Skip to content

feat(networking): introduce message-oriented networking transports - #10074

Merged
ReubenBond merged 52 commits into
dotnet:mainfrom
ReubenBond:split/message-oriented-networking
Oct 5, 2026
Merged

ReubenBond merged 52 commits into
dotnet:mainfrom
ReubenBond:split/message-oriented-networking

Conversation

@ReubenBond

@ReubenBond ReubenBond commented Apr 30, 2026 •

Copy link
Copy Markdown
Member

Problem

Orleans networking is organized around byte-stream connections. Message-oriented transports provide a common request contract for sending and receiving framed messages across transport implementations.

Solution

  • Introduces message-oriented transport abstractions with socket, stream, and TLS implementations, and wires them into client, gateway, and silo connections.
  • Integrates TLS into Core/Runtime hosting and updates the related packages, documentation, and samples. TLS retains the established Orleans1 ALPN identifier and certificate-mode defaults.
  • Adapts message serialization and pooled buffers to transport requests, with serializer/read/write pools owned by each MessageHandlerShared instance.
  • Updates TestingHost in-memory and Unix-domain socket transports and preserves connection establishment draining, runner cleanup, send-worker quiescence, and buffered tail-read behavior.
  • Preserves established message-center routing and queued gateway delivery. Revised local activation-target caching is developed separately in perf(runtime): cache local message targets with directory entries #10886.

Compatibility and migration

The transport replacement intentionally removes the legacy byte-stream connection configuration/middleware APIs, including ClientConnectionOptions and SiloConnectionOptions. Custom connection behavior migrates to message transport connector/listener decorators registered through dependency injection; the connection-middleware guide provides the migration path. Package-specific compatibility suppressions list only the removed legacy APIs for net8.0/net10.0, including their generated socket-exception codecs, while retaining validation for the rest of each package.

TLS APIs move from the retired Microsoft.Orleans.Connections.Security assembly into Core and Runtime. Explicit static calls to OrleansConnectionSecurityHostingExtensions migrate to ClientTlsHostingExtensions or SiloTlsHostingExtensions; extension calls retain the builder.UseTls(...) syntax. TLS options, features, and the public CertificateLoader.LoadFromStoreCert utility reside in Orleans.Connections.Transport.Security. Applications and libraries rebuild against the consolidated packages; the TLS guide lists the migration mappings and binary compatibility impact.

Microsoft Reviewers: Open in CodeFlow

@ReubenBond ReubenBond changed the title Message-oriented networking Introduce message-oriented networking transports Apr 30, 2026
@ReubenBond
ReubenBond requested a lite review from Copilot April 30, 2026 04:37

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Introduces a new message-oriented transport layer (TCP/socket/stream/TLS implementations) and rewires Orleans client/gateway/silo networking plus serialization/buffering to flow through these abstractions, including updates to TestingHost transports and related tests.

Changes:

  • Add MessageTransport / listener / connector abstractions and socket + TLS transport implementations.
  • Rewire runtime/client connection factories & listeners to use message transports (including updated tracing/logging and lifecycle).
  • Update serialization buffer handling (ArcBuffer/ArcBufferWriter) and add/adjust unit tests and benchmarks accordingly.
Show a summary per file
File Description
test/Orleans.Serialization.UnitTests/PooledBufferTests.cs Adjusts slice enumerator tests to focus on span enumeration.
test/Orleans.Core.Tests/Orleans.Core.Tests.csproj Adds System.IO.Pipelines package reference for new test usage.
test/Orleans.Core.Tests/Networking/MessageTransportLifecycleTests.cs Adds lifecycle/defaults tests for transport-related options and handler sharing.
test/Orleans.Connections.Security.Tests/TlsConnectionTests.cs Updates TLS tests to new transport security namespace.
test/Orleans.Connections.Security.Tests/Orleans.Connections.Security.Tests.csproj Removes reference to removed Orleans.Connections.Security project.
test/Benchmarks/Serialization/ComplexTypeBenchmarks.cs Updates benchmark to new MessageSerializer construction path.
src/Orleans.TestingHost/UnixSocketTransport/UnixSocketConnectionOptions.cs Removes old memory-pool factory remnants from Unix socket options.
src/Orleans.TestingHost/UnixSocketTransport/UnixSocketConnectionListenerFactory.cs Comments out legacy Kestrel-connection listener factory (now obsolete).
src/Orleans.TestingHost/UnixSocketTransport/UnixSocketConnectionListener.cs Removes legacy Kestrel IConnectionListener implementation.
src/Orleans.TestingHost/UnixSocketTransport/UnixSocketConnectionFactory.cs Removes legacy Kestrel IConnectionFactory implementation.
src/Orleans.TestingHost/UnixSocketTransport/UnixSocketConnectionExtensions.cs Removes legacy DI registration extensions for Kestrel-based Unix sockets.
src/Orleans.TestingHost/UnixSocketTransport/UnixDomainSocketMessageTransportListener.cs Adds message-transport-based Unix domain socket listener.
src/Orleans.TestingHost/UnixSocketTransport/UnixDomainSocketMessageTransportConnector.cs Adds message-transport-based Unix domain socket connector.
src/Orleans.TestingHost/UnixSocketTransport/SocketsLog.cs Adds (currently commented-out) Unix socket transport logging scaffold.
src/Orleans.TestingHost/TestClusterOptions.cs Changes default test cluster transport to TCP sockets.
src/Orleans.TestingHost/TestClusterHostFactory.cs Adds logging namespace import for updated DI usage.
src/Orleans.TestingHost/TestCluster.cs Rewires TestCluster transport selection to message transports (TCP/InMemory/UnixSocket).
src/Orleans.TestingHost/Orleans.TestingHost.csproj Adds logging + pipelines package references for new transports.
src/Orleans.TestingHost/InProcTestCluster.cs Updates in-proc cluster to use new in-memory message transport hooks.
src/Orleans.TestingHost/InMemoryTransport/InMemoryTransportHostingExtensions.cs Adds DI extensions to configure in-memory message transport.
src/Orleans.TestingHost/InMemoryTransport/InMemoryTransportConnection.cs Removes legacy Kestrel TransportConnection in-memory pipe implementation.
src/Orleans.Serialization/Serializers/CodecProvider.cs Minor edits plus introduction of commented-out unfinished code.
src/Orleans.Serialization/Serializer.cs Adds ArcBuffer deserialize overloads and formatting/style fixes.
src/Orleans.Serialization/Buffers/Writer.cs Adds ArcBufferWriter wrapper support for Writer.Create(...).
src/Orleans.Serialization/Buffers/Adaptors/BufferSliceReaderInput.cs Adds ArcBufferReaderInput for Reader<TInput> over ArcBuffer.
src/Orleans.Serialization.TestKit/FieldCodecTester.cs Switches round-trip helper to ArcBufferWriter/ArcBuffer flow.
src/Orleans.Runtime/Networking/SiloConnectionListener.cs Replaces Kestrel connection listener plumbing with message transport listeners.
src/Orleans.Runtime/Networking/SiloConnectionFactory.cs Replaces Kestrel connection factory plumbing with message transport connector.
src/Orleans.Runtime/Networking/SiloConnection.cs Updates connection to operate over MessageTransport and new run loop shape.
src/Orleans.Runtime/Networking/GatewayInboundConnection.cs Updates gateway inbound connection to MessageTransport.
src/Orleans.Runtime/Networking/GatewayConnectionListener.cs Updates gateway listener to message transport listener pipeline.
src/Orleans.Runtime/Messaging/Gateway.cs Adjusts imports to use transport abstractions.
src/Orleans.Runtime/Hosting/SiloTlsHostingExtensions.ISiloBuilder.cs Moves silo TLS hosting extensions onto message transport TLS middleware.
src/Orleans.Runtime/Hosting/DefaultSiloServices.cs Registers message transports (TCP + listeners) and shared handler pools.
src/Orleans.Runtime/Configuration/SiloConnectionOptions.cs Removes legacy Kestrel connection-builder options type.
src/Orleans.Core/Utils/SingleWaiterAutoResetEvent.cs Adds new single-waiter auto-reset event utility.
src/Orleans.Core/Orleans.Core.csproj Removes Kestrel connections abstractions dependency; adds InternalsVisibleTo.
src/Orleans.Core/Networking/Transport/WriteRequest.cs Adds write request abstraction over ArcBufferReader.
src/Orleans.Core/Networking/Transport/TlsMessageTransportConnectorMiddleware.cs Adds TLS middleware wrappers for connectors/listeners.
src/Orleans.Core/Networking/Transport/Sockets/TcpMessageTransportListener.cs Adds TCP message transport listener implementation.
src/Orleans.Core/Networking/Transport/Sockets/TcpMessageTransportConnector.cs Adds TCP message transport connector implementation.
src/Orleans.Core/Networking/Transport/Sockets/SocketsLog.cs Adds socket transport logging helpers.
src/Orleans.Core/Networking/Transport/Sockets/SocketSender.cs Adds multi-buffer socket send helper for transports.
src/Orleans.Core/Networking/Transport/Sockets/SocketReceiver.cs Adds socket receive helper for transports.
src/Orleans.Core/Networking/Transport/Sockets/SocketOperationResult.cs Adds result wrapper for socket operations.
src/Orleans.Core/Networking/Transport/Sockets/SocketExtensions.cs Adds fast-path enabling extension for sockets.
src/Orleans.Core/Networking/Transport/Sockets/SocketConnectionException.cs Adds transport-level socket connection exception type.
src/Orleans.Core/Networking/Transport/Sockets/SocketAwaitableEventArgs.cs Adds awaitable SocketAsyncEventArgs base for send/receive.
src/Orleans.Core/Networking/Transport/Sockets/CorrelationIdGenerator.cs Adds transport-side correlation ID generator.
src/Orleans.Core/Networking/Transport/Sockets/BufferExtensions.cs Adds Memory<T>/ReadOnlyMemory<T> array extraction helpers for sockets.
src/Orleans.Core/Networking/Transport/Sockets/AddressInUseException.cs Adds address-in-use exception for listener bind failures.
src/Orleans.Core/Networking/Transport/Security/TlsServerAuthenticationOptions.cs Adds TLS server auth options wrapper.
src/Orleans.Core/Networking/Transport/Security/TlsOptions.cs Adds new TLS options model for message transports.
src/Orleans.Core/Networking/Transport/Security/TlsMessageTransportListener.cs Adds TLS-wrapping listener implementation.
src/Orleans.Core/Networking/Transport/Security/TlsMessageTransportConnector.cs Adds TLS-wrapping connector implementation.
src/Orleans.Core/Networking/Transport/Security/TlsMessageTransport.cs Adds TLS stream transport implementation.
src/Orleans.Core/Networking/Transport/Security/TlsClientAuthenticationOptions.cs Adds TLS client auth options wrapper.
src/Orleans.Core/Networking/Transport/Security/ServerTlsMessageTransport.cs Adds server-authenticating TLS transport.
src/Orleans.Core/Networking/Transport/Security/RemoteCertificateMode.cs Adds remote certificate policy enum.
src/Orleans.Core/Networking/Transport/Security/ClientTlsMessageTransport.cs Adds client-authenticating TLS transport.
src/Orleans.Core/Networking/Transport/Security/CertificateLoader.cs Adds certificate store loading/validation helpers.
src/Orleans.Core/Networking/Transport/ReadRequest.cs Adds read request abstraction over ArcBufferReader.
src/Orleans.Core/Networking/Transport/NetworkTransportBase.cs Adds base class for message transport implementations.
src/Orleans.Core/Networking/Transport/MessageTransportListener.cs Adds message transport listener abstraction.
src/Orleans.Core/Networking/Transport/MessageTransport.cs Adds core MessageTransport/connector APIs + middleware interfaces.
src/Orleans.Core/Networking/Transport/IFeatureCollection.cs Adds typed feature collection interface for transports.
src/Orleans.Core/Networking/Transport/FeatureCollection.cs Adds default feature collection implementation.
src/Orleans.Core/Networking/Transport/ConnectionResetException.cs Adds connection reset exception type.
src/Orleans.Core/Networking/Transport/ConnectionEndPointFeature.cs Adds local/remote endpoint transport feature.
src/Orleans.Core/Networking/Transport/ConnectionAbortedException.cs Adds aborted/closed connection exception types.
src/Orleans.Core/Networking/SocketDirection.cs Removes legacy connection direction enum file.
src/Orleans.Core/Networking/Shared/TransportConnection.cs Removes legacy Kestrel ConnectionContext-based transport connection.
src/Orleans.Core/Networking/Shared/SocketsTrace.cs Removes legacy socket trace logger abstraction.
src/Orleans.Core/Networking/Shared/SocketSenderReceiverBase.cs Removes legacy socket send/receive base.
src/Orleans.Core/Networking/Shared/SocketSender.cs Removes legacy socket sender implementation.
src/Orleans.Core/Networking/Shared/SocketSchedulers.cs Removes legacy IOQueue-based schedulers.
src/Orleans.Core/Networking/Shared/SocketReceiver.cs Removes legacy socket receiver implementation.
src/Orleans.Core/Networking/Shared/SocketExtensions.cs Removes legacy socket extensions (fast-path/keepalive).
src/Orleans.Core/Networking/Shared/SocketConnectionOptions.cs Removes legacy socket connection options.
src/Orleans.Core/Networking/Shared/SocketConnectionListenerFactory.cs Removes legacy socket listener factory.
src/Orleans.Core/Networking/Shared/SocketConnectionListener.cs Removes legacy socket listener.
src/Orleans.Core/Networking/Shared/SocketConnectionFactory.cs Removes legacy socket connection factory.
src/Orleans.Core/Networking/Shared/SocketAwaitableEventArgs.cs Removes legacy awaitable socket args.
src/Orleans.Core/Networking/Shared/SharedMemoryPool.cs Removes legacy shared memory pool wrapper.
src/Orleans.Core/Networking/Shared/MemoryPoolSlab.cs Removes legacy slab memory pool internals.
src/Orleans.Core/Networking/Shared/MemoryPoolBlock.cs Removes legacy slab memory pool internals.
src/Orleans.Core/Networking/Shared/KestrelMemoryPool.cs Removes legacy Kestrel memory pool wrapper.
src/Orleans.Core/Networking/Shared/ISocketsTrace.cs Removes legacy sockets trace interface.
src/Orleans.Core/Networking/Shared/IOQueue.cs Removes legacy IOQueue scheduler.
src/Orleans.Core/Networking/Shared/DuplexPipe.cs Removes legacy duplex pipe helpers.
src/Orleans.Core/Networking/Shared/BufferExtensions.cs Removes legacy buffer-to-array helpers (moved to transport).
src/Orleans.Core/Networking/MessageWriteRequest.cs Adds message framing + serialization write request.
src/Orleans.Core/Networking/MessageReadRequest.cs Adds framed message read request with deferred body handling.
src/Orleans.Core/Networking/MessageHandlerShared.cs Adds per-shared-instance pools for serializers/read/write handlers.
src/Orleans.Core/Networking/IUnderlyingTransportFeature.cs Removes legacy underlying transport feature interface.
src/Orleans.Core/Networking/CorrelationIdGenerator.cs Moves correlation ID generator to new namespace/usage.
src/Orleans.Core/Networking/ConnectionTrace.cs Adds ConnectionTrace diagnostic/logger wrapper.
src/Orleans.Core/Networking/ConnectionShared.cs Updates shared connection services and lazy MessageHandlerShared access.
src/Orleans.Core/Networking/ConnectionOptions.cs Adds close connection timeout option.
src/Orleans.Core/Networking/ConnectionManager.cs Updates run method call to RunAsync().
src/Orleans.Core/Networking/ConnectionLogScope.cs Reduces log scope fields to connection ID only.
src/Orleans.Core/Networking/ConnectionFactory.cs Replaces Kestrel-based connection creation with message transport connector.
src/Orleans.Core/Networking/ConnectionDirection.cs Adds connection direction + transport protocol feature types.
src/Orleans.Core/Networking/ConnectionBuilderDelegates.cs Removes legacy connection-builder delegate infrastructure.
src/Orleans.Core/Networking/ClientOutboundConnectionFactory.cs Updates client outbound connection creation to message transports.
src/Orleans.Core/Networking/ClientOutboundConnection.cs Updates client outbound connection to MessageTransport.
src/Orleans.Core/Networking/ClientConnectionOptions.cs Removes legacy Kestrel connection options.
src/Orleans.Core/Messaging/MessageFactory.cs Updates TTL copying logic to new helper.
src/Orleans.Core/Messaging/Message.cs Adds deferred body deserialization via MessageReadRequest and safe formatting behavior.
src/Orleans.Core/Messaging/CachingSiloAddressCodec.cs Adjusts timestamp capture ordering in cache lookup path.
src/Orleans.Core/Hosting/ClientTlsHostingExtensions.IClientBuilder.cs Adds/renames public client TLS hosting extensions using transport middleware.
src/Orleans.Core/Core/DefaultClientServices.cs Registers message transports and shared handler pools for client default services.
src/Orleans.Connections.Security/Security/TlsServerAuthenticationOptions.cs Removes old TLS security types (moved to new transport security).
src/Orleans.Connections.Security/Security/TlsOptions.cs Removes old TLS options (moved).
src/Orleans.Connections.Security/Security/TlsDuplexPipe.cs Removes old TLS duplex pipe adapter.
src/Orleans.Connections.Security/Security/TlsConnectionFeature.cs Removes old TLS features plumbing.
src/Orleans.Connections.Security/Security/TlsClientAuthenticationOptions.cs Removes old TLS auth options wrapper.
src/Orleans.Connections.Security/Security/RemoteCertificateMode.cs Removes old enum (moved).
src/Orleans.Connections.Security/Security/OrleansApplicationProtocol.cs Removes old application protocol constant.
src/Orleans.Connections.Security/Security/MemoryPoolExtensions.cs Removes old memory pool sizing helpers.
src/Orleans.Connections.Security/Security/ITlsHandshakeFeature.cs Removes old TLS handshake feature interface.
src/Orleans.Connections.Security/Security/ITlsConnectionFeature.cs Removes old TLS connection feature interface.
src/Orleans.Connections.Security/Security/ITlsApplicationProtocolFeature.cs Removes old TLS ALPN feature interface.
src/Orleans.Connections.Security/Security/DuplexPipeStreamAdapter.cs Removes old duplex pipe stream adapter.
src/Orleans.Connections.Security/Security/CertificateLoader.cs Removes old certificate loader (moved).
src/Orleans.Connections.Security/Orleans.Connections.Security.csproj Removes the old TLS extension package project from the repo.
src/Orleans.Connections.Security/Hosting/HostingExtensions.cs Removes old Kestrel connection-builder TLS extensions.
Orleans.slnx Removes the old connections security project and its test project from the solution.

Copilot's findings

Comments suppressed due to low confidence (2)

src/Orleans.Core/Hosting/ClientTlsHostingExtensions.IClientBuilder.cs:13

  • This change introduces/renames public hosting extension APIs (ClientTlsHostingExtensions.UseTls). For this repo, public API changes in packable src/ projects require updating the generated API surface files under src/api. Please regenerate/update the relevant src/api entries so CI/public API checks stay consistent.
    src/Orleans.Runtime/Hosting/SiloTlsHostingExtensions.ISiloBuilder.cs:16
  • This introduces/renames public hosting extension APIs (SiloTlsHostingExtensions.UseTls). Public API changes in packable src/ projects are expected to be reflected in the generated API surface files under src/api. Please regenerate/update the relevant src/api files accordingly.
  • Files reviewed: 147/148 changed files
  • Comments generated: 7

Comment thread src/Orleans.Core/Networking/Transport/Sockets/TcpMessageTransportConnector.cs Outdated
Comment thread src/Orleans.Serialization/Serializers/CodecProvider.cs Outdated
Comment thread src/Orleans.TestingHost/UnixSocketTransport/SocketsLog.cs Outdated
Comment thread Orleans.slnx
@ReubenBond
ReubenBond force-pushed the split/message-oriented-networking branch from c39371b to e6288cc Compare April 30, 2026 15:33
@ReubenBond
ReubenBond force-pushed the split/message-oriented-networking branch from e6288cc to 224174d Compare May 8, 2026 22:14
@ReubenBond ReubenBond changed the title Introduce message-oriented networking transports feat(networking): introduce message-oriented networking transports May 29, 2026
Copilot AI review requested due to automatic review settings August 18, 2026 10:16
@ReubenBond
ReubenBond force-pushed the split/message-oriented-networking branch from 85c05e3 to 38dc995 Compare August 18, 2026 10:16

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review details

Suppressed comments (1)

src/Orleans.Core/Messaging/CachingSiloAddressCodec.cs:113

  • When serializing a null SiloAddress, WriteRaw writes a length byte of 1, but ReadRaw treats length==0 as null and otherwise expects at least 4 bytes (hash code). This will cause decoding to read past the payload for null values (or produce corrupt results).
        public void WriteRaw<TBufferWriter>(ref Writer<TBufferWriter> writer, SiloAddress value) where TBufferWriter : IBufferWriter<byte>
        {
            var currentTimestamp = Environment.TickCount64;
            if (value is null)
            {
                writer.WriteByte(1); // writer.WriteVarUInt32(0);
                return;
            }
  • Files reviewed: 153/155 changed files
  • Comments generated: 1
  • Review effort level: Lite

Comment thread src/Orleans.TestingHost/TestClusterOptions.cs Outdated
@ReubenBond

Copy link
Copy Markdown
Member Author

CI review: the rebased branch builds successfully on all solution targets, but the current .NET CI run has widespread provider and test-job failures while the build jobs pass. The failed jobs are timing out or crashing in test execution, which points to a runtime regression in the message-oriented transport branch rather than runner infrastructure. The current run is still waiting on macOS hang-dump jobs; the latest push restarts CI after correcting the review feedback.

Copilot AI review requested due to automatic review settings August 18, 2026 11:31

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review details

  • Files reviewed: 153/155 changed files
  • Comments generated: 2
  • Review effort level: Lite

Comment thread src/Orleans.Runtime/Hosting/DefaultSiloServices.cs
Comment thread src/Orleans.Core/Core/DefaultClientServices.cs
Copilot AI review requested due to automatic review settings August 18, 2026 11:57

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review details

Suppressed comments (2)

src/Orleans.Core/Messaging/CachingSiloAddressCodec.cs:42

  • ReadRaw() is declared as returning SiloAddress, but it returns null when the encoded length is 0. This breaks the null-sentinel contract used by MessageSerializer (SendingSilo/TargetSilo are nullable) and can surface as nulls flowing through a non-null return type.

This issue also appears on line 108 of the same file.

            var length = (int)reader.ReadVarUInt32();
            if (length == 0)
            {
                return null;
            }

src/Orleans.Core/Messaging/CachingSiloAddressCodec.cs:112

  • WriteRaw() attempts to handle null SiloAddress values, but it writes a single byte value of 1 (length=1) rather than encoding a varuint length of 0. ReadRaw() treats length==0 as the null sentinel, so the current code will deserialize null values as a 1-byte payload and then fail when it tries to read the 4-byte hash code.
            var currentTimestamp = Environment.TickCount64;
            if (value is null)
            {
                writer.WriteByte(1); // writer.WriteVarUInt32(0);
                return;
  • Files reviewed: 153/155 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

@ReubenBond

Copy link
Copy Markdown
Member Author

The retried Documentation workflow still has PR-specific validation failures. Microsoft.Orleans.Connections.Security is documented and referenced by the TLS sample but is not produced by Orleans.slnx; the docs also reference three lifecycle stages absent from the public API: ValidateInitialConnectivity, GrainDirectoryShutdown, and GrainDeactivation. Run: https://github.com/dotnet/orleans/actions/runs/32134317547

Copilot AI review requested due to automatic review settings August 20, 2026 14:13
@ReubenBond
ReubenBond force-pushed the split/message-oriented-networking branch from 324b9ce to 8f7f6f7 Compare August 20, 2026 14:13

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review details

Suppressed comments (2)

src/Orleans.Core/Hosting/ClientTlsHostingExtensions.IClientBuilder.cs:106

  • TlsOptionsValidator is declared as internal, but it is referenced from Orleans.Runtime (see SiloTlsHostingExtensions). Since this type needs to be constructed across assemblies, it must be public (or otherwise moved into Orleans.Runtime).
    src/Orleans.Serialization/Serializers/CodecProvider.cs:30
  • There is a commented-out field left in the implementation. This dead code adds noise and should be removed to keep the provider implementation maintainable.
  • Files reviewed: 153/155 changed files
  • Comments generated: 2
  • Review effort level: Lite

Comment thread test/Orleans.Connections.Security.Tests/TlsConnectionTests.cs
Comment thread src/Orleans.Core/Networking/MessageWriteRequest.cs Outdated
Copilot AI review requested due to automatic review settings August 20, 2026 15:17

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review details

Suppressed comments (3)

Previously missed (3) — in code that hasn't changed since the last review.

src/Orleans.Core/Networking/Transport/MessageTransport.cs:119

  • MessageTransportConnectorFactory/MessageTransportListenerFactory are typed to concrete TLS middleware (IEnumerable<TlsMessageTransportMiddleware>) even though the abstractions are IMessageTransportMiddleware. This prevents non-TLS middleware from being applied and will also break DI resolution if these factories are ever constructed from the services which register middleware by the interface type.
    src/Orleans.Core/Networking/ConnectionFrameHelper.cs:215
  • WriteFrameWithPrefixingWriter now buffers the entire payload into an ArrayBufferWriter and then copies it into the PipeWriter. This adds an extra allocation/copy on a hot path (frame writes), and it also forces the entire payload to be materialized in a contiguous array before writing.

Consider switching back to a streaming/pooled approach (e.g., a pooled buffer writer) to avoid the extra copy, especially for larger frames.
src/Orleans.Core/Networking/ConnectionDirection.cs:16

  • This change introduces new public API surface in Orleans.Core (e.g., TransportProtocol and ITransportProtocolFeature). Since Orleans.Core is API-tracked (see src/api/Orleans.Core/Orleans.Core.cs), the PR should also update the generated API surface file (or make these types internal if they are not intended as public API).
  • Files reviewed: 155/157 changed files
  • Comments generated: 1
  • Review effort level: Lite

Comment thread docs/site/src/content/docs/host/transport-layer-security.md
Copilot AI review requested due to automatic review settings August 20, 2026 16:24
@ReubenBond
ReubenBond force-pushed the split/message-oriented-networking branch from 012e74b to cc067d1 Compare August 20, 2026 16:24

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review this pull request because it exceeds the maximum number of lines (20,000). Try reducing the number of changed lines and requesting a review from Copilot again.

@ReubenBond

Copy link
Copy Markdown
Member Author

CI root cause: the transport refactor retained client removal but dropped the current-main \GatewayEvents.ClientDropped\ emission and silo address used by dropped-client stream tests. NATS, SQS, PostgreSQL, Kinesis, and related jobs therefore timed out waiting for a diagnostic event that never arrived. The branch now restores that event path; the provider-independent memory-stream dropped-client tests pass. The stale \Microsoft.Orleans.Connections.Security\ references were also removed from TLS snippet projects, and docs validation plus \Orleans.slnx\ build pass.

Copilot AI review requested due to automatic review settings August 20, 2026 17:01

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review this pull request because it exceeds the maximum number of lines (20,000). Try reducing the number of changed lines and requesting a review from Copilot again.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Critical transport issues and a moderate Unix listener shutdown issue remain unresolved.

Review effort: Lite
Findings: 2 High severity

Open (2)

Comment thread src/Orleans.Core/Networking/Transport/Sockets/SocketExtensions.cs Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Critical message-buffer disposal leaks and additional lifecycle and endpoint issues remain unresolved.

Review effort: Lite
Findings: 2 High severity

Open (2)
Resolved since last review (2)
Previously missed (1)

In code that hasn't changed since last review

Medium severity Composed connector is not disposed at host shutdown

src/​Orleans.Core/​Networking/​ConnectionFactory.cs:22

The middleware-composed connector is stored only in ConnectionFactory; ConnectionFactory is not disposable, so decorators created by mw.Apply never receive DisposeAsync at host shutdown. DI can dispose the original registered connector, but it cannot dispose wrapper instances which may own resources. Make the factory own/dispose the composed connector or register the composed instance through DI.

Comment thread src/Orleans.Core/Runtime/OutsideRuntimeClient.cs
Comment thread src/Orleans.Runtime/Core/InsideRuntimeClient.cs
@ReubenBond

Copy link
Copy Markdown
Member Author

Addressed the review-level connector-disposal finding in df0f50c. ConnectionFactory now owns and disposes the middleware-created decorator chain after admitted connection attempts have drained. A borrowed connector at the DI boundary leaves the registered connector owned by the service provider, preserving exactly-once disposal of both decorators and the registered connector. Repeated disposal shares one completion task. The middleware guide documents this ownership contract, and regressions cover synchronous/asynchronous provider disposal, nested decorators, and an in-flight connection attempt.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The changes require final human review because they are too complex or risky for automated approval.

Review effort: Lite
Findings: None

Resolved since last review (2)

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Unresolved critical API-suppression, public-API, and concurrency findings block approval.

Review effort: Lite
Findings: 3 High severity

Open (3)
Previously missed (2)

In code that hasn't changed since last review

Low severity Document newly public TLS delegate and options API

src/​Orleans.Core/​Networking/​Transport/​Security/​TlsClientAuthenticationOptions.cs:12

This newly public delegate and options type omit XML documentation, unlike the surrounding TLS public API and the previous versions of these types. Add docs for the delegate, type, and its public members before shipping the moved API.

Low severity Document newly public TLS delegate and options API

src/​Orleans.Core/​Networking/​Transport/​Security/​TlsServerAuthenticationOptions.cs:12

This newly public delegate and options type omit XML documentation, unlike the surrounding TLS public API and the previous versions of these types. Add docs for the delegate, type, and its public members before shipping the moved API.

Comment thread src/Orleans.Core/CompatibilitySuppressions.xml
Comment thread src/Orleans.Runtime/CompatibilitySuppressions.xml
@ReubenBond

Copy link
Copy Markdown
Member Author

Addressed the review-summary TLS documentation findings in a69cd83: both certificate-selection delegates, both authentication-options types, and all their public properties now have XML documentation. TestingHost's generated API includes the listener-options type.

Also fixed the three cross-platform BVT failures introduced by the shutdown regression fixture. The test manually publishes its capturing sender without starting a connection runner, so it now explicitly closes and removes that owned routing registration during cleanup. Previously the registration remained in ConnectionManager and its shutdown drain timed out. The complete, unmodified ConnectionManagerTests class passes all 14 cases on net8.0 and net10.0 against the real current runtime and TestingHost projects, including the three shutdown cases and teardown.

Normal Release packs for Core, Runtime, and TestingHost pass. The two requested hosting-extension suppressions are unnecessary: the removed type is in the separate Connections.Security baseline assembly, not either package's baseline. The inline replies document that metadata evidence. Fresh CI will cover the published commit.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Resolve the two moderate transport shutdown and TLS option-registration issues before approval.

Review effort: Lite
Findings: None

Resolved since last review (3)
Previously missed (1)

In code that hasn't changed since last review

Low severity Fix missing space in non-null value error message

src/​Orleans.Core/​Networking/​Transport/​Security/​ClientTlsMessageTransport.cs:42

This concatenation omits the space between non-null and value, so the exception reads non-nullvalue. Include the missing space to keep the configuration failure message clear and consistent with the server-side equivalent.

@ReubenBond

Copy link
Copy Markdown
Member Author

Investigated the latest overview's reference to moderate shutdown and TLS option-registration issues. The review has no new inline findings or detailed description for those two issues; the historical TLS registration comments are the available concrete explanation.

Published e6c8a50 with a reproduced Unix listener shutdown-contract fix. Pending accepts already terminate on shutdown, but a subsequent AcceptAsync threw "Transport is not bound" after either unbind or disposal instead of returning null as MessageTransportListener requires. The stopped-state check now preserves the terminal null result while retaining the pre-bind error. AcceptAfterShutdownReturnsNull verifies pending and subsequent accepts, socket-file cleanup, and the pre-bind boundary for both shutdown paths. Both cases failed before the fix and pass now.

The historical TLS claim incorrectly treats services.Configure(configure) as ConfigureAll. Configure targets Options.DefaultName; the explicit silo/gateway registrations each initialize their own named instance once. Removing those registrations would leave inbound listeners unconfigured. SiloTlsConfiguration_AppliesOncePerConnectionRole now exercises the real UseTls registration and options monitor, checks exactly three configured instances, cached repeated resolutions, an unrelated option name remaining unconfigured, and exactly one non-idempotent authentication callback per role. No TLS registration change is needed.

All four Unix listener cases and all seven TLS option cases pass on net8.0 and net10.0 against the current runtime/TestingHost projects. The commit also includes the requested "non-null value" spacing correction. Fresh CI will validate the published head.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

One or more issues must be addressed before approval.

Review effort: Lite
Findings: None

Previously missed (2)

In code that hasn't changed since last review

Low severity Document the public aborted connection exception

src/​Orleans.Core/​Networking/​Transport/​ConnectionAbortedException.cs:8

This new public exception has no XML documentation, unlike the neighboring public transport exception and the other new transport APIs. Add a summary describing when callers should observe an aborted connection so the generated package documentation is complete.

Low severity Document the public reset connection exception

src/​Orleans.Core/​Networking/​Transport/​ConnectionResetException.cs:9

This new public exception is missing XML documentation. Add a summary describing a reset connection so the public transport API follows the documentation convention used by ConnectionClosedException and the other new transport types.

@ReubenBond

Copy link
Copy Markdown
Member Author

Addressed both review-summary documentation findings in 5408054. ConnectionAbortedException now describes termination before initialization or a pending operation completes; ConnectionResetException describes resets from the remote peer or underlying network. Both types and all their constructors have XML documentation. This is a documentation-only change with no public signature or runtime behavior changes.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The transport and TLS replacement spans broad networking, lifecycle, and public API changes requiring human review.

Review effort: Lite
Findings: None

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

One or more issues must be addressed before approval.

Review effort: Lite
Findings: 1 High severity

Open (1)

Comment thread src/Orleans.Runtime/Core/InsideRuntimeClient.cs

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

One or more issues must be addressed before approval.

Review effort: Lite
Findings: 4 High severity

Open (4)

Comment thread src/Orleans.Core/Networking/Transport/Sockets/SocketReceiver.cs
Comment thread src/Orleans.Core/Networking/Transport/Sockets/SocketSender.cs

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Critical transport publication and mTLS enforcement issues, plus compatibility and response-disposal fixes, remain unresolved.

Review effort: Lite
Findings: 2 High severity

Open (2)
Resolved since last review (4)

Comment thread src/Orleans.Core/Networking/ConnectionShared.cs Outdated
Comment thread src/Orleans.Core/Networking/Transport/Security/ClientTlsMessageTransport.cs Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The broad networking and TLS replacement spans transport, lifecycle, API, and compatibility changes requiring human review.

Review effort: Lite
Findings: None

Resolved since last review (2)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants