npx skills add ...
npx skills add dotnet/skills --skill dotnet-pinvoke
Correctly call native (C/C++) libraries from .NET using P/Invoke and LibraryImport. Covers function signatures, string marshalling, memory lifetime, SafeHandle, and cross-platform patterns. USE FOR: writing new P/Invoke or LibraryImport declarations, reviewing or debugging existing native interop code, wrapping a C or C++ library for use in .NET, diagnosing crashes, memory leaks, or corruption at the managed/native boundary. DO NOT USE FOR: COM interop, C++/CLI mixed-mode assemblies, or pure managed code with no native dependencies.
npx skills add dotnet/skills --skill dotnet-pinvoke
Calling native code from .NET is powerful but unforgiving. Incorrect signatures, garbled strings, and leaked or freed memory are the most common sources of bugs — all can manifest as intermittent crashes, silent data corruption, or access violations far from the actual defect.
This skill covers both DllImport (available since .NET Framework 1.0) and LibraryImport (source-generated, .NET 7+). When targeting .NET Framework, always use DllImport. When targeting .NET 7+, prefer LibraryImport for new code. When native AOT is a requirement, LibraryImport is the only option.
[DllImport] or [LibraryImport] declaration from a C/C++ headerAccessViolationException, DllNotFoundException, or silent data corruption at the native boundaryDllImport declarations to LibraryImport for AOT/trimming compatibilityDllImport to LibraryImport unless the user asks or AOT/trimming is an explicit requirement.| Input | Required | Description |
|---|---|---|
| Native header or documentation | Yes | C/C++ function signatures, struct definitions, calling conventions |
| Target framework | Yes | Determines whether to use DllImport or LibraryImport |
| Target platforms | Recommended | Affects type sizes (long, size_t) and library naming |
| Memory ownership contract | Yes | Who allocates and who frees each buffer or handle |
Agent behavior: When documentation and native headers diverge, always trust the header. Online documentation (including official Win32 API docs) frequently omits or simplifies details about types, calling conventions, and struct layout that are critical for correct P/Invoke signatures.
| Aspect | DllImport | LibraryImport (.NET 7+) |
|---|---|---|
| Mechanism | Runtime marshalling | Source generator (compile-time) |
| AOT / Trim safe | No | Yes |
| String marshalling | CharSet enum | StringMarshalling enum |
| Error handling | SetLastError | SetLastPInvokeError |
| Availability | .NET Framework 1.0+ | .NET 7+ only |
The most dangerous mappings — these cause the majority of bugs:
| C / Win32 Type | .NET Type | Why |
|---|---|---|
long | CLong | 32-bit on Windows, 64-bit on 64-bit Unix. With LibraryImport, requires [assembly: DisableRuntimeMarshalling] |
size_t | nuint / UIntPtr | Pointer-sized. Use nuint on .NET 8+ and UIntPtr on earlier .NET. Never use ulong |
BOOL (Win32) | int | Not bool — Win32 BOOL is 4 bytes |
bool (C99) | [MarshalAs(UnmanagedType.U1)] bool | Must specify 1-byte marshal |
HANDLE, HWND | SafeHandle | Prefer over raw IntPtr |
LPWSTR / wchar_t* | string | UTF-16 on Windows (lowest cost for in strings). Avoid in cross-platform code — wchar_t width is compiler-defined (typically UTF-32 on non-Windows) |
LPSTR / char* | string | Must specify encoding (ANSI or UTF-8). Always requires marshalling cost for in parameters |
For the complete type mapping table, struct layout, and blittable type rules, see references/type-mapping.md.
❌ NEVER use
intorlongfor Clong— it's 32-bit on Windows, 64-bit on Unix. Always useCLong. ❌ NEVER useulongforsize_t— causes stack corruption on 32-bit. UsenuintorUIntPtr. ❌ NEVER useboolwithoutMarshalAs— the default marshal size is wrong.
Given a C header:
DllImport:
LibraryImport:
Calling conventions only need to be specified when targeting Windows x86 (32-bit), where Cdecl and StdCall differ. On x64, ARM, and ARM64, there is a single calling convention and the attribute is unnecessary.
Agent behavior: If you detect that Windows x86 is a target — through project properties (e.g., <PlatformTarget>x86</PlatformTarget>), runtime identifiers (e.g., win-x86), build scripts, comments, or developer instructions — flag this to the developer and recommend explicit calling conventions on all P/Invoke declarations.
If the managed method name differs from the native export name, specify EntryPoint to avoid EntryPointNotFoundException:
W (UTF-16) variant. The A variant needs a specific reason and explicit ANSI encoding.CharSet.Auto.StringBuilder for output buffers.❌ NEVER rely on
CharSet.Autoor omit string encoding — there is no safe default.
String lifetime warning: Marshalled strings are freed after the call returns. If native code stores the pointer (instead of copying), the lifetime must be manually managed. On Windows or .NET Framework, CoTaskMemAlloc/CoTaskMemFree is the first choice for cross-boundary ownership; on non-Windows targets, use NativeMemory APIs. The library may have its own allocator that must be used instead.
When memory crosses the boundary, exactly one side must own it — and both sides must agree.
❌ NEVER free with a mismatched allocator —
Marshal.FreeHGlobalonmalloc'd memory is heap corruption.
Model 1 — Caller allocates, caller frees (safest):
Model 2 — Callee allocates, caller frees (common in Win32):
Critical rule: Always free with the matching allocator. Never use Marshal.FreeHGlobal or Marshal.FreeCoTaskMem on malloc'd memory.
Model 3 — Handle-based (callee allocates, callee frees): Use SafeHandle (see Step 6).
Pinning managed objects — when native code stores the pointer or runs asynchronously:
Raw IntPtr leaks on exceptions and has no double-free protection. SafeHandle is non-negotiable.
Preferred (.NET 8+): UnmanagedCallersOnly — avoids delegates entirely, no GC lifetime risk:
The method must be static, must not throw exceptions back to native code, and can only use blittable parameter types.
Fallback (older TFMs or when instance state is needed): delegate with rooting
If native code stores the function pointer, the delegate must stay rooted for its entire lifetime. A collected delegate means a crash.
GC.KeepAlive for short-lived callbacks: When converting a delegate to a function pointer with Marshal.GetFunctionPointerForDelegate, the GC does not track the relationship between the pointer and the delegate. Use GC.KeepAlive to prevent collection before the native call completes:
Use NativeLibrary.SetDllImportResolver for complex scenarios, or conditional compilation for simple cases. Use CLong/CULong for C long/unsigned long. Note: CLong/CULong with LibraryImport requires [assembly: DisableRuntimeMarshalling].
For codebases targeting .NET 7+, migrating provides AOT compatibility and trimming safety.
partial to the containing class and make the method static partial[DllImport] with [LibraryImport]CharSet with StringMarshallingSetLastError = true with SetLastPInvokeError = trueCallingConvention unless targeting Windows x86SYSLIB1054–SYSLIB1057 analyzer warningsEnable the interop analyzers:
For Win32 P/Invoke, prefer Microsoft.Windows.CsWin32 over hand-written signatures. It source-generates correct declarations from metadata. Add a NativeMethods.txt listing the APIs you need:
For WinRT interop, use Microsoft.Windows.CsWinRT to generate .NET projections from .winmd files.
For binding Objective-C libraries (macOS/iOS), use Objective Sharpie to generate initial P/Invoke and binding definitions from Objective-C headers.
CharSet.AutoSafeHandle used for all native handles (no raw IntPtr escaping the interop layer)SetLastError/SetLastPInvokeError set for APIs that use OS error codesCLong/CULong used for C long/unsigned long in cross-platform codeCLong/CULong with LibraryImport, [assembly: DisableRuntimeMarshalling] is appliedbool without explicit MarshalAs — always specify UnmanagedType.Bool (4-byte) or UnmanagedType.U1 (1-byte) to ensure normalization across the language boundary.SYSLIB1054–SYSLIB1057 warnings:
Marshal.SizeOf<T>() equals the native sizeof