You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Two families of app.config binding redirects name assembly versions that are not deployed. Twelve project configs redirect Fizzler to 1.3.0.0 while the deployed assembly is 1.3.1.0, and SVGControl/app.config redirects System.Runtime.CompilerServices.Unsafe to 6.0.2.0 while the deployed assembly is 6.0.3.0 and all sixteen sibling configs say 6.0.3.0. This is the same defect class as bug #418, where a redirect to a non-deployed ExCSS version caused SvgDocument.Open to fail in hosts that apply the redirect.
Command/flags used: static inspection of */app.config against packages/ and against assembly metadata
Data source or fixture: the repository's own app.config set and restored packages/ tree
Steps to Reproduce
Verified 2026-08-04 on branch bug/svg-renderer-null-document-nre-418 at commit 296eac95:
grep -rl 'name="Fizzler"' --include=app.config . returns 13 files. Of their redirects, 12 read newVersion="1.3.0.0" and 1 reads newVersion="1.3.1.0".
The only deployed Fizzler is packages/Fizzler.1.3.1/, and [System.Reflection.AssemblyName]::GetAssemblyName('packages\Fizzler.1.3.1\lib\netstandard2.0\Fizzler.dll').Version returns 1.3.1.0. No 1.3.0.0 assembly exists anywhere in the repository.
Enumerating System.Runtime.CompilerServices.Unsafe redirects across all seventeen project configs: sixteen read newVersion="6.0.3.0"; SVGControl/app.config alone reads newVersion="6.0.2.0".
SVGControl/bin/Debug/System.Runtime.CompilerServices.Unsafe.dll is assembly version 6.0.3.0, and both SVGControl and SVGControl.Test pin package version 6.1.2.
Expected Behavior
Every bindingRedirectnewVersion names an assembly version that is actually deployed to the output directory, so a host that honors the redirect can satisfy the bind.
Actual Behavior
Twelve Fizzler redirects and one Unsafe redirect name versions that exist nowhere in the repository. A host that applies these redirects would request an assembly that cannot be found.
Logs / Screenshots
Attached minimal logs or screenshot
Snippet: no runtime failure captured. Both findings are currently latent - see below.
Impact / Severity
Blocker
High
Medium
Low
Both findings are latent today, which is why they were deferred rather than folded into #418:
Fizzler is inert. Research during Bug: svg-renderer-null-document-nre #418 established that nothing in the deployed graph carries a Fizzler assembly reference. Svg 3.4.7 does not reference it (its CSS selector work goes through ExCSS StylesheetParser, and the Fizzler string is absent from Svg.dll), and ExCSS 4.3.1 does not reference it. The using Fizzler; at SVGControl/PictureBoxSVG.cs:14 is unused and emits no AssemblyRef. With no requesting reference, the redirect is never consulted.
The Unsafe outlier is masked.SVGControl is a library, so the redirect in SVGControl/app.config is not the one the CLR reads at runtime; the host's config governs, and every host config in the repository says 6.0.3.0.
The severity is Low on current evidence, not on principle. Either becomes live the moment a dependency starts carrying the corresponding reference - which is precisely how #418 arose, and #418 was rated High.
Summary
Two families of
app.configbinding redirects name assembly versions that are not deployed. Twelve project configs redirectFizzlerto1.3.0.0while the deployed assembly is1.3.1.0, andSVGControl/app.configredirectsSystem.Runtime.CompilerServices.Unsafeto6.0.2.0while the deployed assembly is6.0.3.0and all sixteen sibling configs say6.0.3.0. This is the same defect class as bug #418, where a redirect to a non-deployedExCSSversion causedSvgDocument.Opento fail in hosts that apply the redirect.Environment
net481), WinForms + VSTO*/app.configagainstpackages/and against assembly metadataapp.configset and restoredpackages/treeSteps to Reproduce
Verified 2026-08-04 on branch
bug/svg-renderer-null-document-nre-418at commit296eac95:grep -rl 'name="Fizzler"' --include=app.config .returns 13 files. Of their redirects, 12 readnewVersion="1.3.0.0"and 1 readsnewVersion="1.3.1.0".packages/Fizzler.1.3.1/, and[System.Reflection.AssemblyName]::GetAssemblyName('packages\Fizzler.1.3.1\lib\netstandard2.0\Fizzler.dll').Versionreturns1.3.1.0. No1.3.0.0assembly exists anywhere in the repository.System.Runtime.CompilerServices.Unsaferedirects across all seventeen project configs: sixteen readnewVersion="6.0.3.0";SVGControl/app.configalone readsnewVersion="6.0.2.0".SVGControl/bin/Debug/System.Runtime.CompilerServices.Unsafe.dllis assembly version6.0.3.0, and bothSVGControlandSVGControl.Testpin package version6.1.2.Expected Behavior
Every
bindingRedirectnewVersionnames an assembly version that is actually deployed to the output directory, so a host that honors the redirect can satisfy the bind.Actual Behavior
Twelve Fizzler redirects and one
Unsaferedirect name versions that exist nowhere in the repository. A host that applies these redirects would request an assembly that cannot be found.Logs / Screenshots
Impact / Severity
Both findings are latent today, which is why they were deferred rather than folded into #418:
Fizzlerassembly reference.Svg 3.4.7does not reference it (its CSS selector work goes through ExCSSStylesheetParser, and theFizzlerstring is absent fromSvg.dll), andExCSS 4.3.1does not reference it. Theusing Fizzler;atSVGControl/PictureBoxSVG.cs:14is unused and emits noAssemblyRef. With no requesting reference, the redirect is never consulted.Unsafeoutlier is masked.SVGControlis a library, so the redirect inSVGControl/app.configis not the one the CLR reads at runtime; the host's config governs, and every host config in the repository says6.0.3.0.The severity is Low on current evidence, not on principle. Either becomes live the moment a dependency starts carrying the corresponding reference - which is precisely how #418 arose, and #418 was rated High.
Source
From: docs/features/potential/2026-08-04-stale-fizzler-and-unsafe-binding-redirects.md