From a5c906a47abe3dbb875ee10b2550c43131deedb4 Mon Sep 17 00:00:00 2001 From: Jan Vorlicek Date: Thu, 6 Aug 2026 17:14:08 +0200 Subject: [PATCH 1/2] Fix AV in gc_heap::init_heap_segment There is a bug in get_card_table_element_layout / get_card_table_commit_layout that results in the last page of the seg_mapping_table_element not being committed in case there was no mark_array_element. That happens when concurrent GC is disabled. The change fixes that by ensuring that every layout[element] is aligned according to its alignment requirements even when its size is 0. That allows the get_card_table_commit_layout to set commit end of the seg_mapping_table_element to include the last page even when the mark_array_element is not present. The problem happens because when a memory page is shared by multiple card table elements, the commit range for the first element on that page doesn't include that page and the next element is supposed to do the commit. Close #129681 --- src/coreclr/gc/card_table.cpp | 2 +- .../Github/Runtime_129681/Runtime_129681.cs | 53 +++++++++++++++++++ .../Runtime_129681/Runtime_129681.csproj | 24 +++++++++ 3 files changed, 78 insertions(+), 1 deletion(-) create mode 100644 src/tests/GC/Regressions/Github/Runtime_129681/Runtime_129681.cs create mode 100644 src/tests/GC/Regressions/Github/Runtime_129681/Runtime_129681.csproj diff --git a/src/coreclr/gc/card_table.cpp b/src/coreclr/gc/card_table.cpp index c2ad5e7a4d53cb..a8cc465e36f60c 100644 --- a/src/coreclr/gc/card_table.cpp +++ b/src/coreclr/gc/card_table.cpp @@ -221,7 +221,7 @@ void gc_heap::get_card_table_element_layout (uint8_t* start, uint8_t* end, size_ for (int element = brick_table_element; element <= total_bookkeeping_elements; element++) { layout[element] = layout[element - 1] + sizes[element - 1]; - if ((element != total_bookkeeping_elements) && (sizes[element] != 0)) + if (element != total_bookkeeping_elements) { layout[element] = ALIGN_UP(layout[element], alignment[element]); } diff --git a/src/tests/GC/Regressions/Github/Runtime_129681/Runtime_129681.cs b/src/tests/GC/Regressions/Github/Runtime_129681/Runtime_129681.cs new file mode 100644 index 00000000000000..d5637875356aad --- /dev/null +++ b/src/tests/GC/Regressions/Github/Runtime_129681/Runtime_129681.cs @@ -0,0 +1,53 @@ +// Licensed to the .NET Foundation under one or more agreements. +// The .NET Foundation licenses this file to you under the MIT license. + +using System; +using Xunit; + +public class Runtime_129681 +{ + private const int StorageLength = 8192; + + [Fact] + public static void TestEntryPoint() + { + object[] storage = new object[StorageLength]; + int index = 0; + + try + { + while (index < storage.Length) + { + storage[index++] = GC.AllocateArray(16 * 1024, pinned: true); + } + } + catch (OutOfMemoryException) + { + } + + try + { + while (index < storage.Length) + { + storage[index++] = GC.AllocateArray(256, pinned: true); + } + } + catch (OutOfMemoryException) + { + } + + try + { + while (index < storage.Length) + { + storage[index++] = GC.AllocateArray(1, pinned: true); + } + } + catch (OutOfMemoryException) + { + return; + } + + throw new Exception("The configured GC heap hard limit was not reached."); + } +} diff --git a/src/tests/GC/Regressions/Github/Runtime_129681/Runtime_129681.csproj b/src/tests/GC/Regressions/Github/Runtime_129681/Runtime_129681.csproj new file mode 100644 index 00000000000000..11a66b584276d2 --- /dev/null +++ b/src/tests/GC/Regressions/Github/Runtime_129681/Runtime_129681.csproj @@ -0,0 +1,24 @@ + + + true + 1 + + + + + + + + From 447238ac22a43e6651c321f26b6ae56f022ab461 Mon Sep 17 00:00:00 2001 From: Jan Vorlicek Date: Thu, 6 Aug 2026 19:55:40 +0200 Subject: [PATCH 2/2] Disable the test for Mono --- .../GC/Regressions/Github/Runtime_129681/Runtime_129681.csproj | 1 + 1 file changed, 1 insertion(+) diff --git a/src/tests/GC/Regressions/Github/Runtime_129681/Runtime_129681.csproj b/src/tests/GC/Regressions/Github/Runtime_129681/Runtime_129681.csproj index 11a66b584276d2..c9943ca7ecfbf0 100644 --- a/src/tests/GC/Regressions/Github/Runtime_129681/Runtime_129681.csproj +++ b/src/tests/GC/Regressions/Github/Runtime_129681/Runtime_129681.csproj @@ -2,6 +2,7 @@ true 1 + true