Skip to content

[release/11.0] JIT: guard overflow in loop cloning offset limits - #134350

Merged
JulieLeeMSFT merged 1 commit into
release/11.0from
backport/pr-133834-to-release/11.0
Sep 21, 2026
Merged

JulieLeeMSFT merged 1 commit into
release/11.0from
backport/pr-133834-to-release/11.0

Conversation

@github-actions

@github-actions github-actions Bot commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Backport of #133834 to release/11.0

/cc @AndyAyersMS

Customer Impact

  • Customer reported
  • Found internally

Loop cloning can incorrectly remove array bounds checks when a positive arr.Length + offset loop limit overflows to a negative value. Safe C# can then perform an out-of-bounds read and terminate with a native access violation instead of throwing IndexOutOfRangeException. This reproduces on .NET 11 RC1 and RC2; .NET 10 is correct. See #133823.

Regression

  • Yes
  • No

Introduced during the .NET 11 cycle by #129309, which extended loop cloning to handle span/stride and constant-offset limits.

Testing

Added regression coverage for decreasing loops with overflowing positive offsets. The test fails before the fix and verifies that the required bounds exception is preserved after the fix. The original PR also passed JIT CI; Mono exclusions were added because this is CoreCLR-specific loop-cloning coverage.

Risk

Low. The change is localized to loop-cloning condition derivation. It rejects offsets that cannot be represented safely instead of selecting the unchecked fast clone, so the fallback retains the existing bounds checks.

Positive array length offsets can wrap negative and let the fast clone
run
without bounds checks. Guard offsets that can overflow and add
regression
coverage for decreasing loops.

Fixes #133823

> [!NOTE]
> This pull request description was generated with GitHub Copilot.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 336fb408-8580-4f7b-b3e6-087280a6294a
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@github-actions github-actions Bot added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label Sep 21, 2026
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
See info in area-owners.md if you want to be subscribed.

@AndyAyersMS
AndyAyersMS requested a review from a team September 21, 2026 18:56
@AndyAyersMS

Copy link
Copy Markdown
Member

@dotnet/jit-contrib ptal

@AndyAyersMS AndyAyersMS added the Servicing-consider Issue for next servicing release review label Sep 21, 2026
@JulieLeeMSFT JulieLeeMSFT added Servicing-approved Approved for servicing release and removed Servicing-consider Issue for next servicing release review labels Sep 21, 2026
@JulieLeeMSFT JulieLeeMSFT added this to the 11.0.0 milestone Sep 21, 2026
@JulieLeeMSFT
JulieLeeMSFT merged commit 6040288 into release/11.0 Sep 21, 2026
127 of 131 checks passed
@JulieLeeMSFT
JulieLeeMSFT deleted the backport/pr-133834-to-release/11.0 branch September 21, 2026 21:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI Servicing-approved Approved for servicing release

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants