Conversation
Keep TLS trivial and let each dispatch scope own the pending-list snapshot so unused attaching threads allocate nothing and completed dispatches retain no thread-owned storage. Preserve nested listener and release semantics. Add listener coverage and an SDK-only unload regression that checks zero outstanding blocks and bytes with seven worker threads still alive. Files changed: - lib/callbacks/DebugSource.cpp - lib/callbacks/DebugSourceInternal.hpp - tests/CMakeLists.txt - tests/unittests/DebugEventSourceTests.cpp - tests/dll-unload/CMakeLists.txt - tests/dll-unload/debug-listener-unload-module.cpp - tests/dll-unload/debug-listener-unload-test.cpp - tests/dll-unload/README.md Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: e3876793-eab3-449a-b32b-5a983d24a6c3
Replace the WinRT activation path that can fail or hang after final apartment teardown. Resolve modern IP Helper APIs dynamically and balance native NLM subscriptions in an SDK-owned STA on older supported Windows. Drain dispatched callbacks through completion, retain the embedding DLL only until callback return, and preserve drain state for reentrant/concurrent stop and restart. Keep cost refreshes on the backend's owning thread. Files changed: - lib/pal/desktop/NetworkDetector.cpp - lib/pal/desktop/NetworkDetector.hpp - tests/common/network-detector-test-access.hpp - tests/unittests/NetworkDetectorTests.cpp - tests/dll-unload/CMakeLists.txt - tests/dll-unload/debug-listener-unload-module.cpp - tests/dll-unload/debug-listener-unload-test.cpp - tests/dll-unload/network-detector-reload-test.cpp - tests/dll-unload/README.md - docs/building-custom-SKU.md - .github/workflows/memory-leak-analysis.yml Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: e3876793-eab3-449a-b32b-5a983d24a6c3
Before the WinRT-only detector change, NLM connectivity monitoring could run when its optional cost interface was unavailable. Activate INetworkListManager first and keep Unknown cost after logged query failures, including on Server. Preserve the original three NLM event families instead of requiring the newly added cost-specific events. Let the private non-agile sink's STA complete COM rundown after an explicit disconnect failure instead of terminating the host. Cover no-cost operation, cost-query errors, partial subscriptions and apartment rundown in unit tests and the zero-allocation DLL unload/reload harness. Files changed: - lib/pal/desktop/NetworkDetector.cpp - lib/pal/desktop/NetworkDetector.hpp - tests/common/network-detector-test-access.hpp - tests/unittests/NetworkDetectorTests.cpp - tests/dll-unload/CMakeLists.txt - tests/dll-unload/debug-listener-unload-module.cpp - tests/dll-unload/debug-listener-unload-test.cpp - tests/dll-unload/network-detector-reload-test.cpp - tests/dll-unload/README.md - docs/building-custom-SKU.md Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: e3876793-eab3-449a-b32b-5a983d24a6c3
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fix Debug Windows leaks when a DLL embedding the SDK is unloaded with attaching
threads still alive, and make Windows network detection survive repeated DLL
loads without requiring the host to keep a COM MTA alive.
Pending listeners
PendingListenersScope-owned storage.registrations, removal, exception unwinding, and reentrant release callbacks.
Network detector
The SDK-only reproducer failed on the second load with the former WinRT
activation path. Keeping a host MTA alive isolated the dependency but is not
part of this fix.
on Windows 10 version 2004/build 19041 and later, without WinRT or NLM.
INetworkListManagerand the original three event families on a private SDK-owned STA.
Query
INetworkCostManageronly as an optional capability. Missing costsupport or logged cost-query failures retain
Unknowncost while monitoringcontinues, matching the pre-Fix Windows network detection leak, add periodic leak reports, and standardize dependencies #1536 behavior. Server does not require the
unsupported cost interface. No cost-specific event subscriptions are required.
Unsubscribe, disconnect, release all interfaces, and balance COM initialization
on the owning thread before joining it.
interfaces across apartments; recognize listener generations across restart.
stops after a reentrant stop. Restart also drains the previous dispatch.
Balance each callback's temporary DLL reference with
FreeLibraryWhenCallbackReturns; do not permanently retain the DLL.log the failure, release interfaces, and call
CoUninitializebefore joining.This closes its RPC connections without terminating the host. Native
notification cancellation failure remains fatal because it has no apartment
rundown safety mechanism.
the forced legacy backend; a separate modern-backend run preserves the
no-
netprofm.dllgate alongside functional/sample production paths.The modern backend reports aggregate connectivity hints rather than only the
WinRT Internet connection profile. These hints do not expose WinRT's separate
background-data restriction flag. Roaming and approaching/exceeded data limits
remain restrictive. The legacy fallback legitimately loads
netprofm.dll.Validation
The Windows hosts do not link the SDK. They embed the static SDK in a Debug DLL,
require the shared Debug CRT/default Debug STL iterator checking, verify actual
DLL unloading, and count outstanding normal/client CRT allocations.
tests pass, covering default, legacy and no-cost capabilities, failed subscription/retry, repeated
start/read/stop, queued refresh races, concurrent/reentrant stop, callback drain,
restart, and cost reads across listener generations.
read/stop/unload cycles, with 0 blocks / 0 bytes per cycle, while the host
COM apartment remains uninitialized. All seven worker threads are confirmed
alive at the six live-thread unload checkpoints.
passed ten DLL stress rounds and three focused-unit rounds.
DebugEventSourceTests.*pass.suites. The feature-disabled module reports explicit skip code 77 for network
cases; its idle/dispatch cases still pass with zero blocks/bytes.
misspellv0.3.4 andgit diff --checkpass.jobs pass. The x64 Debug job runs 653 unit tests, including the forced
legacy/no-cost and failure-path tests, without skipping those paths.
The isolated modern network backend, Windows functional tests and basic sample
each report zero actual and possible leaks; the modern production paths
also pass the no-
netprofm.dllcheck.total actual leaks (824 bytes), and 39 unique / 44 total possible leaks
(225,601 bytes). The unchanged baseline comparison emits warnings, not a
failing exit status. Its successful workflow status must not be interpreted
as a clean leak baseline.
NETPROFM.dll,CoInitializeExand an OS WNF notification thread. Other actual-leak stacksinvolve offline-storage and HTTP tests. These full-suite results do not
establish whether the legacy backend grows native allocations per lifecycle;
no zero-native-heap claim is made for the legacy path.
Coverage: The base NLM APIs are documented for Vista/Server 2008 onward;
optional cost APIs are Windows 8-client APIs with no supported Server versions.
The detector no longer requires WinRT or Windows 8 cost support on the
Windows 7 SP1/Server 2008 R2 range referenced by the old source. This does not
change the whole SDK's support policy or compiler/runtime requirements.
Limits: Forced legacy execution on the current Windows host is not actual
Server 2016/2019 validation. These are SDK-only embedding tests, not an ORT
Windows consumer build: the inspected ORT checkout uses ETW on Windows and
excludes 1DS from its standard Windows build. The Debug CRT checks are not a
claim of zero allocations in every OS/native heap. The CI-pinned Dr. Memory
tool could not launch even an SDK-independent target locally (0xc06d007f);
native-heap results above come from the supported Windows CI host.
The workflow's pre-existing timing-sensitive exclusions are unchanged, and
no new exclusions or relaxed leak baselines have been added.
Based on Microsoft
mainat3886eda702c3dd986bf47160a6e91b91f19114ae.