Development About 2 min read

C# protocol development

In C#, check cancellation, asynchronous lifetimes and typed data handling. Define reconnect behaviour and how the application represents uncertain operation results.

Sources and scopeSource record 25 August 2026

Technical source record: 25 August 2026. Check the linked documentation for current product requirements.

Inherited check dated 10 September 2026. Supporting evidence for this inherited check has not been independently confirmed.

Recorded scope: The .NET 10, 9 and 8 support dates were checked against Microsoft's policy. The supplied C# example has not been executed locally; its documented test command requires .NET 10.

C# and .NET integration guidance; exact patch, package, OS, vendor SDK, protocol, and product compatibility is environment specific.

Verification and testing

Overview#

C# is the primary reference language for enterprise VMS/PACS SDKs and Windows hosted integrations. The reviewed baseline is .NET 10 LTS with C# 14; vendor SDK requirements may mandate another supported target DOTNET.

Support dates#

Microsoft lists .NET 10 as LTS through 14 November 2028. Support for both .NET 8 and .NET 9 ends on 10 November 2026. Supported systems need the current patch within their chosen release. A vendor SDK can impose additional framework, operating system and processor requirements.1

Baseline#

  • Enable nullable reference types, analyzer warnings and checked handling where numeric overflow matters.
  • Make public protocol/domain models immutable where practical.
  • Validate deserialized JSON/XML and SDK objects at runtime; annotations don't enforce wire input.
  • Reuse HttpClient through an appropriate handler/factory lifecycle; don't create a new client for each request.
  • Propagate CancellationToken through all I/O and waiting paths.
  • Bound response bodies, streams, queues and parallel device work.

TLS and authentication#

Use platform hostname and chain validation with an explicitly managed trust store. Never publish callbacks that return true for every certificate. Separate OAuth/token acquisition, Windows/AD authentication, client certificates and vendor SDK session credentials; redact them from diagnostic context.

Async and events#

Avoid sync over async and unobserved fire and forget tasks. Unsubscribe event handlers and dispose subscriptions deterministically. Serialize state changes per device/resource when ordering matters; bound channels and define full behaviour.

Native and media SDKs#

Wrap native handles in SafeHandle or vendor recommended deterministic lifetime constructs. Control callback lifetime, thread affinity and buffer ownership. Copy or pin media buffers only under documented ownership rules, and avoid logging frame content.

Services and plugins#

Use unique service identity, least privileges and explicit shutdown. Keep plugin boundaries distrustful: version check assemblies/packages, isolate configuration, and prevent a vendor callback from directly authorizing a physical command.

Sources#

  1. Microsoft, .NET support policy. ↩