Skip to content

Custom AndroidMessageHandler.ServerCertificateCustomValidationCallback that returns false may cause application crash while debugging. #8608

Description

@anton-yashin

Android application type

.NET Android (net7.0-android, net8.0-android, etc.)

Affected platform version

VS2022 18.3 with .net 34.0.43/8.0.100

Description

When you using AndroidMessageHandler with ServerCertificateCustomValidationCallback that returns false while debugging you may get application crash.

Steps to Reproduce

  1. Create new android app with code like this
    Sample code:
try
{
    using (var ch = new AndroidMessageHandler())
    {
        ch.ServerCertificateCustomValidationCallback += (a, b, c, d) => false;
        using (var hc = new HttpClient(ch))
        {
            var result = await hc.GetAsync("https://github.com");
            // never get here
        }
    }
}
catch (Exception ex)
{
    // may be get here
    XDebug.WriteLine($"exception handled {ex.Message}");
}
  1. Run it several times. Two times in my case.
  2. Observe application crash.
    See sample project in attachment: UnhandledCertificateException.zip

Did you find any workaround?

No response

Relevant log output

No response

Activity

  1. anton-yashin commented on Dec 22, 2023

    @anton-yashin
    Author

    You may run sample code more than one time to crash application. Debugger is required.

  2. jpobst commented on Dec 22, 2023

    @jpobst
    Contributor

    To be clear, the issue is that the exception isn't caught, correct?

    The exception is expected, but the catch handler isn't functioning.

  3. anton-yashin commented on Dec 22, 2023

    @anton-yashin
    Author

    With VS2022 17.8.3 debugger it's going to crash application, after second time running sample code. Without debugger seems works fine. There something strange happens.

  4. anton-yashin commented on Dec 22, 2023

    @anton-yashin
    Author

    With a debugger, it looks like a crash from an uncaught exception.

  5. changed the title [-]Java.Security.Cert.CertificateException when AndroidMessageHandler.ServerCertificateCustomValidationCallback is set and returns false.[/-] [+]Custom AndroidMessageHandler.ServerCertificateCustomValidationCallback that returns false may cause application crash while debugging.[/+] on Dec 23, 2023
  6. grendello commented on Jan 3, 2024

    @grendello
    Contributor

    Please provide more information about the crash. We would need the following:

    Any messages VS shows in either its output/debug/etc panes and screenshots of popup boxes (if any) it produces.

    Full logcat of the application from the device/emulator. To record it, please follow the steps below:

    1. Open the VS Developer prompt. Do not start the application yet.
    2. Type the following commands one by one:
      1. adb shell setprop debug.mono.log default,assembly,mono_log_level=debug,mono_log_mask=all
      2. adb logcat -G 16M
      3. adb logcat -c
    3. Start the application from within VS and trigger the crash
    4. Back in the VS Developer prompt type: adb logcat -d > logcat.txt

    Please attach logcat.txt and the requested VS messages/screenshots. Thanks!

  7. added
    need-infoIssues that need more information from the author.
    Area: Mono RuntimeMono-related issues: BCL bugs, AOT issues, etc.
    Area: DebuggerIssues using or interacting with the debugger.
    and removed
    needs-triageIssues that need to be assigned.
    on Jan 3, 2024
  8. anton-yashin commented on Jan 8, 2024

    @anton-yashin
    Author

    Here requested addtional info
    logcat.txt

  9. 14 remaining items

  10. removed their assignment
    on Feb 7, 2024
  11. gkarabin commented on Jun 14, 2024

    @gkarabin

    My team seems to be running into this. Are there any other related tickets open?

    We are just getting organized to look into this. Is there anything we could do to help move things along?

  12. simonrozsival commented on Jun 15, 2024

    @simonrozsival
    Member

    This can't be easily fixed without additional runtime support.

    Would it be possible to raise the Java exception directly through some JNI helper in ServerCertificateCustomValidator without throwing it in C# first? Would we be able to avoid hitting the uncaught exception handler code?

  13. removed their assignment
    on Mar 26, 2026
  14. anton-yashin commented on Aug 14, 2026

    @anton-yashin
    Author

    Checked w 36.1.69/10.0.100. Works fine. Thanks :)

  15. added
    need-attentionA xamarin-android contributor needs to review
    and removed
    possibly-staleIssues that are potentially no longer relevant.
    on Aug 14, 2026
  16. locked and limited conversation to collaborators on Sep 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Area: Mono.AndroidIssues with the Android API binding (Mono.Android.dll).need-attentionA xamarin-android contributor needs to review

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions