Skip to content

[release/11.0] JIT: fix range assertions for bypassed phi blocks - #133481

Merged
JulieLeeMSFT merged 1 commit into
dotnet:release/11.0from
EgorBo:backport-133268-release-11.0
Sep 9, 2026
Merged

JulieLeeMSFT merged 1 commit into
dotnet:release/11.0from
EgorBo:backport-133268-release-11.0

Conversation

@EgorBo

@EgorBo EgorBo commented Sep 9, 2026

Copy link
Copy Markdown
Member

Backport of #133268 to release/11.0

Customer Impact

  • Customer reported
  • Found internally

The JIT may merge range assertions from a block bypassed by jump threading, then optimize based on stale facts. Valid optimized code can take an impossible error path and throw unexpectedly.

Regression

  • Yes
  • No

Introduced during .NET 11 development. Reproduces on .NET 11 RC1 and does not reproduce on .NET 10.0.12.

Testing

Regression test added. Built the Checked JIT and verified the repro returns the expected value (4) with the backported JIT.

Risk

Low. The change stops merging potentially stale block assertions into local definitions and uses the existing edge-aware assertion merge at the use.

Backport dotnet#133268 to release/11.0.

(cherry picked from commit b22e1b8)

Copilot-Session: 56f763ef-1e54-421c-9e79-fe14ed2b906a

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI lite review requested due to automatic review settings September 9, 2026 11:16
@EgorBo EgorBo added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label Sep 9, 2026
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
See info in area-owners.md if you want to be subscribed.

@EgorBo
EgorBo requested a review from jakobbotsch September 9, 2026 11:19
@EgorBo

EgorBo commented Sep 9, 2026

Copy link
Copy Markdown
Member Author

PTAL @jakobbotsch backport of the fix to net11.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

The change affects JIT assertion/range reasoning (high blast radius) and should get a final human pass despite the small diff and added regression test.

Pull request overview

Backports a JIT range-checking fix to avoid incorporating potentially stale assertions from jump-threaded/bypassed blocks when computing local ranges, and adds a regression test to lock in the corrected behavior.

Changes:

  • Adjusts RangeCheck::ComputeRangeForLocalDef to stop merging the use-block incoming assertions into the computed definition range.
  • Ensures assertion merging happens at the use via MergeAssertion (which is edge-aware for GT_PHI_ARG).
  • Adds a new JIT regression test case and registers it in Regression_ro_2.csproj.
File summaries
File Description
src/coreclr/jit/rangecheck.h Updates the ComputeRangeForLocalDef signature to remove the use-block parameter.
src/coreclr/jit/rangecheck.cpp Removes merging of bbAssertionIn at the definition site and relies on MergeAssertion at the use site (edge-aware for phi args).
src/tests/JIT/Regression/JitBlue/Runtime_133267/Runtime_133267.cs Adds regression coverage for the stale-assertion/jump-threading scenario.
src/tests/JIT/Regression/Regression_ro_2.csproj Includes the new regression test source file in the test project.
Review details
  • Files reviewed: 4/4 changed files
  • Comments generated: 0
  • Review effort level: Lite

@JulieLeeMSFT

Copy link
Copy Markdown
Member

/ba-g known issues.

@JulieLeeMSFT

Copy link
Copy Markdown
Member

Approved.

@JulieLeeMSFT
JulieLeeMSFT merged commit 8af40c5 into dotnet:release/11.0 Sep 9, 2026
126 of 131 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI Servicing-approved Approved for servicing release

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants