBUG_SAFEHANDLE_FINALIZATION environment variable to "1".
- Auditing use of SafeHandle.IsInvalid
There's a lot more that can be cleaned up using the SafeHandle instrumentation, but I'm pausing here for now. The System.IO.Pipes, System.IO.FileSystem, and System.Security.Cryptography tests are clean on Windows.
@stephentoub
stephentoubforce-pushed the moresafehandlefinalization branch from fd8d46d to 767ee06CompareJuly 12, 2022 20:55
@danmoseley

Copy link
Copy Markdown
Contributor

Makes sense -- probably we can use this flag on rare occasions, eg., having written a new feature with non trivial use of safehandles.

@bartonjs

Copy link
Copy Markdown
Member

If you have to spin again, Steve, I'm indifferent about keeping or removing the version in

#if DEBUG
privatestaticreadonlybools_captureTrace=
Environment.GetEnvironmentVariable("DEBUG_SAFEX509HANDLE_FINALIZATION")!=null;
privatereadonlyStackTrace?_stacktrace=
s_captureTrace?newStackTrace(fNeedFileInfo:true):null;
~SafeX509Handle()
{
if(s_captureTrace)
{
Console.WriteLine($"0x{handle.ToInt64():x}{_stacktrace?.ToString()??"no stacktrace..."}");
}
}
#endif
that I left in from getting Linux PKCS7 tidy.

@stephentoub

Copy link
Copy Markdown
MemberAuthor

I'm indifferent about keeping or removing the version

Me, too. I will need to resolve a conflict, so I can remove it if you like.

@bartonjs

Copy link
Copy Markdown
Member

Eh, if you're indifferent and I'm indifferent, let's leave it, so I can have a "smaller than the whole world" experience :)

@stephentoub
stephentoub merged commit 199580b into dotnet:mainJul 13, 2022
@stephentoub
stephentoub deleted the moresafehandlefinalization branch July 13, 2022 11:09
@ghostghost locked as resolved and limited conversation to collaborators Aug 12, 2022
@AndyAyersMS

Copy link
Copy Markdown
Member

Possible regression: dotnet/perf-autofiling-issues#6973

@bartonjs

Copy link
Copy Markdown
Member

Since CryptoConfig.CreateFromName is just a lookup in ConcurrentDictionary, reflection to find a suitable ctor, and then reflection invocation of said ctor, I don't think this change was involved.

@stephentoub

stephentoub commented Aug 18, 2022

Copy link
Copy Markdown
MemberAuthor

@bartonjs, I did touch this:
https://github.com/dotnet/runtime/pull/71991/files#diff-b5e1d8d2d47fbe472dd7de0d3d5450bc58de31363bee3ae108cf295bf879b4e4R44
I guess that could have caused this (an extra non-inlineable function call, an extra generic dictionary lookup, etc.)?

That said, I'm not sure how much a few hundred nanoseconds on this particular method matters. We don't want folks using this method anyway, right?

@bartonjs

Copy link
Copy Markdown
Member

@stephentoub

Copy link
Copy Markdown
MemberAuthor

In that case, yeah, I'm not on the hook :)

Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@stephentoub@jkotas@danmoseley@bartonjs@AndyAyersMS@AaronRobinsonMSFT
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

More reliably clean up more SafeHandle instances - #71991

Merged
stephentoub merged 5 commits into
dotnet:mainfrom
stephentoub:moresafehandlefinalization
Jul 13, 2022
Merged

More reliably clean up more SafeHandle instances#71991
stephentoub merged 5 commits into
dotnet:mainfrom
stephentoub:moresafehandlefinalization

Conversation

@stephentoub

Copy link
Copy Markdown
Member

This calls Dispose on SafeHandles (or things wrapping SafeHandles) that were otherwise being left for finalization:

  1. Some of these are fixing finalization happening even on success paths (typically where the implementation isn't disposing of something that directly or indirectly wraps a SafeHandle).
  2. Some of these are fixing finalization happening for invalid SafeHandles. Their IsInvalid is true, but they still get finalized.
  3. Some of these are fixing tests to finalize less. My goal with fixing the tests was to eliminate the noise in order to find instances of the other two cases.

These were found primarily via two means:

  • Debug-instrumentation in SafeHandle to log when one is finalized. This instrumentation is built into debug/checked builds of SafeHandle and requires setting the DEBUG_SAFEHANDLE_FINALIZATION environment variable to "1".
  • Auditing use of SafeHandle.IsInvalid

There's a lot more that can be cleaned up using the SafeHandle instrumentation, but I'm pausing here for now. The System.IO.Pipes, System.IO.FileSystem, and System.Security.Cryptography tests are clean on Windows (with the exception of a few tests that are purposefully leaving objects for finalization to test finalization code paths).

@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @dotnet/area-system-security, @vcsjones
See info in area-owners.md if you want to be subscribed.

Issue Details

This calls Dispose on SafeHandles (or things wrapping SafeHandles) that were otherwise being left for finalization:

  1. Some of these are fixing finalization happening even on success paths (typically where the implementation isn't disposing of something that directly or indirectly wraps a SafeHandle).
  2. Some of these are fixing finalization happening for invalid SafeHandles. Their IsInvalid is true, but they still get finalized.
  3. Some of these are fixing tests to finalize less. My goal with fixing the tests was to eliminate the noise in order to find instances of the other two cases.

These were found primarily via two means:

  • Debug-instrumentation in SafeHandle to log when one is finalized. This instrumentation is built into debug/checked builds of SafeHandle and requires setting the DEBUG_SAFEHANDLE_FINALIZATION environment variable to "1".
  • Auditing use of SafeHandle.IsInvalid

There's a lot more that can be cleaned up using the SafeHandle instrumentation, but I'm pausing here for now. The System.IO.Pipes, System.IO.FileSystem, and System.Security.Cryptography tests are clean on Windows (with the exception of a few tests that are purposefully leaving objects for finalization to test finalization code paths).

Author:stephentoub
Assignees:-
Labels:

area-System.Security

Milestone:-

@stephentoub
stephentoubforce-pushed the moresafehandlefinalization branch from 4e05508 to fd8d46dCompareJuly 12, 2022 13:38
Comment threadsrc/libraries/System.IO.FileSystem/tests/File/OpenHandle.cs Outdated
@jkotas

Copy link
Copy Markdown
Member

The runtime and SafeHandle.cs changes LGTM. I have done cursory review of the rest.

Comment threadsrc/libraries/Common/src/System/Net/ContextAwareResult.Windows.cs Outdated

@bartonjsbartonjs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, other than braceless usings in product code (which I believed we had banned in style outside of tests, but I guess not?)

@stephentoub

Copy link
Copy Markdown
MemberAuthor

other than braceless usings in product code (which I believed we had banned in style outside of tests

I don't know why we'd ban them.

@danmoseley

Copy link
Copy Markdown
Contributor

Yay, glad you added this switch. Do you plan to make an "up for grabs" issue to continue, in case folks are interested? eg., with a checkbox for each library that has hits (if you have that data gathered)?

Can you imagine us getting clean - I'm guessing there are test cases for finalizers, though.

How much slower is it to run tests when the switch is flipped? I assume it's expensive to gather stacks.

@stephentoub

Copy link
Copy Markdown
MemberAuthor

How much slower is it to run tests when the switch is flipped? I assume it's expensive to gather stacks.

A lot... starting with the fact that it's only built into a debug/checked runtime, and then layering on a stack walk for every safe handle created.

Can you imagine us getting clean - I'm guessing there are test cases for finalizers, though.

Without workarounds that'd be challenging, e.g. because of tests for finalizers as you say, tests that purposefully allow resources to not be disposed to avoid race conditions, etc.

if you have that data gathered

I don't.

This calls Dispose on SafeHandles (or things wrapping SafeHandles) that were otherwise being left for finalization:
1. Some of these are fixing finalization happening even on success paths (typically where the implementation isn't disposing of something that directly or indirectly wraps a SafeHandle).
2. Some of these are fixing finalization happening for invalid SafeHandles.
3. Some of these are fixing tests to finalize less. My goal with fixing the tests was to eliminate the noise in order to find instances of the other two cases.
These were found primarily via two means:
- Debug-instrumentation in SafeHandle to log when one is finalized. This instrumentation is built into debug/checked builds of SafeHandle and requires setting the DEBUG_SAFEHANDLE_FINALIZATION environment variable to "1".
- Auditing use of SafeHandle.IsInvalid
There's a lot more that can be cleaned up using the SafeHandle instrumentation, but I'm pausing here for now. The System.IO.Pipes, System.IO.FileSystem, and System.Security.Cryptography tests are clean on Windows.
@stephentoub
stephentoubforce-pushed the moresafehandlefinalization branch from fd8d46d to 767ee06CompareJuly 12, 2022 20:55
@danmoseley

Copy link
Copy Markdown
Contributor

Makes sense -- probably we can use this flag on rare occasions, eg., having written a new feature with non trivial use of safehandles.

@bartonjs

Copy link
Copy Markdown
Member

If you have to spin again, Steve, I'm indifferent about keeping or removing the version in

#if DEBUG
privatestaticreadonlybools_captureTrace=
Environment.GetEnvironmentVariable("DEBUG_SAFEX509HANDLE_FINALIZATION")!=null;
privatereadonlyStackTrace?_stacktrace=
s_captureTrace?newStackTrace(fNeedFileInfo:true):null;
~SafeX509Handle()
{
if(s_captureTrace)
{
Console.WriteLine($"0x{handle.ToInt64():x}{_stacktrace?.ToString()??"no stacktrace..."}");
}
}
#endif
that I left in from getting Linux PKCS7 tidy.

@stephentoub

Copy link
Copy Markdown
MemberAuthor

I'm indifferent about keeping or removing the version

Me, too. I will need to resolve a conflict, so I can remove it if you like.

@bartonjs

Copy link
Copy Markdown
Member

Eh, if you're indifferent and I'm indifferent, let's leave it, so I can have a "smaller than the whole world" experience :)

@stephentoub
stephentoub merged commit 199580b into dotnet:mainJul 13, 2022
@stephentoub
stephentoub deleted the moresafehandlefinalization branch July 13, 2022 11:09
@ghostghost locked as resolved and limited conversation to collaborators Aug 12, 2022
@AndyAyersMS

Copy link
Copy Markdown
Member

Possible regression: dotnet/perf-autofiling-issues#6973

@bartonjs

Copy link
Copy Markdown
Member

Since CryptoConfig.CreateFromName is just a lookup in ConcurrentDictionary, reflection to find a suitable ctor, and then reflection invocation of said ctor, I don't think this change was involved.

@stephentoub

stephentoub commented Aug 18, 2022

Copy link
Copy Markdown
MemberAuthor

@bartonjs, I did touch this:
https://github.com/dotnet/runtime/pull/71991/files#diff-b5e1d8d2d47fbe472dd7de0d3d5450bc58de31363bee3ae108cf295bf879b4e4R44
I guess that could have caused this (an extra non-inlineable function call, an extra generic dictionary lookup, etc.)?

That said, I'm not sure how much a few hundred nanoseconds on this particular method matters. We don't want folks using this method anyway, right?

@bartonjs

Copy link
Copy Markdown
Member

@stephentoub

Copy link
Copy Markdown
MemberAuthor

In that case, yeah, I'm not on the hook :)

Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@stephentoub@jkotas@danmoseley@bartonjs@AndyAyersMS@AaronRobinsonMSFT
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

More reliably clean up more SafeHandle instances - #71991

Merged
stephentoub merged 5 commits into
dotnet:mainfrom
stephentoub:moresafehandlefinalization
Jul 13, 2022
Merged

More reliably clean up more SafeHandle instances#71991
stephentoub merged 5 commits into
dotnet:mainfrom
stephentoub:moresafehandlefinalization

Conversation

@stephentoub

Copy link
Copy Markdown
Member

This calls Dispose on SafeHandles (or things wrapping SafeHandles) that were otherwise being left for finalization:

  1. Some of these are fixing finalization happening even on success paths (typically where the implementation isn't disposing of something that directly or indirectly wraps a SafeHandle).
  2. Some of these are fixing finalization happening for invalid SafeHandles. Their IsInvalid is true, but they still get finalized.
  3. Some of these are fixing tests to finalize less. My goal with fixing the tests was to eliminate the noise in order to find instances of the other two cases.

These were found primarily via two means:

  • Debug-instrumentation in SafeHandle to log when one is finalized. This instrumentation is built into debug/checked builds of SafeHandle and requires setting the DEBUG_SAFEHANDLE_FINALIZATION environment variable to "1".
  • Auditing use of SafeHandle.IsInvalid

There's a lot more that can be cleaned up using the SafeHandle instrumentation, but I'm pausing here for now. The System.IO.Pipes, System.IO.FileSystem, and System.Security.Cryptography tests are clean on Windows (with the exception of a few tests that are purposefully leaving objects for finalization to test finalization code paths).

@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @dotnet/area-system-security, @vcsjones
See info in area-owners.md if you want to be subscribed.

Issue Details

This calls Dispose on SafeHandles (or things wrapping SafeHandles) that were otherwise being left for finalization:

  1. Some of these are fixing finalization happening even on success paths (typically where the implementation isn't disposing of something that directly or indirectly wraps a SafeHandle).
  2. Some of these are fixing finalization happening for invalid SafeHandles. Their IsInvalid is true, but they still get finalized.
  3. Some of these are fixing tests to finalize less. My goal with fixing the tests was to eliminate the noise in order to find instances of the other two cases.

These were found primarily via two means:

  • Debug-instrumentation in SafeHandle to log when one is finalized. This instrumentation is built into debug/checked builds of SafeHandle and requires setting the DEBUG_SAFEHANDLE_FINALIZATION environment variable to "1".
  • Auditing use of SafeHandle.IsInvalid

There's a lot more that can be cleaned up using the SafeHandle instrumentation, but I'm pausing here for now. The System.IO.Pipes, System.IO.FileSystem, and System.Security.Cryptography tests are clean on Windows (with the exception of a few tests that are purposefully leaving objects for finalization to test finalization code paths).

Author:stephentoub
Assignees:-
Labels:

area-System.Security

Milestone:-

@stephentoub
stephentoubforce-pushed the moresafehandlefinalization branch from 4e05508 to fd8d46dCompareJuly 12, 2022 13:38
Comment threadsrc/libraries/System.IO.FileSystem/tests/File/OpenHandle.cs Outdated
@jkotas

Copy link
Copy Markdown
Member

The runtime and SafeHandle.cs changes LGTM. I have done cursory review of the rest.

Comment threadsrc/libraries/Common/src/System/Net/ContextAwareResult.Windows.cs Outdated

@bartonjsbartonjs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, other than braceless usings in product code (which I believed we had banned in style outside of tests, but I guess not?)

@stephentoub

Copy link
Copy Markdown
MemberAuthor

other than braceless usings in product code (which I believed we had banned in style outside of tests

I don't know why we'd ban them.

@danmoseley

Copy link
Copy Markdown
Contributor

Yay, glad you added this switch. Do you plan to make an "up for grabs" issue to continue, in case folks are interested? eg., with a checkbox for each library that has hits (if you have that data gathered)?

Can you imagine us getting clean - I'm guessing there are test cases for finalizers, though.

How much slower is it to run tests when the switch is flipped? I assume it's expensive to gather stacks.

@stephentoub

Copy link
Copy Markdown
MemberAuthor

How much slower is it to run tests when the switch is flipped? I assume it's expensive to gather stacks.

A lot... starting with the fact that it's only built into a debug/checked runtime, and then layering on a stack walk for every safe handle created.

Can you imagine us getting clean - I'm guessing there are test cases for finalizers, though.

Without workarounds that'd be challenging, e.g. because of tests for finalizers as you say, tests that purposefully allow resources to not be disposed to avoid race conditions, etc.

if you have that data gathered

I don't.

This calls Dispose on SafeHandles (or things wrapping SafeHandles) that were otherwise being left for finalization:
1. Some of these are fixing finalization happening even on success paths (typically where the implementation isn't disposing of something that directly or indirectly wraps a SafeHandle).
2. Some of these are fixing finalization happening for invalid SafeHandles.
3. Some of these are fixing tests to finalize less. My goal with fixing the tests was to eliminate the noise in order to find instances of the other two cases.
These were found primarily via two means:
- Debug-instrumentation in SafeHandle to log when one is finalized. This instrumentation is built into debug/checked builds of SafeHandle and requires setting the DEBUG_SAFEHANDLE_FINALIZATION environment variable to "1".
- Auditing use of SafeHandle.IsInvalid
There's a lot more that can be cleaned up using the SafeHandle instrumentation, but I'm pausing here for now. The System.IO.Pipes, System.IO.FileSystem, and System.Security.Cryptography tests are clean on Windows.
@stephentoub
stephentoubforce-pushed the moresafehandlefinalization branch from fd8d46d to 767ee06CompareJuly 12, 2022 20:55
@danmoseley

Copy link
Copy Markdown
Contributor

Makes sense -- probably we can use this flag on rare occasions, eg., having written a new feature with non trivial use of safehandles.

@bartonjs

Copy link
Copy Markdown
Member

If you have to spin again, Steve, I'm indifferent about keeping or removing the version in

#if DEBUG
privatestaticreadonlybools_captureTrace=
Environment.GetEnvironmentVariable("DEBUG_SAFEX509HANDLE_FINALIZATION")!=null;
privatereadonlyStackTrace?_stacktrace=
s_captureTrace?newStackTrace(fNeedFileInfo:true):null;
~SafeX509Handle()
{
if(s_captureTrace)
{
Console.WriteLine($"0x{handle.ToInt64():x}{_stacktrace?.ToString()??"no stacktrace..."}");
}
}
#endif
that I left in from getting Linux PKCS7 tidy.

@stephentoub

Copy link
Copy Markdown
MemberAuthor

I'm indifferent about keeping or removing the version

Me, too. I will need to resolve a conflict, so I can remove it if you like.

@bartonjs

Copy link
Copy Markdown
Member

Eh, if you're indifferent and I'm indifferent, let's leave it, so I can have a "smaller than the whole world" experience :)

@stephentoub
stephentoub merged commit 199580b into dotnet:mainJul 13, 2022
@stephentoub
stephentoub deleted the moresafehandlefinalization branch July 13, 2022 11:09
@ghostghost locked as resolved and limited conversation to collaborators Aug 12, 2022
@AndyAyersMS

Copy link
Copy Markdown
Member

Possible regression: dotnet/perf-autofiling-issues#6973

@bartonjs

Copy link
Copy Markdown
Member

Since CryptoConfig.CreateFromName is just a lookup in ConcurrentDictionary, reflection to find a suitable ctor, and then reflection invocation of said ctor, I don't think this change was involved.

@stephentoub

stephentoub commented Aug 18, 2022

Copy link
Copy Markdown
MemberAuthor

@bartonjs, I did touch this:
https://github.com/dotnet/runtime/pull/71991/files#diff-b5e1d8d2d47fbe472dd7de0d3d5450bc58de31363bee3ae108cf295bf879b4e4R44
I guess that could have caused this (an extra non-inlineable function call, an extra generic dictionary lookup, etc.)?

That said, I'm not sure how much a few hundred nanoseconds on this particular method matters. We don't want folks using this method anyway, right?

@bartonjs

Copy link
Copy Markdown
Member

@stephentoub

Copy link
Copy Markdown
MemberAuthor

In that case, yeah, I'm not on the hook :)

Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@stephentoub@jkotas@danmoseley@bartonjs@AndyAyersMS@AaronRobinsonMSFT
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

More reliably clean up more SafeHandle instances - #71991

Merged
stephentoub merged 5 commits into
dotnet:mainfrom
stephentoub:moresafehandlefinalization
Jul 13, 2022
Merged

More reliably clean up more SafeHandle instances#71991
stephentoub merged 5 commits into
dotnet:mainfrom
stephentoub:moresafehandlefinalization

Conversation

@stephentoub

Copy link
Copy Markdown
Member

This calls Dispose on SafeHandles (or things wrapping SafeHandles) that were otherwise being left for finalization:

  1. Some of these are fixing finalization happening even on success paths (typically where the implementation isn't disposing of something that directly or indirectly wraps a SafeHandle).
  2. Some of these are fixing finalization happening for invalid SafeHandles. Their IsInvalid is true, but they still get finalized.
  3. Some of these are fixing tests to finalize less. My goal with fixing the tests was to eliminate the noise in order to find instances of the other two cases.

These were found primarily via two means:

  • Debug-instrumentation in SafeHandle to log when one is finalized. This instrumentation is built into debug/checked builds of SafeHandle and requires setting the DEBUG_SAFEHANDLE_FINALIZATION environment variable to "1".
  • Auditing use of SafeHandle.IsInvalid

There's a lot more that can be cleaned up using the SafeHandle instrumentation, but I'm pausing here for now. The System.IO.Pipes, System.IO.FileSystem, and System.Security.Cryptography tests are clean on Windows (with the exception of a few tests that are purposefully leaving objects for finalization to test finalization code paths).

@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @dotnet/area-system-security, @vcsjones
See info in area-owners.md if you want to be subscribed.

Issue Details

This calls Dispose on SafeHandles (or things wrapping SafeHandles) that were otherwise being left for finalization:

  1. Some of these are fixing finalization happening even on success paths (typically where the implementation isn't disposing of something that directly or indirectly wraps a SafeHandle).
  2. Some of these are fixing finalization happening for invalid SafeHandles. Their IsInvalid is true, but they still get finalized.
  3. Some of these are fixing tests to finalize less. My goal with fixing the tests was to eliminate the noise in order to find instances of the other two cases.

These were found primarily via two means:

  • Debug-instrumentation in SafeHandle to log when one is finalized. This instrumentation is built into debug/checked builds of SafeHandle and requires setting the DEBUG_SAFEHANDLE_FINALIZATION environment variable to "1".
  • Auditing use of SafeHandle.IsInvalid

There's a lot more that can be cleaned up using the SafeHandle instrumentation, but I'm pausing here for now. The System.IO.Pipes, System.IO.FileSystem, and System.Security.Cryptography tests are clean on Windows (with the exception of a few tests that are purposefully leaving objects for finalization to test finalization code paths).

Author:stephentoub
Assignees:-
Labels:

area-System.Security

Milestone:-

@stephentoub
stephentoubforce-pushed the moresafehandlefinalization branch from 4e05508 to fd8d46dCompareJuly 12, 2022 13:38
Comment threadsrc/libraries/System.IO.FileSystem/tests/File/OpenHandle.cs Outdated
@jkotas

Copy link
Copy Markdown
Member

The runtime and SafeHandle.cs changes LGTM. I have done cursory review of the rest.

Comment threadsrc/libraries/Common/src/System/Net/ContextAwareResult.Windows.cs Outdated

@bartonjsbartonjs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, other than braceless usings in product code (which I believed we had banned in style outside of tests, but I guess not?)

@stephentoub

Copy link
Copy Markdown
MemberAuthor

other than braceless usings in product code (which I believed we had banned in style outside of tests

I don't know why we'd ban them.

@danmoseley

Copy link
Copy Markdown
Contributor

Yay, glad you added this switch. Do you plan to make an "up for grabs" issue to continue, in case folks are interested? eg., with a checkbox for each library that has hits (if you have that data gathered)?

Can you imagine us getting clean - I'm guessing there are test cases for finalizers, though.

How much slower is it to run tests when the switch is flipped? I assume it's expensive to gather stacks.

@stephentoub

Copy link
Copy Markdown
MemberAuthor

How much slower is it to run tests when the switch is flipped? I assume it's expensive to gather stacks.

A lot... starting with the fact that it's only built into a debug/checked runtime, and then layering on a stack walk for every safe handle created.

Can you imagine us getting clean - I'm guessing there are test cases for finalizers, though.

Without workarounds that'd be challenging, e.g. because of tests for finalizers as you say, tests that purposefully allow resources to not be disposed to avoid race conditions, etc.

if you have that data gathered

I don't.

This calls Dispose on SafeHandles (or things wrapping SafeHandles) that were otherwise being left for finalization:
1. Some of these are fixing finalization happening even on success paths (typically where the implementation isn't disposing of something that directly or indirectly wraps a SafeHandle).
2. Some of these are fixing finalization happening for invalid SafeHandles.
3. Some of these are fixing tests to finalize less. My goal with fixing the tests was to eliminate the noise in order to find instances of the other two cases.
These were found primarily via two means:
- Debug-instrumentation in SafeHandle to log when one is finalized. This instrumentation is built into debug/checked builds of SafeHandle and requires setting the DEBUG_SAFEHANDLE_FINALIZATION environment variable to "1".
- Auditing use of SafeHandle.IsInvalid
There's a lot more that can be cleaned up using the SafeHandle instrumentation, but I'm pausing here for now. The System.IO.Pipes, System.IO.FileSystem, and System.Security.Cryptography tests are clean on Windows.
@stephentoub
stephentoubforce-pushed the moresafehandlefinalization branch from fd8d46d to 767ee06CompareJuly 12, 2022 20:55
@danmoseley

Copy link
Copy Markdown
Contributor

Makes sense -- probably we can use this flag on rare occasions, eg., having written a new feature with non trivial use of safehandles.

@bartonjs

Copy link
Copy Markdown
Member

If you have to spin again, Steve, I'm indifferent about keeping or removing the version in

#if DEBUG
privatestaticreadonlybools_captureTrace=
Environment.GetEnvironmentVariable("DEBUG_SAFEX509HANDLE_FINALIZATION")!=null;
privatereadonlyStackTrace?_stacktrace=
s_captureTrace?newStackTrace(fNeedFileInfo:true):null;
~SafeX509Handle()
{
if(s_captureTrace)
{
Console.WriteLine($"0x{handle.ToInt64():x}{_stacktrace?.ToString()??"no stacktrace..."}");
}
}
#endif
that I left in from getting Linux PKCS7 tidy.

@stephentoub

Copy link
Copy Markdown
MemberAuthor

I'm indifferent about keeping or removing the version

Me, too. I will need to resolve a conflict, so I can remove it if you like.

@bartonjs

Copy link
Copy Markdown
Member

Eh, if you're indifferent and I'm indifferent, let's leave it, so I can have a "smaller than the whole world" experience :)

@stephentoub
stephentoub merged commit 199580b into dotnet:mainJul 13, 2022
@stephentoub
stephentoub deleted the moresafehandlefinalization branch July 13, 2022 11:09
@ghostghost locked as resolved and limited conversation to collaborators Aug 12, 2022
@AndyAyersMS

Copy link
Copy Markdown
Member

Possible regression: dotnet/perf-autofiling-issues#6973

@bartonjs

Copy link
Copy Markdown
Member

Since CryptoConfig.CreateFromName is just a lookup in ConcurrentDictionary, reflection to find a suitable ctor, and then reflection invocation of said ctor, I don't think this change was involved.

@stephentoub

stephentoub commented Aug 18, 2022

Copy link
Copy Markdown
MemberAuthor

@bartonjs, I did touch this:
https://github.com/dotnet/runtime/pull/71991/files#diff-b5e1d8d2d47fbe472dd7de0d3d5450bc58de31363bee3ae108cf295bf879b4e4R44
I guess that could have caused this (an extra non-inlineable function call, an extra generic dictionary lookup, etc.)?

That said, I'm not sure how much a few hundred nanoseconds on this particular method matters. We don't want folks using this method anyway, right?

@bartonjs

Copy link
Copy Markdown
Member

@stephentoub

Copy link
Copy Markdown
MemberAuthor

In that case, yeah, I'm not on the hook :)

Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@stephentoub@jkotas@danmoseley@bartonjs@AndyAyersMS@AaronRobinsonMSFT