Skip to content

Bug: stale-fizzler-and-unsafe-binding-redirects #953

Description

@drmoisan
  • Work Mode: minor-audit

Summary

Two families of app.config binding redirects name assembly versions that are not deployed. Twelve project configs redirect Fizzler to 1.3.0.0 while the deployed assembly is 1.3.1.0, and SVGControl/app.config redirects System.Runtime.CompilerServices.Unsafe to 6.0.2.0 while the deployed assembly is 6.0.3.0 and all sixteen sibling configs say 6.0.3.0. This is the same defect class as bug #418, where a redirect to a non-deployed ExCSS version caused SvgDocument.Open to fail in hosts that apply the redirect.

Environment

  • OS/version: Windows 11 Pro 10.0.26200
  • .NET/framework: .NET Framework 4.8.1 (net481), WinForms + VSTO
  • Command/flags used: static inspection of */app.config against packages/ and against assembly metadata
  • Data source or fixture: the repository's own app.config set and restored packages/ tree

Steps to Reproduce

Verified 2026-08-04 on branch bug/svg-renderer-null-document-nre-418 at commit 296eac95:

  1. grep -rl 'name="Fizzler"' --include=app.config . returns 13 files. Of their redirects, 12 read newVersion="1.3.0.0" and 1 reads newVersion="1.3.1.0".
  2. The only deployed Fizzler is packages/Fizzler.1.3.1/, and [System.Reflection.AssemblyName]::GetAssemblyName('packages\Fizzler.1.3.1\lib\netstandard2.0\Fizzler.dll').Version returns 1.3.1.0. No 1.3.0.0 assembly exists anywhere in the repository.
  3. Enumerating System.Runtime.CompilerServices.Unsafe redirects across all seventeen project configs: sixteen read newVersion="6.0.3.0"; SVGControl/app.config alone reads newVersion="6.0.2.0".
  4. SVGControl/bin/Debug/System.Runtime.CompilerServices.Unsafe.dll is assembly version 6.0.3.0, and both SVGControl and SVGControl.Test pin package version 6.1.2.

Expected Behavior

Every bindingRedirect newVersion names an assembly version that is actually deployed to the output directory, so a host that honors the redirect can satisfy the bind.

Actual Behavior

Twelve Fizzler redirects and one Unsafe redirect name versions that exist nowhere in the repository. A host that applies these redirects would request an assembly that cannot be found.

Logs / Screenshots

  • Attached minimal logs or screenshot
  • Snippet: no runtime failure captured. Both findings are currently latent - see below.

Impact / Severity

  • Blocker
  • High
  • Medium
  • Low

Both findings are latent today, which is why they were deferred rather than folded into #418:

  • Fizzler is inert. Research during Bug: svg-renderer-null-document-nre #418 established that nothing in the deployed graph carries a Fizzler assembly reference. Svg 3.4.7 does not reference it (its CSS selector work goes through ExCSS StylesheetParser, and the Fizzler string is absent from Svg.dll), and ExCSS 4.3.1 does not reference it. The using Fizzler; at SVGControl/PictureBoxSVG.cs:14 is unused and emits no AssemblyRef. With no requesting reference, the redirect is never consulted.
  • The Unsafe outlier is masked. SVGControl is a library, so the redirect in SVGControl/app.config is not the one the CLR reads at runtime; the host's config governs, and every host config in the repository says 6.0.3.0.

The severity is Low on current evidence, not on principle. Either becomes live the moment a dependency starts carrying the corresponding reference - which is precisely how #418 arose, and #418 was rated High.

Source

From: docs/features/potential/2026-08-04-stale-fizzler-and-unsafe-binding-redirects.md

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions