Runtime: cannot find source code for the System.Security.Cryptography.Cng library

Created on 4 Sep 2020  路  21Comments  路  Source: dotnet/runtime

I am trying to find the source code of the 4.5.0 version of System.Security.Cryptography.Cng library. The nuget package: https://www.nuget.org/packages/System.Security.Cryptography.Cng/4.5.0 shows an incorrect location.

area-System.Security customer assistance question

Most helpful comment

The assembly in the package contains [assembly: AssemblyInformationalVersion("4.6.26515.06 @BuiltBy: dlab-DDVSOWINAGE059 @Branch: release/2.1 @SrcCode: https://github.com/dotnet/corefx/tree/30ab651fcb4354552bd4891619a0bdd81e0ebdbf")]

Is https://github.com/dotnet/corefx/tree/30ab651fcb4354552bd4891619a0bdd81e0ebdbf what you need? It seems like the right SHA.

All 21 comments

Tagging subscribers to this area: @bartonjs, @vcsjones, @krwq
See info in area-owners.md if you want to be subscribed.

The assembly in the package contains [assembly: AssemblyInformationalVersion("4.6.26515.06 @BuiltBy: dlab-DDVSOWINAGE059 @Branch: release/2.1 @SrcCode: https://github.com/dotnet/corefx/tree/30ab651fcb4354552bd4891619a0bdd81e0ebdbf")]

Is https://github.com/dotnet/corefx/tree/30ab651fcb4354552bd4891619a0bdd81e0ebdbf what you need? It seems like the right SHA.

@danmosemsft Thanks.

I am trying to build the 4.5.0 version of System.Security.Cryptography.Cng nuget package locally that has the netstandard2.0 target. To do that, I have cloned the repo: https://github.com/dotnet/corefx/tree/30ab651fcb4354552bd4891619a0bdd81e0ebdbf and I execute the following commands:

Machine - macOS Mojave (10.14.6)

  • ./build-managed.sh -release --TargetGroup=netstandard from the root level of the repo.

The build gets failed with the following type of errors:(However, I see System.Security.Cryptography.Cng dll file targeting netstandard2.0 in the pacakges directory. )

mscorlib.forwards.cs(8,43): error CS0234: The type or namespace name 'TypeForwardedToAttribute' does not exist in the namespace 'System.Runtime.CompilerServices' (are you missing an assembly reference?) [/Users/test-1/Downloads/corefx-30ab651fcb4354552bd4891619a0bdd81e0ebdbf-5/src/shims/manual/mscorlib.csproj]

/Users/test-1/Downloads/corefx-30ab651fcb4354552bd4891619a0bdd81e0ebdbf-5/bin/obj/AnyOS.AnyCPU.Release/mscorlib/netcoreapp/_AssemblyInfo.cs(4,11): error CS0246: The type or namespace name 'AssemblyDescriptionAttribute' could not be found (are you missing a using directive or an assembly reference?) [/Users/test-1/Downloads/corefx-30ab651fcb4354552bd4891619a0bdd81e0ebdbf-5/src/shims/manual/mscorlib.csproj]

/Users/test-1/Downloads/corefx-30ab651fcb4354552bd4891619a0bdd81e0ebdbf-5/bin/obj/AnyOS.AnyCPU.Release/mscorlib/uap/_AssemblyInfo.cs(3,25): error CS0518: Predefined type 'System.String' is not defined or imported [/Users/test-1/Downloads/corefx-30ab651fcb4354552bd4891619a0bdd81e0ebdbf-5/src/shims/manual/mscorlib.csproj]`

  • ./build-managed.sh - the build is passed but I do not see a dll file that targets netstandard2.0 in the lib directory of System.Security.Cryptography.Cng directory present in the packages. However, I see dll files for netstandard1.3, 1.4 and 1.6.

Can you provide some pointers on how to resolve these errors and build the System.Security.Cryptography.Cng nuget package that has the netstandard2.0 target ?

To find the source code, say, 4.7.0 version of System.Security.Cryptography.Cng, what's the approach to follow ? The project site hyperlink mentioned here points to [dotnet/runtime] and then not sure where to navigate.

To find sources for a package download it then open it and use ILSPY

https://github.com/icsharpcode/ILSpy

to inspect the assembly metadata of the implementation assembly (found inside the lib folder within the package). This is how I got the info in my comment above
https://github.com/dotnet/runtime/issues/41837#issuecomment-686815984
You should find a link to the right repo and SHA.

Within the repo you should find sources in the System.Security.Cryptography.Cng folder.

Does that help?

For context can you share why you are intending to build that older code?

In our project, we are using the 6.7.1 version of System.IdentityModel.Tokens.Jwt. we have a requirement to build that package and all its dependencies in our local machines and use those dll's.

One of the dependency for Jwt package is System.Security.Cryptography.Cng (>=4.5.0). So, I have chosen 4.5.0 verison of System.Security.Cryptography.Cng to build locally.

I have executed the command: ./build-managed.sh --allconfigurations.

It created the nupkg files for the versions 4.2.0, 4.3.0 and 4.4.0 of System.Security.Cryptography.Cng but not actual 4.5.0 version.

@ericstj is there someone could help our Oracle friend here?

It created the nupkg files for the versions 4.2.0, 4.3.0 and 4.4.0 of System.Security.Cryptography.Cng but not actual 4.5.0 version.

Be careful where you look, those are downloaded not built. Look under bin folder for build outputs.

This is the 2.1 codebase. I believe for that you need two commands"
./build-managed.sh -release --allConfigurations
./build-managed.sh -release --packages

You'll find the built packages in bin/packages/release

@ericstj I see. Thanks.

I have tried to run the following sequence of commands
./build.sh - this step is executed.
./build-managed.sh -release --allConfigurations, - here, it fails with the following error.

/Users/test-1/Downloads/corefx-4bf469db354d3e87c9cbcabfbc592c7c621f1be6-3/external/runtime/runtime.depproj(72,5): error MSB3073: The command "chmod +x /Users/test-1/Downloads/corefx-4bf469db354d3e87c9cbcabfbc592c7c621f1be6-3/bin/testhost/netcoreapp-OSX-Release-x64/dotnet" exited with code 1.

Make sure you pass -release to build.sh as well. I'm assuming you want a release and not debug build which is why I'm suggesting this.

Got it.

I have executed the following sequence of commands:
./build.sh -release - this step is executed.
./build-managed.sh -release --allConfigurations, - here, it fails with the following error:

PE file is already strong-name signed.
I went through couple of threads related to the above error and I did not find any solution to resolve that.

I have deleted the dll's for which the error PE file is already strong-name signed. is reported and then I again executed the command: ./build-managed.sh -release --allConfigurations
and it returns the following error:
CSC : error CS2001: Source file 'corefx/src/Common/src/Interop/Windows/Kernel32/Interop.FreeLibrary.cs' could not be found. [corefx/src/System.Net.NameResolution/src/System.Net.NameResolution.csproj]

so I was able to resolve the above error by creating the copy of kernel32 directory, it was looking for uppercase Kernel32.

./build.sh -release - success
./build-managed.sh -release --allConfigurations - success
Now, when I execute the command: ./build-managed.sh -release --packages, it results in following type of errors:

corefx/Tools/Packaging.targets(1150,5): error : File WindowsBase.dll is marked as inbox for framework netcoreapp2.1 but was missing from framework package Microsoft.Private.CoreFx.NETCoreApp/4.5.0-rtm-29307-0. Either add the file or update InboxOn entry in corefx/pkg/Microsoft.Private.PackageBaseline/packageIndex.json. This may be suppressed with with PermitMissingInbox suppression [corefx/pkg/Microsoft.Private.CoreFx.NETCoreApp/Microsoft.Private.CoreFx.NETCoreApp.pkgproj]

I am interested to build the 4.5.0 version of System.Security.Cryptography.Cng package. So, I have tried the following command in System.Security.Cryptography.Cng directory:

cd src/System.Security.Cryptography.Cng/pkg/
dotnet build -c Release - success.
I have navigated to corefx/bin/packages/Release and then I see couple of packages related to Cng:

  • System.Security.Cryptography.Cng.4.5.0-rtm-29307-0.nupkg
  • System.Security.Cryptography.Cng.4.5.0-rtm-29307-0.nupkg.requires_nupkg_signing

So, It actually build RTM version. How can I build just 4.5.0 version ?
And is there difference between the version 4.5.0 and 4.5.0-rtm-29307-0 ?
Can I say that two packages are similar in terms of functionality except the signing part as it suggests ?

Any packages you build locally will not be signed, including the binaries within. The suffix is there just because the central stable-versioning property is not set. @Anipik could share this.

Running dotnet build in a subdirectory doesn't actually scope the build. The CNG package was actually built when you ran ./build-managed.sh -release --packages despite the error for a different package. If you only wanted to build the CNG package you could just run dotnet msbuild /p:ConfigurationGroup=Release on src/System.Security.Cryptography.Cng/pkg/System/Security.Cryptography.Cng.pkgproj.

Got it, Thanks.

@Anipik How can I build the exact 4.5.0 version ?
Is there any difference between the version 4.5.0 and 4.5.0-rtm-29307-0 ?

Is there any difference between the version 4.5.0 and 4.5.0-rtm-29307-0 ?

Both will be same functionally

@Anipik How can I build the exact 4.5.0 version ?

https://github.com/dotnet/corefx/blob/release/2.1/Packaging.props#L3
set this property to true or pass it as global property.

Let me know if u still face any issues.

@Anipik It worked. Thanks.

I am curious to know how to resolve the following error:

./build.sh -release - success
./build-managed.sh -release --allConfigurations - success
Now, when I execute the command: ./build-managed.sh -release --packages, it results in following type of errors:( It returned multiple error which are similar to the below one)

corefx/Tools/Packaging.targets(1150,5): error : File WindowsBase.dll is marked as inbox for framework netcoreapp2.1 but was missing from framework package Microsoft.Private.CoreFx.NETCoreApp/4.5.0-rtm-29307-0. Either add the file or update InboxOn entry in corefx/pkg/Microsoft.Private.PackageBaseline/packageIndex.json. This may be suppressed with with PermitMissingInbox suppression [corefx/pkg/Microsoft.Private.CoreFx.NETCoreApp/Microsoft.Private.CoreFx.NETCoreApp.pkgproj]

ASFAIK, When we build the stable packages, we run this target https://github.com/dotnet/corefx/blob/release/2.1/src/packages.builds#L41

Which adds the inboxOn Entry to the packageIndex.json

Was this page helpful?
0 / 5 - 0 ratings

Related issues

nalywa picture nalywa  路  3Comments

GitAntoinee picture GitAntoinee  路  3Comments

Timovzl picture Timovzl  路  3Comments

EgorBo picture EgorBo  路  3Comments

jkotas picture jkotas  路  3Comments