You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
SslStream_TargetHostName_Succeeds(useEmptyName: True, useCallback: True) completes its TLS handshake and ping-pong, but observes zero remote-certificate-validation callback invocations instead of one.
This was observed in the Windows x86 Checked CoreCLR libraries leg of runtime build 20261001.53.
Reproduction Steps
Run the existing System.Net.Security.Tests.SslStreamNetworkStreamTest.SslStream_TargetHostName_Succeeds case with useEmptyName: True and useCallback: True in the configuration below. This report records a concrete CI occurrence; no deterministic local reproduction is claimed.
Expected behavior
The remote-certificate-validation callback is invoked once.
Actual behavior
The test fails with Expected: 1 and Actual: 0. The full failure excerpt is below.
Reported worker OS: Windows Server 2016, build 10.0.14393
Whether the failure is exclusive to this configuration is unknown.
Other information
Found while triaging #135038. That PR changes interpreter/WASM codegen, not SslStream, and its sort changes are gated by HOST_WASM; this failure is in the regular Windows x86 CoreCLR libraries leg.
Related incorrect-server-name failures are tracked by #135031. This KBE is scoped to the distinct zero-callback assertion; a shared root cause has not been established.
Description
SslStream_TargetHostName_Succeeds(useEmptyName: True, useCallback: True)completes its TLS handshake and ping-pong, but observes zero remote-certificate-validation callback invocations instead of one.This was observed in the Windows x86 Checked CoreCLR libraries leg of runtime build
20261001.53.Reproduction Steps
Run the existing
System.Net.Security.Tests.SslStreamNetworkStreamTest.SslStream_TargetHostName_Succeedscase withuseEmptyName: TrueanduseCallback: Truein the configuration below. This report records a concrete CI occurrence; no deterministic local reproduction is claimed.Expected behavior
The remote-certificate-validation callback is invoked once.
Actual behavior
The test fails with
Expected: 1andActual: 0. The full failure excerpt is below.Regression?
Unknown.
Known Workarounds
None confirmed.
Configuration
net11.0-windows-Debug-x86-coreclr_checked-Windows.10.Amd64.OpenOther information
Found while triaging #135038. That PR changes interpreter/WASM codegen, not SslStream, and its sort changes are gated by
HOST_WASM; this failure is in the regular Windows x86 CoreCLR libraries leg.Related incorrect-server-name failures are tracked by #135031. This KBE is scoped to the distinct zero-callback assertion; a shared root cause has not been established.
Build Information
Build: https://dev.azure.com/dnceng-public/public/_build/results?buildId=1619952
Build error leg or test failing: net11.0-windows-Debug-x86-coreclr_checked-Windows.10.Amd64.Open - System.Net.Security.Tests.SslStreamNetworkStreamTest.SslStream_TargetHostName_Succeeds
Pull request: #135038
KBE authoring guidance (ci-failure-scan)
Error Detailsis for readers. The excerpt below is from the failing test.Error Message.ErrorMessageelement is a case-sensitive literal substring from a line in the log, in order.BuildRetryis false;ExcludeConsoleLogis false.Error Details
Console log: https://helixr1107v0xdcypoyl9e7f.blob.core.windows.net/dotnet-runtime-refs-pull-135038-merge-73e86d532136444fb6/System.Net.Security.Tests/1/console.7804703e.log?helixlogtype=result
Test result: https://dev.azure.com/dnceng-public/public/_build/results?buildId=1619952&view=ms.vss-test-web.build-test-results-tab&runId=44873014&resultId=178113
Error Message
{ "ErrorMessage": [ "SslStream_TargetHostName_Succeeds(useEmptyName: True, useCallback: True) [FAIL]", "Assert.Equal() Failure: Values differ", "Expected: 1", "Actual: 0" ], "ErrorPattern": "", "BuildRetry": false, "ExcludeConsoleLog": false }Agentic workflow metadata (ci-failure-scan)
Workflow artifact: ci-failure-scan
Artifact kind: kbe-verification
Verified match count: 1 hits in failure.log
Note
This issue was prepared with GitHub Copilot assistance.
Known issue validation
Build: 🔎 https://dev.azure.com/dnceng-public/public/_build/results?buildId=1619952
Error message validated:
[SslStream_TargetHostName_Succeeds(useEmptyName: True, useCallback: True) [FAIL] Assert.Equal() Failure: Values differ Expected: 1 Actual: 0]Result validation: ✅ Known issue matched with the provided build.
Validation performed at: 10/1/2026 9:22:48 PM UTC
Report
Summary