[release/11.0] JIT: fix range assertions for bypassed phi blocks - #133481
Merged
JulieLeeMSFT merged 1 commit intoSep 9, 2026
Merged
Conversation
Backport dotnet#133268 to release/11.0. (cherry picked from commit b22e1b8) Copilot-Session: 56f763ef-1e54-421c-9e79-fe14ed2b906a Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
|
Azure Pipelines: Successfully started running 3 pipeline(s). 13 pipeline(s) were filtered out due to trigger conditions. There may be pipelines that require an authorized user to comment /azp run to run. |
Contributor
|
Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch |
Member
Author
|
PTAL @jakobbotsch backport of the fix to net11. |
jakobbotsch
approved these changes
Sep 9, 2026
Contributor
There was a problem hiding this comment.
🔵 Needs a closer look
The change affects JIT assertion/range reasoning (high blast radius) and should get a final human pass despite the small diff and added regression test.
Pull request overview
Backports a JIT range-checking fix to avoid incorporating potentially stale assertions from jump-threaded/bypassed blocks when computing local ranges, and adds a regression test to lock in the corrected behavior.
Changes:
- Adjusts
RangeCheck::ComputeRangeForLocalDefto stop merging the use-block incoming assertions into the computed definition range. - Ensures assertion merging happens at the use via
MergeAssertion(which is edge-aware forGT_PHI_ARG). - Adds a new JIT regression test case and registers it in
Regression_ro_2.csproj.
File summaries
| File | Description |
|---|---|
| src/coreclr/jit/rangecheck.h | Updates the ComputeRangeForLocalDef signature to remove the use-block parameter. |
| src/coreclr/jit/rangecheck.cpp | Removes merging of bbAssertionIn at the definition site and relies on MergeAssertion at the use site (edge-aware for phi args). |
| src/tests/JIT/Regression/JitBlue/Runtime_133267/Runtime_133267.cs | Adds regression coverage for the stale-assertion/jump-threading scenario. |
| src/tests/JIT/Regression/Regression_ro_2.csproj | Includes the new regression test source file in the test project. |
Review details
- Files reviewed: 4/4 changed files
- Comments generated: 0
- Review effort level: Lite
Member
|
/ba-g known issues. |
Member
|
Approved. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Backport of #133268 to release/11.0
Customer Impact
The JIT may merge range assertions from a block bypassed by jump threading, then optimize based on stale facts. Valid optimized code can take an impossible error path and throw unexpectedly.
Regression
Introduced during .NET 11 development. Reproduces on .NET 11 RC1 and does not reproduce on .NET 10.0.12.
Testing
Regression test added. Built the Checked JIT and verified the repro returns the expected value (
4) with the backported JIT.Risk
Low. The change stops merging potentially stale block assertions into local definitions and uses the existing edge-aware assertion merge at the use.