You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Orleans networking is organized around byte-stream connections. Message-oriented transports provide a common request contract for sending and receiving framed messages across transport implementations.
Solution
Introduces message-oriented transport abstractions with socket, stream, and TLS implementations, and wires them into client, gateway, and silo connections.
Integrates TLS into Core/Runtime hosting and updates the related packages, documentation, and samples. TLS retains the established Orleans1 ALPN identifier and certificate-mode defaults.
Adapts message serialization and pooled buffers to transport requests, with serializer/read/write pools owned by each MessageHandlerShared instance.
Updates TestingHost in-memory and Unix-domain socket transports and preserves connection establishment draining, runner cleanup, send-worker quiescence, and buffered tail-read behavior.
The transport replacement intentionally removes the legacy byte-stream connection configuration/middleware APIs, including ClientConnectionOptions and SiloConnectionOptions. Custom connection behavior migrates to message transport connector/listener decorators registered through dependency injection; the connection-middleware guide provides the migration path. Package-specific compatibility suppressions list only the removed legacy APIs for net8.0/net10.0, including their generated socket-exception codecs, while retaining validation for the rest of each package.
TLS APIs move from the retired Microsoft.Orleans.Connections.Security assembly into Core and Runtime. Explicit static calls to OrleansConnectionSecurityHostingExtensions migrate to ClientTlsHostingExtensions or SiloTlsHostingExtensions; extension calls retain the builder.UseTls(...) syntax. TLS options, features, and the public CertificateLoader.LoadFromStoreCert utility reside in Orleans.Connections.Transport.Security. Applications and libraries rebuild against the consolidated packages; the TLS guide lists the migration mappings and binary compatibility impact.
The reason will be displayed to describe this comment to others. Learn more.
Pull request overview
Introduces a new message-oriented transport layer (TCP/socket/stream/TLS implementations) and rewires Orleans client/gateway/silo networking plus serialization/buffering to flow through these abstractions, including updates to TestingHost transports and related tests.
Changes:
Add MessageTransport / listener / connector abstractions and socket + TLS transport implementations.
Rewire runtime/client connection factories & listeners to use message transports (including updated tracing/logging and lifecycle).
Update serialization buffer handling (ArcBuffer/ArcBufferWriter) and add/adjust unit tests and benchmarks accordingly.
This change introduces/renames public hosting extension APIs (ClientTlsHostingExtensions.UseTls). For this repo, public API changes in packable src/ projects require updating the generated API surface files under src/api. Please regenerate/update the relevant src/api entries so CI/public API checks stay consistent. src/Orleans.Runtime/Hosting/SiloTlsHostingExtensions.ISiloBuilder.cs:16
This introduces/renames public hosting extension APIs (SiloTlsHostingExtensions.UseTls). Public API changes in packable src/ projects are expected to be reflected in the generated API surface files under src/api. Please regenerate/update the relevant src/api files accordingly.
When serializing a null SiloAddress, WriteRaw writes a length byte of 1, but ReadRaw treats length==0 as null and otherwise expects at least 4 bytes (hash code). This will cause decoding to read past the payload for null values (or produce corrupt results).
public void WriteRaw<TBufferWriter>(ref Writer<TBufferWriter> writer, SiloAddress value) where TBufferWriter : IBufferWriter<byte>
{
var currentTimestamp = Environment.TickCount64;
if (value is null)
{
writer.WriteByte(1); // writer.WriteVarUInt32(0);
return;
}
CI review: the rebased branch builds successfully on all solution targets, but the current .NET CI run has widespread provider and test-job failures while the build jobs pass. The failed jobs are timing out or crashing in test execution, which points to a runtime regression in the message-oriented transport branch rather than runner infrastructure. The current run is still waiting on macOS hang-dump jobs; the latest push restarts CI after correcting the review feedback.
ReadRaw() is declared as returning SiloAddress, but it returns null when the encoded length is 0. This breaks the null-sentinel contract used by MessageSerializer (SendingSilo/TargetSilo are nullable) and can surface as nulls flowing through a non-null return type.
This issue also appears on line 108 of the same file.
var length = (int)reader.ReadVarUInt32();
if (length == 0)
{
return null;
}
WriteRaw() attempts to handle null SiloAddress values, but it writes a single byte value of 1 (length=1) rather than encoding a varuint length of 0. ReadRaw() treats length==0 as the null sentinel, so the current code will deserialize null values as a 1-byte payload and then fail when it tries to read the 4-byte hash code.
var currentTimestamp = Environment.TickCount64;
if (value is null)
{
writer.WriteByte(1); // writer.WriteVarUInt32(0);
return;
The retried Documentation workflow still has PR-specific validation failures. Microsoft.Orleans.Connections.Security is documented and referenced by the TLS sample but is not produced by Orleans.slnx; the docs also reference three lifecycle stages absent from the public API: ValidateInitialConnectivity, GrainDirectoryShutdown, and GrainDeactivation. Run: https://github.com/dotnet/orleans/actions/runs/32134317547
TlsOptionsValidator is declared as internal, but it is referenced from Orleans.Runtime (see SiloTlsHostingExtensions). Since this type needs to be constructed across assemblies, it must be public (or otherwise moved into Orleans.Runtime). src/Orleans.Serialization/Serializers/CodecProvider.cs:30
There is a commented-out field left in the implementation. This dead code adds noise and should be removed to keep the provider implementation maintainable.
MessageTransportConnectorFactory/MessageTransportListenerFactory are typed to concrete TLS middleware (IEnumerable<TlsMessageTransportMiddleware>) even though the abstractions are IMessageTransportMiddleware. This prevents non-TLS middleware from being applied and will also break DI resolution if these factories are ever constructed from the services which register middleware by the interface type. src/Orleans.Core/Networking/ConnectionFrameHelper.cs:215
WriteFrameWithPrefixingWriter now buffers the entire payload into an ArrayBufferWriter and then copies it into the PipeWriter. This adds an extra allocation/copy on a hot path (frame writes), and it also forces the entire payload to be materialized in a contiguous array before writing.
Consider switching back to a streaming/pooled approach (e.g., a pooled buffer writer) to avoid the extra copy, especially for larger frames. src/Orleans.Core/Networking/ConnectionDirection.cs:16
This change introduces new public API surface in Orleans.Core (e.g., TransportProtocol and ITransportProtocolFeature). Since Orleans.Core is API-tracked (see src/api/Orleans.Core/Orleans.Core.cs), the PR should also update the generated API surface file (or make these types internal if they are not intended as public API).
The reason will be displayed to describe this comment to others. Learn more.
Copilot wasn't able to review this pull request because it exceeds the maximum number of lines (20,000). Try reducing the number of changed lines and requesting a review from Copilot again.
CI root cause: the transport refactor retained client removal but dropped the current-main \GatewayEvents.ClientDropped\ emission and silo address used by dropped-client stream tests. NATS, SQS, PostgreSQL, Kinesis, and related jobs therefore timed out waiting for a diagnostic event that never arrived. The branch now restores that event path; the provider-independent memory-stream dropped-client tests pass. The stale \Microsoft.Orleans.Connections.Security\ references were also removed from TLS snippet projects, and docs validation plus \Orleans.slnx\ build pass.
The reason will be displayed to describe this comment to others. Learn more.
Copilot wasn't able to review this pull request because it exceeds the maximum number of lines (20,000). Try reducing the number of changed lines and requesting a review from Copilot again.
The middleware-composed connector is stored only in ConnectionFactory; ConnectionFactory is not disposable, so decorators created by mw.Apply never receive DisposeAsync at host shutdown. DI can dispose the original registered connector, but it cannot dispose wrapper instances which may own resources. Make the factory own/dispose the composed connector or register the composed instance through DI.
Addressed the review-level connector-disposal finding in df0f50c. ConnectionFactory now owns and disposes the middleware-created decorator chain after admitted connection attempts have drained. A borrowed connector at the DI boundary leaves the registered connector owned by the service provider, preserving exactly-once disposal of both decorators and the registered connector. Repeated disposal shares one completion task. The middleware guide documents this ownership contract, and regressions cover synchronous/asynchronous provider disposal, nested decorators, and an in-flight connection attempt.
This newly public delegate and options type omit XML documentation, unlike the surrounding TLS public API and the previous versions of these types. Add docs for the delegate, type, and its public members before shipping the moved API.
Document newly public TLS delegate and options API
This newly public delegate and options type omit XML documentation, unlike the surrounding TLS public API and the previous versions of these types. Add docs for the delegate, type, and its public members before shipping the moved API.
Addressed the review-summary TLS documentation findings in a69cd83: both certificate-selection delegates, both authentication-options types, and all their public properties now have XML documentation. TestingHost's generated API includes the listener-options type.
Also fixed the three cross-platform BVT failures introduced by the shutdown regression fixture. The test manually publishes its capturing sender without starting a connection runner, so it now explicitly closes and removes that owned routing registration during cleanup. Previously the registration remained in ConnectionManager and its shutdown drain timed out. The complete, unmodified ConnectionManagerTests class passes all 14 cases on net8.0 and net10.0 against the real current runtime and TestingHost projects, including the three shutdown cases and teardown.
Normal Release packs for Core, Runtime, and TestingHost pass. The two requested hosting-extension suppressions are unnecessary: the removed type is in the separate Connections.Security baseline assembly, not either package's baseline. The inline replies document that metadata evidence. Fresh CI will cover the published commit.
This concatenation omits the space between non-null and value, so the exception reads non-nullvalue. Include the missing space to keep the configuration failure message clear and consistent with the server-side equivalent.
Investigated the latest overview's reference to moderate shutdown and TLS option-registration issues. The review has no new inline findings or detailed description for those two issues; the historical TLS registration comments are the available concrete explanation.
Published e6c8a50 with a reproduced Unix listener shutdown-contract fix. Pending accepts already terminate on shutdown, but a subsequent AcceptAsync threw "Transport is not bound" after either unbind or disposal instead of returning null as MessageTransportListener requires. The stopped-state check now preserves the terminal null result while retaining the pre-bind error. AcceptAfterShutdownReturnsNull verifies pending and subsequent accepts, socket-file cleanup, and the pre-bind boundary for both shutdown paths. Both cases failed before the fix and pass now.
The historical TLS claim incorrectly treats services.Configure(configure) as ConfigureAll. Configure targets Options.DefaultName; the explicit silo/gateway registrations each initialize their own named instance once. Removing those registrations would leave inbound listeners unconfigured. SiloTlsConfiguration_AppliesOncePerConnectionRole now exercises the real UseTls registration and options monitor, checks exactly three configured instances, cached repeated resolutions, an unrelated option name remaining unconfigured, and exactly one non-idempotent authentication callback per role. No TLS registration change is needed.
All four Unix listener cases and all seven TLS option cases pass on net8.0 and net10.0 against the current runtime/TestingHost projects. The commit also includes the requested "non-null value" spacing correction. Fresh CI will validate the published head.
This new public exception has no XML documentation, unlike the neighboring public transport exception and the other new transport APIs. Add a summary describing when callers should observe an aborted connection so the generated package documentation is complete.
This new public exception is missing XML documentation. Add a summary describing a reset connection so the public transport API follows the documentation convention used by ConnectionClosedException and the other new transport types.
Addressed both review-summary documentation findings in 5408054. ConnectionAbortedException now describes termination before initialization or a pending operation completes; ConnectionResetException describes resets from the remote peer or underlying network. Both types and all their constructors have XML documentation. This is a documentation-only change with no public signature or runtime behavior changes.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Orleans networking is organized around byte-stream connections. Message-oriented transports provide a common request contract for sending and receiving framed messages across transport implementations.
Solution
Orleans1ALPN identifier and certificate-mode defaults.MessageHandlerSharedinstance.Compatibility and migration
The transport replacement intentionally removes the legacy byte-stream connection configuration/middleware APIs, including
ClientConnectionOptionsandSiloConnectionOptions. Custom connection behavior migrates to message transport connector/listener decorators registered through dependency injection; the connection-middleware guide provides the migration path. Package-specific compatibility suppressions list only the removed legacy APIs for net8.0/net10.0, including their generated socket-exception codecs, while retaining validation for the rest of each package.TLS APIs move from the retired
Microsoft.Orleans.Connections.Securityassembly into Core and Runtime. Explicit static calls toOrleansConnectionSecurityHostingExtensionsmigrate toClientTlsHostingExtensionsorSiloTlsHostingExtensions; extension calls retain thebuilder.UseTls(...)syntax. TLS options, features, and the publicCertificateLoader.LoadFromStoreCertutility reside inOrleans.Connections.Transport.Security. Applications and libraries rebuild against the consolidated packages; the TLS guide lists the migration mappings and binary compatibility impact.Microsoft Reviewers: Open in CodeFlow