Skip to content

[release/11.0] Fix concurrent Reflection.Emit TypeLoadException (#129230) - #132672

Open
github-actions[bot] wants to merge 1 commit into
release/11.0from
backport/pr-130696-to-release/11.0
Open

[release/11.0] Fix concurrent Reflection.Emit TypeLoadException (#129230)#132672
github-actions[bot] wants to merge 1 commit into
release/11.0from
backport/pr-130696-to-release/11.0

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Backport of #130696 to release/11.0

/cc @steveisok

Customer Impact

  • Customer reported
  • Found internally

[Select one or both of the boxes. Describe how this issue impacts customers, citing the expected and actual behaviors and scope of the issue. If customer-reported, provide the issue number.]

Regression

  • Yes
  • No

[If yes, specify when the regression was introduced. Provide the PR or commit if known.]

Testing

[How was the fix verified? How was the issue missed previously? What tests were added?]

Risk

[High/Medium/Low. Justify the indication by mentioning how risks were measured and addressed.]

IMPORTANT: If this backport is for a servicing release, please verify that:

  • For .NET 8 and .NET 9: The PR target branch is release/X.0-staging, not release/X.0.
  • For .NET 10+: The PR target branch is release/X.0 (no -staging suffix).

Package authoring no longer needed in .NET 9

IMPORTANT: Starting with .NET 9, you no longer need to edit a NuGet package's csproj to enable building and bump the version.
Keep in mind that we still need package authoring in .NET 8 and older versions.

PR #125536 added an AddPropertyToLookUpTable call inside
CMiniMdRW::AddPropertyToPropertyMap (and AddEventToLookUpTable inside
AddEventToEventMap) so that the ENC/hot-reload path, which reaches those
functions via metamodelenc.cpp rather than RegMeta::DefineProperty,
would also maintain the property/event parent lookup table (fixing
#125534).

However the emit path already appended to the lookup table:
DefineProperty and _DefineEvent call
AddPropertyToPropertyMap/AddEventToEventMap and then also call
Add*ToLookUpTable themselves, gated on HasIndirectTable. The S_FALSE
branch in AddPropertyToPropertyMap fires under exactly the same
condition (an indirect PropertyPtr/EventPtr table exists), so after
#125536 the emit path appended the same <member, typedef> entry twice.

Add*ToLookUpTable only appends once the lazily-built lookup map is
non-NULL (the map is built on demand by a reader in
FindParentOf*Helper). When a concurrent reader has built the map, the
duplicate append desyncs the map's Count from the member RID, so a
subsequently emitted member is recorded against the wrong parent
typedef, surfacing as a TypeLoadException. This is why the regression
only reproduces under concurrent emit + reflection.

Remove the now-redundant emit-side appends so the lookup table is
maintained in exactly one place
(AddPropertyToPropertyMap/AddEventToEventMap), which serves both the
emit and ENC/hot-reload callers and preserves the #125534 fix.

Fixes #129230

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @agocke
See info in area-owners.md if you want to be subscribed.

@steveisok steveisok added the Servicing-approved Approved for servicing release label Aug 23, 2026
@steveisok
steveisok requested a review from a team August 23, 2026 17:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-VM-coreclr Servicing-approved Approved for servicing release

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant