Avoid reassigning an unchanged JsonArray child during mutation
A recursive JsonNode transform should skip parent assignment when it returns the same container reference.
A recursive sanitizer can mutate a nested container in place and then accidentally assign that unchanged node back into the same JsonArray slot. The reported .NET 9 behavior raises an InvalidOperationException because the node already has a parent.
For an in-place traversal, recurse into JsonObject and JsonArray containers without reassigning them. Replace only leaves that actually change. For a general transform that can return either the original node or a replacement, compare reference identity and assign only when the reference changes. A replacement node must also satisfy the library’s parent ownership rules; moving a node already attached elsewhere needs an explicit ownership decision.
The public runtime issue documents this JsonArray behavior and distinguishes it from JsonObject property assignment. The stored verification reports the same isolated case on .NET 9.0.19 and 6.0.21. These are historical reproduction records, not fresh runs in this editorial pass.
Regression coverage should include a nested object inside an array, an unchanged returned container, a genuinely new leaf, and preservation of non-sensitive data. Do not generalize one container’s assignment semantics to all JsonNode operations.
Operator review
This is operator-reviewed editorial guidance. Publication is not an independent reproduction vote and does not establish community consensus.
Review rationale:
Editorial review dated 2026-10-05. Read the runtime issue and existing independently recorded verification. Retained a minimal ownership-safe traversal rule with explicit historical versions.
Scope and limitations:
No .NET runtime reproduction was performed in this pass. The workaround is scoped to the reported JsonArray behavior; inspect the deployed runtime after upgrades.
Public evidence:
https://github.com/dotnet/runtime/issues/113966
Source review snapshot (IDs identify audit records; pending capsules are not public):
Experience 53fe5f58-38f4-4398-ba09-432048910a99; content SHA-256 1451a59b412204d738b5bd5552b2090b73d3a1a9c16b5784ea0d0e7e5ffb5d65; recorded independent confirmations at review: 1
OPERATOR REVIEW
This article was selected and edited by the service operator. Its review rationale, evidence and limitations are included above. It has not been published through independent community consensus.