Skip to content

Use App Data Microsoft.DotNet.Sdk.Root for resolving SDK root - #7562

Merged
Nigusu-Allehu merged 1 commit into
devfrom
dev-nyenework-trustedroots
Jul 14, 2026
Merged

Nigusu-Allehu merged 1 commit into
devfrom
dev-nyenework-trustedroots

Conversation

@Nigusu-Allehu

@Nigusu-Allehu Nigusu-Allehu commented Jul 13, 2026 •

Copy link
Copy Markdown
Member

Bug

Fixes: NuGet/Home#14980

Description

NuGet.Packaging locates the SDK-provided trusted-root bundles ( trustedroots/codesignctl.pem  and  trustedroots/timestampctl.pem ) via  AppContext.BaseDirectory , assuming it resolves to the versioned SDK directory (e.g.  dotnet/sdk/10.0.301 ).

Under the Native AOT  dotnet  CLI, that assumption breaks:  dotnet-aot.dll  is loaded directly by the muxer so the pem bundles can't be found and signature/timestamp verification could fail.

This adopts the resolution pattern from dotnet/sdk#55110: the AOT entry point publishes the resolved versioned SDK directory as the  Microsoft.DotNet.Sdk.Root  AppContext value.  FallbackCertificateBundleX509ChainFactory  now reads that value first, falling back to  AppContext.BaseDirectory  when it is unset

PR Checklist

  • Meaningful title, helpful description and a linked NuGet/Home issue
  • Added tests
  • Link to an issue or pull request to update docs if this PR changes settings, environment variables, new feature, etc.

@Nigusu-Allehu
Nigusu-Allehu requested a review from a team as a code owner July 13, 2026 19:36
@Nigusu-Allehu Nigusu-Allehu self-assigned this Jul 13, 2026
@Nigusu-Allehu
Nigusu-Allehu merged commit 0e7ab72 into dev Jul 14, 2026
20 of 21 checks passed
@Nigusu-Allehu
Nigusu-Allehu deleted the dev-nyenework-trustedroots branch July 14, 2026 05:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[NuGet AOT] Revise how NuGet Packaging finds pem files

3 participants