10.0 release notes¶
InfoCarrier.Core 10.0 is a rewrite for Entity Framework Core 10. It shares its name and its idea with the 1.0 to 3.1 line and almost nothing else: the expression serializer, the wire format, the client/server split and the security model are all new code.
The last release of this line is 10.0.1, which fixes a query parameter reaching the database as
a literal instead of a parameter. Upgrading to it needs no code change.
The current release is 10.1.0. See 10.1 release notes, and read its "Queries that now
throw" section before you upgrade. Everything on this page still describes what 10.0 brought over
3.1.
The expression serializer is in-tree¶
Remote.Linq and Aqua are gone. The wire format, its type allowlist and its trimming behaviour are now this project's to reason about, and a client no longer carries their dependency tree.
A transport ships¶
3.1 shipped none, so every application wrote its own IInfoCarrierClient.
HttpInfoCarrierTransport is now in the box and app.MapInfoCarrier() is one line on the server.
For another protocol you still write one small class.
A stated security boundary¶
Your server executes an expression tree that arrived over the network, and 3.1 had nothing to say
about that. This release has a default-deny allowlist over node kinds, types and methods, loads no
assembly to satisfy a payload, blocks the reflection entry points that turn a resolved Type into a
call, and bounds the payload size before parsing. See Security.
Capabilities the EF Core 3.1 era did not have¶
EF Core 10 is where most of these come from. What is new here is that each one survives the round trip.
- Complex types, and JSON-mapped owned collections
ExecuteUpdateandExecuteDelete- Many-to-many without an explicit join entity
- Compiled models
- Savepoints, and a second client
DbContextthat can join a transaction the first one began.3.1had begin, commit and rollback only - Spatial types without data loss: Z and M ordinates survive the round trip, which
3.1's GeoJSON form did not preserve - Cancelling a query stops it on the server. The token reaches the
DbCommand, so the store cancels the command rather than the client alone abandoning its wait - Blazor WebAssembly, published trimmed
- Symbol packages and SourceLink on both packages, so you can step into the provider
Breaking changes¶
Your DbContext and your entity classes carry over unchanged. Everything around them moves, and
existing code will not compile.
3.1.1 |
10.0 |
|
|---|---|---|
| Target framework | netstandard2.0 |
net10.0 |
| EF Core | 3.1 | 10.0 |
| Dependencies | Remote.Linq and Aqua | none beyond Microsoft.EntityFrameworkCore |
| Packages | one | two: the provider, and the ASP.NET Core endpoint |
| Client wiring | UseInfoCarrierClient |
UseInfoCarrier |
| Namespaces | .Client, .Server, .Common |
InfoCarrier.Core, plus .Common and .ValueMapping |
IInfoCarrierClient |
sync and async pairs | async only; synchronous DbContext calls still work |
IInfoCarrierValueMapper |
TryMapToDynamicObject / TryMapFromDynamicObject |
TryMapToWire / TryMapFromWire |
| Server endpoint | a controller with a route per operation | app.MapInfoCarrier() |
The three public interfaces kept their names and changed their shapes on purpose, so an old implementation fails to compile rather than compiling and misbehaving. Upgrading from 3.1 has the before-and-after for each, and a checklist.
The client contract is async only, where 3.1 carried sync and async pairs. Synchronous
DbContext calls still work, and what they cost a UI thread is on
Configuring the client.
How it is verified¶
The provider inherits Microsoft's own EF Core specification suite:
The nine failures are known, classified, and gated in continuous integration so the number cannot grow unnoticed. Each of the nine is written up on the limitations page in terms of the code that triggers it. The 177 skips are EF Core's own, not suppressions added here. Skipping a test to make the suite green is forbidden in this repository.
Requirements¶
| Runtime | .NET 10 |
| EF Core | 10.0 |
| Server-side provider | any: SQL Server, PostgreSQL, SQLite, InMemory … |
| Client platforms | anywhere .NET 10 runs, including Blazor WebAssembly |
Trimming works and is verified on Blazor WebAssembly. Native AOT is not supported, because
remoting a query means building and compiling an expression tree at run time. UseInfoCarrier
carries [RequiresUnreferencedCode] and [RequiresDynamicCode], so a trimmed or AOT publish
says so at build time.
Authentication and authorization are out of scope and remain yours. No identity travels in the envelope, so authenticate the transport.
Credits¶
Built on Entity Framework Core and judged by its test suite. InfoCarrier.Core 1.0 to 3.1, by on/off it-solutions gmbh, proved the idea, and built it on Remote.Linq and aqua-core by Christof Senn.
This rewrite was carried out with Claude (Anthropic) as an engineering partner throughout.