Skip to content

Fix NativeAOT reflection ref-return storage lifetime - #135172

Merged
jkotas merged 3 commits into
mainfrom
copilot/fix-wrong-object-ref-return
Oct 4, 2026
Merged

jkotas merged 3 commits into
mainfrom
copilot/fix-wrong-object-ref-return

Conversation

Copilot AI commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

NativeAOT reflection invocation can return a byref into a helper’s temporary argument storage. Dereferencing it after the helper returns can yield a stale or incorrect object.

  • Lifetime: All five invocation helpers now return object?, transforming results before their argument storage expires or GC registrations are removed. Copy-back and exception wrapping remain unchanged.
  • Regression coverage: Extend the existing reflection smoke test with one-, four-, and five-argument ref-return cases across MethodInfo.Invoke and MethodInvoker span/fixed-argument paths, checking object identity and null results.

@azure-pipelines

azure-pipelines Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

Co-authored-by: jkotas <6668460+jkotas@users.noreply.github.com>
Copilot AI changed the title [WIP] Fix MethodInfo.Invoke returning wrong object for ref-returning methods Fix NativeAOT reflection ref-return storage lifetime Oct 3, 2026
Copilot AI requested a review from jkotas October 3, 2026 21:02
Comment thread src/tests/nativeaot/SmokeTests/Reflection/Reflection.cs Outdated
Co-authored-by: jkotas <6668460+jkotas@users.noreply.github.com>
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @steveisok, @dotnet/area-system-reflection
See info in area-owners.md if you want to be subscribed.

@jkotas
jkotas marked this pull request as ready for review October 3, 2026 22:40
@jkotas
jkotas requested review from EgorBo and a balanced review from Copilot October 3, 2026 22:40
@jkotas

jkotas commented Oct 3, 2026

Copy link
Copy Markdown
Member

/azp run runtime-nativeaot-outerloop

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The regression test does not reliably reproduce the compacting-GC timing required to expose the original lifetime bug.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Fixes NativeAOT reflection ref-return lifetime handling by transforming returned references before temporary argument storage expires.

Changes:

  • Moves return transformation into all argument helper paths.
  • Adds ref-return identity and null-result tests across invocation APIs.
File Description
DynamicInvokeInfo.cs Transforms results within temporary-storage lifetimes.
MethodInvokerTests.cs Adds ref-return regression scenarios.

@jkotas

jkotas commented Oct 4, 2026

Copy link
Copy Markdown
Member

/ba-g Know issues #135190 and #134912 - build analysis is unable to match them for some reason

@jkotas
jkotas merged commit 30f8136 into main Oct 4, 2026
156 of 160 checks passed
@jkotas
jkotas deleted the copilot/fix-wrong-object-ref-return branch October 4, 2026 19:56
@dotnet-milestone-bot dotnet-milestone-bot Bot added this to the 12.0-preview1 milestone Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

NativeAOT: MethodInfo.Invoke on a ref-returning method can return a wrong object (ref return escapes invoke helper's argument storage)

4 participants