Part Creation Policy Not Export¶
What does this mean ?¶
Classic MEF's PartCreationPolicy describes a discovered part's lifetime. The attribute alone does not publish an export or make a manually constructed object shared. Microsoft documents the supported creation policies.
What can happen ?¶
A developer may expect a service to be available when the composition catalog exposes no matching export. Retrieval can then fail, or an optional import may remain empty. This is primarily a discovery and configuration issue; the attribute mismatch does not establish a security vulnerability.
Recommendation¶
If this class is intended to export a contract, declare that export and include the part in the catalog. Otherwise remove a misleading unused creation policy. Check for member exports, inherited exports, or convention-based registration before assuming a missing class-level Export is a defect. Do not expose extra services simply to satisfy a rule.
Sample Code¶
These alternatives assume using System.ComponentModel.Composition; and public interface IClock { }. No other exports or registration conventions are present.
Incomplete for the intended service export:
[PartCreationPolicy(CreationPolicy.Shared)]
public class Clock : IClock { }
Explicit export with the intended lifetime:
[Export(typeof(IClock))]
[PartCreationPolicy(CreationPolicy.Shared)]
public class Clock : IClock { }
Regression test: build the actual catalog, retrieve IClock twice through the same container, and assert reference equality. A negative test with the export removed should demonstrate the missing contract. Also confirm that disposal follows the application's container lifetime.