Skip to content

Fix ParseGenericTypeArgumentNames for nested generic types#1414

Merged
max-charlamb merged 1 commit intomicrosoft:mainfrom
max-charlamb:fix/nested-generic-arg-parsing
Apr 3, 2026
Merged

Fix ParseGenericTypeArgumentNames for nested generic types#1414
max-charlamb merged 1 commit intomicrosoft:mainfrom
max-charlamb:fix/nested-generic-arg-parsing

Conversation

@max-charlamb
Copy link
Copy Markdown
Contributor

GetConcreteGenericTypeArguments was resolving VoidTaskResult (from AsyncTaskMethodBuilder) instead of the state machine type, leaving the
StateMachine field with a null or wrong type after metadata fallback. This caused SOS DumpAsync to crash with an assertion failure.

Fix

Find the last + at depth 0 (outside angle brackets) to skip past outer type names, then search for < from there.

Verification

Input Before (bug) After (fix)
AsyncTaskMethodBuilder<VoidTaskResult>+AsyncStateMachineBox<MyClass+<DoAsync>d__3> VoidTaskResult MyClass+<DoAsync>d__3
Dictionary<String, Int32> String, Int32 String, Int32
Dictionary<String, Int32>+Entry String, Int32 (none) ✅

Fixes the regression reported in dotnet/diagnostics#5789.

ParseGenericTypeArgumentNames used IndexOf('<') to find the start of
generic arguments, which returns the first '<' in the full type name.
For nested generic types like Outer<A>+Inner<B>, this incorrectly
extracts the outer type's arguments (A) instead of the inner type's (B).

This breaks __Canon type resolution for AsyncStateMachineBox<TStateMachine>
because GetConcreteGenericTypeArguments resolves AsyncTaskMethodBuilder's
TResult instead of the state machine type, leaving the StateMachine field
with a null or wrong type after metadata fallback.

Fix: find the last '+' at depth 0 (outside angle brackets) to skip past
outer type names, then search for '<' from there.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@max-charlamb max-charlamb changed the title Fix ParseGenericTypeArgumeantNames for nested generic types Fix ParseGenericTypeArgumentNames for nested generic types Apr 3, 2026
@max-charlamb max-charlamb requested a review from leculver April 3, 2026 19:41
@max-charlamb max-charlamb marked this pull request as ready for review April 3, 2026 19:41
@max-charlamb max-charlamb requested a review from hoyosjs April 3, 2026 19:41
@max-charlamb max-charlamb merged commit ba94db0 into microsoft:main Apr 3, 2026
8 checks passed
@max-charlamb max-charlamb deleted the fix/nested-generic-arg-parsing branch April 3, 2026 22:02
max-charlamb added a commit to dotnet/runtime that referenced this pull request Apr 14, 2026
## Summary

Fix two reference counting bugs in the legacy DAC's `DefaultCOMImpl`
template class, remove the corresponding compat workaround in the cDAC,
bump clrmd, and implement `CLRDATA_REQUEST_REVISION` in the cDAC.

> [!NOTE]
> This PR description was generated with the help of Copilot.

## Sibling PRs:
- dotnet/diagnostics#5789 (merged) — Bump clrmd
in diagnostics, adapt to 4.x API changes
- microsoft/clrmd#1414 (merged) — Fix
`ParseGenericTypeArgumentNames` for nested generic types
- microsoft/clrmd#1416 (merged) — Fall back to
MethodTable when generic type resolution produces a placeholder

## Bug 1: `Release()` uses post-decrement (dacimpl.h)

`DefaultCOMImpl::Release()` used post-decrement (`mRef--`) instead of
pre-decrement (`--mRef`):

```cpp
// Before (bug):
ULONG res = mRef--;  // captures value BEFORE decrement
if (res == 0)        // never true when mRef was 1
    delete this;     // object is never freed
```

Per the [IUnknown::Release
contract](https://learn.microsoft.com/en-us/windows/win32/api/unknwn/nf-unknwn-iunknown-release),
`Release` must return the **new** reference count and free the object
when it reaches 0. The post-decrement meant objects were never freed — a
memory leak affecting all `DefaultCOMImpl`-derived classes
(`DacHandleWalker`, `DacStackReferenceWalker`, `DacMemoryEnumerator`
subclasses, `DacMethodTableSlotEnumerator`,
`DacStackReferenceErrorEnum`).

## Bug 2: `DacMethodTableSlotEnumerator` missing `QueryInterface`
(request.cpp)

`GetMethodTableSlotEnumerator` returned the object via raw pointer
assignment without calling `QueryInterface`/`AddRef`, leaving `mRef` at
0:

```cpp
// Before (bug):
*enumerator = methodTableSlotEnumerator;  // mRef stays 0
```

Every other `DefaultCOMImpl` subclass correctly uses `QueryInterface`
before returning, which calls `AddRef` to give the caller an owning
reference. Fixed to match that pattern.

## cDAC compat removal (SOSDacImpl.cs)

The cDAC's `GetHandleEnum` and `GetHandleEnumForTypes` previously called
`ComInterfaceMarshaller.ConvertToUnmanaged` to intentionally leak a ref
count, matching the legacy DAC's broken behavior. Now that the legacy
bug is fixed, this compat workaround is removed.

## Version bump and cDAC revision

- Bumps `CLRDATA_REQUEST_REVISION` from 9 to 10 in the legacy DAC so
that ClrMD can detect the fixed ref counting behavior via
`IXCLRDataProcess::Request`.
- Implements `CLRDATA_REQUEST_REVISION` directly in the cDAC's
`SOSDacImpl.IXCLRDataProcess.Request` (with DEBUG validation against the
legacy DAC) so consumers get the correct revision without requiring the
legacy DAC fallback.

## ClrMD bump

Updates `Microsoft.Diagnostics.Runtime` from `3.1.512801` to
`4.0.0-beta.26210.1`. The new version includes:
- CLRDATA_REQUEST_REVISION 10 detection to avoid double-freeing
(microsoft/clrmd#1398)
- `ParseGenericTypeArgumentNames` fix for nested generic types
(microsoft/clrmd#1414)
- `GetTypeByName` cached generic instantiation fix
(microsoft/clrmd#1412)
- Canon fallback to MethodTable for compiler-generated types
(microsoft/clrmd#1416)

## cdacstress.cpp double Release removal

Removes the compensating double `pEnum->Release()` in `CollectStackRefs`
that was working around the broken post-decrement in
`DefaultCOMImpl::Release()`.

---------

Co-authored-by: Max Charlamb <maxcharlamb@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants