Skip to content

Guarding calls to platform-specific APIs #33331

Description

@terrajobst

For iOS and Android in particular we want the developer to be able to do runtime checks for the OS version in order to guard method calls. We've steered people away from Environment.OSVersion in favor of RuntimeInformation.IsOSPlatform(). However, we (deliberately) omitted a way to detect version numbers because the guidance has been to move to feature detection instead. However, we've learned that version checks are a practical necessity. Also, they are the status quo on iOS and Android.

We plan on combining these guards with a set of custom attributes that are used by an analyzer to flag code that isn't properly guarded. For more details, see this spec.

API Proposal

namespace System.Runtime.InteropServices
{
    public partial struct OSPlatform
    {
        // Existing properties
        // public static OSPlatform FreeBSD { get; }
        // public static OSPlatform Linux { get; }
        // public static OSPlatform OSX { get; }
        // public static OSPlatform Windows { get; }
        public static OSPlatform Android { get; }
        public static OSPlatform iOS { get; }
        // public static OSPlatform macOS { get; } /* We already have OSX */
        public static OSPlatform tvOS { get; }
        public static OSPlatform watchOS { get; }
    }

    public partial static class RuntimeInformation
    {
        // Existing API
        // public static bool IsOSPlatform(OSPlatform osPlatform);

        // Check for the OS with a >= version comparison
        // Used to guard APIs that were added in the given OS release.
        public static bool IsOSPlatformOrLater(OSPlatform osPlatform, int major);
        public static bool IsOSPlatformOrLater(OSPlatform osPlatform, int major, int minor);
        public static bool IsOSPlatformOrLater(OSPlatform osPlatform, int major, int minor, int build);
        public static bool IsOSPlatformOrLater(OSPlatform osPlatform, int major, int minor, int build, int revision);

        // Allows checking for the OS with a < version comparison
        // Used to guard APIs that were obsoleted or removed in the given OS release. The comparison
        // is less than (rather than less than or equal) so that people can pass in the version where
        // API became obsoleted/removed.
        public static bool IsOSPlatformEarlierThan(OSPlatform osPlatform, int major);
        public static bool IsOSPlatformEarlierThan(OSPlatform osPlatform, int major, int minor);
        public static bool IsOSPlatformEarlierThan(OSPlatform osPlatform, int major, int minor, int build);
        public static bool IsOSPlatformEarlierThan(OSPlatform osPlatform, int major, int minor, int build, int revision);
    }
}

namespace System.Runtime.Versioning
{
    // Base type for all platform-specific attributes. Primarily used to allow grouping
    // in documentation.
    public abstract class PlatformAttribute : Attribute
    {
        protected PlatformAttribute (string platformName);
        public string PlatformName { get; }
    }

    // Records the platform that the project targeted.
    [AttributeUsage(AttributeTargets.Assembly,
                    AllowMultiple=false, Inherited=false)]
    public sealed class TargetPlatformAttribute : PlatformAttribute
    {
        public TargetPlatformAttribute(string platformName);
        public string PlatformName { get; }
    }

    // Records the minimum platform that is required in order to the marked thing.
    //
    // * When applied to an assembly, it means the entire assembly cannot be called
    //   into on earlier versions. It records the TargetPlatformMinVersion property.
    //
    // * When applied to an API, it means the API cannot be called from an earlier
    //   version.
    //
    // In either case, the caller can either mark itself with MinimumPlatformAttribute
    // or guard the call with a platform check.
    //
    // The attribute can be applied multiple times for different operating systems.
    // That means the API is supported on multiple operating systems.
    //
    // A given platform should only be specified once.

    [AttributeUsage(AttributeTargets.Assembly |
                    AttributeTargets.Class |
                    AttributeTargets.Constructor |
                    AttributeTargets.Event |
                    AttributeTargets.Method |
                    AttributeTargets.Module |
                    AttributeTargets.Property |
                    AttributeTargets.Struct,
                    AllowMultiple=true, Inherited=false)]
    public sealed class MinimumPlatformAttribute : PlatformAttribute
    {
        public MinimumPlatformAttribute(string platformName);
    }

    // Marks APIs that were removed in a given operating system version.
    //
    // Primarily used by OS bindings to indicate APIs that are only available in
    // earlier versions.
    [AttributeUsage(AttributeTargets.Assembly |
                    AttributeTargets.Class |
                    AttributeTargets.Constructor |
                    AttributeTargets.Event |
                    AttributeTargets.Method |
                    AttributeTargets.Module |
                    AttributeTargets.Property |
                    AttributeTargets.Struct,
                    AllowMultiple=true, Inherited=false)]
    public sealed class RemovedInPlatformAttribute : PlatformAttribute
    {
        public RemovedInPlatformAttribute(string platformName);
    }

    // Marks APIs that were obsoleted in a given operating system version.
    //
    // Primarily used by OS bindings to indicate APIs that should only be used in
    // earlier versions.
    [AttributeUsage(AttributeTargets.Assembly |
                    AttributeTargets.Class |
                    AttributeTargets.Constructor |
                    AttributeTargets.Event |
                    AttributeTargets.Method |
                    AttributeTargets.Module |
                    AttributeTargets.Property |
                    AttributeTargets.Struct,
                    AllowMultiple=true, Inherited=false)]
    public sealed class ObsoletedInPlatformAttribute : PlatformAttribute
    {
        public ObsoletedInPlatformAttribute(string platformName);
        public string Url { get; set; }
    }
}

This design allows us to encapsulate the version comparison, i.e. the "and later" part.

Usage: Recording Project Properties

<Project>
    <Properties>
        <TargetFramework>net5.0-ios12.0</TargetFramework>
        <TargetPlatformMinVersion>10.0</TargetPlatformMinVersion>
    </Properties>
    ...
</Project>

The SDK already generates a file called AssemblyInfo.cs which includes the TFM. We'll extend on this to also record the target platform and minium version (which can be omitted in the project file which means it's the same as the target platform):

[assembly: TargetFramework(".NETCoreApp, Version=5.0")] // Already exists today
[assembly: TargetPlatform("ios12.0")]  // new
[assembly: MinimumPlatform("ios10.0")] // new

Usage: Guarding Platform-Specific APIs

NSFizzBuzz is an iOS API that was introduced in iOS 14. Since I only want to call the API when I'm running on a version of the OS that supports it I'd guard the call using IsOSPlatformOrLater:

static void ProvideExtraPop()
{
    if (!RuntimeInformation.IsOSPlatformOrLater(OSPlatform.iOS, 14))
        return;

    NSFizzBuzz();
}

Usage: Declaring Platform-Specific APIs

The RemovedInPlatformAttribute and ObsoletedInPlatformAttribute will primarily be used by the OS bindings to indicate
whether a given API shouldn't be used any more.

The MinimumPlatformAttribute will be for two things:

  1. Indicate which OS a given assembly can run on (mostly used by user code)
  2. Indicate which OS a given API is supported on (mostly used by OS bindings)

Both scenarios have effectively the same meaning for our analyzer: calls into the assembly/API are only legal if the call site is from the given operating system, in the exact or later version.

The second scenario can also be used by user code to forward the requirement. For example, imagine the NSFizzBuzz API to be complex. User code might want to encapsulate it's usage in a helper type:

[MinimumPlatform("ios14.0")]
internal class NSFizzBuzzHelper
{
    public void Fizz() { ... }
    public void Buzz() { ... }
}

As far as the analyzer is concerned, NSFizzBuzzHelper can only be used on iOS 14, which means that its members can call iOS 14 APIs without any warnings. The requirement to check for iOS is effectively forwarded to code that calls any members on NSFizzBuzzHelper.

@dotnet/fxdc @mhutch

Activity

  1. self-assigned this
    on Mar 7, 2020
  2. added this to the 5.0 milestone on Mar 7, 2020
  3. bartonjs commented on Mar 7, 2020

    @bartonjs
    Member

    I feel like the method name needs something about the versioning. Like IsOSPlatformVersionOrNewer; or IsMinimumOSPlatformVersion. Because, as written, I could see people writing it thinking it's exact, and where they should have lightup they have fallback.

  4. GrabYourPitchforks commented on Mar 7, 2020

    @GrabYourPitchforks
    Member

    Piggybacking off Jeremy's comment, I recommend IsOSVersionAtLeast (or similar). This somewhat matches the APIs that Windows and iOS expose. (Not sure about Android.)

    It also reads fairly well IMO.

    if (RuntimeInformation.IsOSVersionAtLeast(OSPlatform.iOS, 12, 0)
    {
        /* do something */
    }
  5. nil4 commented on Mar 7, 2020

    @nil4
    Contributor

    Could the two overloads be replaced by a single method taking a System.Version argument? e.g.

    public static bool IsOSVersionAtLeast(OSPlatform osPlatform, Version minimumVersion);
  6. marek-safar commented on Mar 7, 2020

    @marek-safar
    Contributor

    It'd be great if we could design this together with API for minimal version annotations. If we had both standardized someone could, for example, write missing version check analyzer which would work everywhere.

    The expanded version of the sample

    public void OnClick(object sender, EventArgs e)
    {
        if (RuntimeInformation.IsOSPlatform(OSPlatform.iOS, 12, 0))
        {
            NSFizBuzz();
        }
    }
    
    [IntroducedOn(OSPlatform.iOS, 12, 0)]
    static void NSFizBuzz()
    {
    }

    I think the same can apply to libraries targetting Linux or Windows API which could be annotated when API minimal OS version is higher than the lowest version.

    Xamarin version can be explored at https://github.com/xamarin/xamarin-macios/blob/master/src/ObjCRuntime/PlatformAvailability2.cs

    /cc @chamons @jonpryor

  7. jkotas commented on Mar 7, 2020

    @jkotas
    Member

    What is the version that this will use on Linux?

    Is Android treated as a Linux flavor in these APIs?

    the guidance has been to move to feature detection instead. However, it seems this has never taken on in iOS & Android land

    The feature detection is a fine theory, but it is not an option in number of situations on Windows either. #32575 has recent example.

  8. scalablecory commented on Mar 7, 2020

    @scalablecory
    Contributor

    Will this API work correctly in Windows too?

  9. 51 remaining items

  10. jkotas commented on Jul 10, 2020

    @jkotas
    Member

    Cache the result of the "is current platform check?" in the OSPlatform constructor in a bool? The IsOSPlatform checks that we care about can then just check this bool without doing any expensive string comparisons, etc.

  11. jeffhandley commented on Jul 10, 2020

    @jeffhandley
    Member

    Interesting... Something like this?

    RuntimeInformation.Unix.cs (platform-specific, to be defined on Windows and Browser as well)

    public static partial class RuntimeInformation
    {
        internal static IsOSPlatformOrEquivalent(string osPlatform)
        {
            string name = s_osPlatformName ??= Interop.Sys.GetUnixName();
    
            if (osPlatform.Equals(name)) return true;
            if (name == "OSX") return osPlatform.Equals("MACOS");
    
            return false;
        }
    }

    OSPlatform.cs

    public readonly struct OSPlatform : IEquatable<OSPlatform>
    {
        internal bool IsCurrentOSPlatform { get; set; }
    
        private OSPlatform(string osPlatform)
        {
            if (osPlatform == null) throw new ArgumentNullException(nameof(osPlatform));
            if (osPlatform.Length == 0) throw new ArgumentException(SR.Argument_EmptyValue, nameof(osPlatform));
    
            _osPlatform = osPlatform;
            IsCurrentOSPlatform = RuntimeInformation.IsOSPlatformOrEquivalent(_osPlatform);
        }
    }

    RuntimeInformation.cs (cross-platform)

    public static partial class RuntimeInformation
    {
        public static bool IsOSPlatform(OSPlatform osPlatform)
        {
            return osPlatform.IsCurrentOSPlatform;
        }
    }
  12. buyaa-n commented on Jul 10, 2020

    @buyaa-n
    Contributor

    Is the compat analyzer going to do the required data flow analysis to see through cached checks for this?

    No, we determined we couldn't feasibly handle platform checks being in helper/utility methods and therefore only direct calls to IsOSPlatformOrLater and IsOSPlatformEarlierThan would be supported.

    @jeffhandley GlobalFlowStateAnalysis API provided by roslyn-analyzers (Manish recently added) supports cached checks, so we have it for free (just by using GlobalFlowStateAnalysis)

    https://github.com/buyaa-n/roslyn-analyzers/blob/c7a4bc1b05781834f5dcf758fefb6a5690110dd4/src/NetAnalyzers/UnitTests/Microsoft.NetCore.Analyzers/InteropServices/PlatformCompatabilityAnalyzerTests.cs#L918-L954

  13. jeffhandley commented on Jul 11, 2020

    @jeffhandley
    Member

    Thanks, @buyaa-n; I obviously didn't realize that made it in. Would that also cover caching within utility/helper methods or properties though, or is it limited to caching within the scope of the method?

    Would the following work?

    private _canUseIOS14 = RuntimeInformation.IsOSPlatformOrLater(OSPlatform.iOS, 14);
    
    private void M1()
    {
        if (_canUseIOS14)
        {
            M2();
        }
    }
    
    [MinimumOSPlatform("ios14.0")]
    private void M2()
    {
    }
  14. juliusfriedman commented on Jul 11, 2020

    @juliusfriedman
    Contributor

    I really think a set of PlatformSupportAttributes dervived from PlatformSupportAttribute is better than a single attribute here,

    That array given to a single PlatformSupportAttribute as I indicated above and it solves more problems than this does today.

    cc @terrajobst @stephentoub @jkotas

  15. buyaa-n commented on Jul 11, 2020

    @buyaa-n
    Contributor

    Would that also cover caching within utility/helper methods or properties though, or is it limited to caching within the scope of the method?

    I think it is limited within the scope of the method as the action registered to OperationBlockStartAction, I am not sure if we can support the example you wrote, @mavasani might answer that

  16. mavasani commented on Jul 11, 2020

    @mavasani

    Currently it doesn’t support reading values in fields and properties, but we can add support. It would be much cheaper if we only cared about read only fields and properties. Otherwise, we would need to enable PointsTo/Alias analysis, which is implemented in the repo, but would obviously make the analysis more expensive.

    Analysis supports interprocedural analysis, but it is off by default. We can consider enabling it by default with a max level 1 of call chain (single utility/helper). Call chain analysis length is configurable for all DFA in the repo, but obviously makes it more expensive with longer call chain threshold.

    In short, all analyses requested here is/can be supported without too much implementation cost. We only need to be cautious about how much we want to enable by default considering the standard performance vs precision trade off for any DFA.

  17. mavasani commented on Jul 11, 2020

    @mavasani

    Note that the analysis understands Debug asserts. I would personally recommend we take route similar to dataflow analysis for C# nullable reference types:

    1. Default analysis to scope of the current method. No interprocedural analysis by default.
    2. Define well known attributes, say EnsuresOSPlatformXXX(name, version), that can be applied to methods, fields and properties to aid analysis without requiring interprocedural analysis. The attributes will be conditional for debug builds only.
    3. Allow users to add debug asserts to aid analysis and avoid false positives for complex control flow or dataflow cases.

    Users can choose any of the above two modes:

    1. Enable interprocedural analysis, so you pay build time cost at the benefit of not having to add asserts or attribute annotations.
    2. Add debug asserts and debug only attributes for making analysis faster, at the expense of adding and maintaining annotations.
  18. juliusfriedman commented on Jul 11, 2020

    @juliusfriedman
    Contributor

    @mavasani I don't see how this is not better:

    [OSPlatformSupportAttribute(new MinSupportedPlatformAttribute(){ Platform, Version }, new NotSupportedPlatform(){ Platform, Version}), new MaxSupportedPlatformAttribute(){ Platform, Version)]
    int SomeMethod(int param){  /**/ }

    This gives you more flexibility and the ability to have all the information in one place rather than several.

    public sealed class OSPlatformSupportAttribute: System.Attribute  {
    //This is not allowed I guess... https://sharplab.io/#gist:d062656f543144e19805a3b4d5d80ab8
     PlatformSupportAttribute[] PlatformSupportAttributes {get; protected set;}
    }
    
    public abstract class PlatformSupportAttribute: System.Attribute  
    {  
        int m_Major, m_Minor;
        public bool IsSupported {get; protected set;} = true;
        public string Platform {get; protected set;}
        public Version Version {get;} => return new Version(m_Major,m_Minor);
      
        protected PlatformSupportAttribute(string platform, int major, int minor, bool isSupported = true)  
        {  
            if(string.IsNullOrWhiteSpace(platform) throw new InvalidOperationException($"{nameof(platform)} cannot be null or consist of only whitespace");
            Platform = platform;
            IsSupported = isSupported;  
            m_Major = major;  
            m_Minor = minor;
        }  
    }  
    
    public sealed class MinSupportedPlatformAttribute: PlatformSupportAttribute
    {     
        public MinSupportedPlatformAttribute(string platform, int major, int minor, , bool isSupported = true) : base(platform, major, minor, isSupported)  
        { 
        }  
    }  
    
    public sealed class MaxSupportedPlatformAttribute: PlatformSupportAttribute
    {     
        public MaxSupportedPlatformAttribute(string platform, int major, int minor, bool isSupported = true) : base(platform, major, minor, isSupported)  
        { 
        }  
    }  
    
    public sealed class NotSupportedPlatformAttribute: PlatformSupportAttribute
    {     
        public NotSupportedPlatformAttribute(string platform, int major, int minor) : base(platform, major, minor, false)  
        { 
        }  
    }  

    This could be extended for when the OS is patched live or even for CPUSupport etc very easily while proposed implementation cannot.

    Please reconsider.

  19. mavasani commented on Jul 11, 2020

    @mavasani

    @juliusfriedman my comment was not related to your suggestion on actual attributes to use for annotating platform dependent operations. It was regarding the kind of dataflow analysis to perform when detecting if a platform dependent operation was invoked in correct context, when user has performed the platform checks in a helper method or stored it into a field or property.

  20. jkotas commented on Jul 11, 2020

    @jkotas
    Member

    @juliusfriedman You suggestion does not compile as written. System.Version and arrays of non-primitive types are not valid fields in custom attributes.

  21. juliusfriedman commented on Jul 11, 2020

    @juliusfriedman
    Contributor

    @jkotas that's unfortunate, it can either be resolved with a custom version struct or more likley additional members which exspose a version property publicly.

    +protected int m_Major,m_Minor,m_Build,m_Patch;
    +public Version => new Version (m_Major, m_Minor);//Not sure about build and patch here

    See also:

    https://sharplab.io/#gist:d062656f543144e19805a3b4d5d80ab8

    If you really can't have arrays there as in my gist than have a method on the type which returns an array and that array should be able to be baked into the assembly if static.

    + IEnumerable<PlatformSupportAttributes> GetPlatformSupportAttributes()
  22. ghost locked as resolved and limited conversation to collaborators on Dec 10, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions