Skip to content

Fix null vnStore dereference in optAssertionProp_HWIntrinsic - #134441

Merged
EgorBo merged 5 commits into
mainfrom
copilot/fix-null-vnstore-dereference
Sep 22, 2026
Merged

EgorBo merged 5 commits into
mainfrom
copilot/fix-null-vnstore-dereference

Conversation

Copilot AI commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

@azure-pipelines

azure-pipelines Bot commented Sep 22, 2026 •

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 5 pipeline(s).
11 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@EgorBo EgorBo added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label Sep 22, 2026
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
See info in area-owners.md if you want to be subscribed.

@EgorBo

EgorBo commented Sep 22, 2026

Copy link
Copy Markdown
Member

@copilot fix the bug

Copilot AI and others added 3 commits September 22, 2026 18:10
Co-authored-by: EgorBo <523221+EgorBo@users.noreply.github.com>
Co-authored-by: EgorBo <523221+EgorBo@users.noreply.github.com>
Co-authored-by: EgorBo <523221+EgorBo@users.noreply.github.com>

Copilot AI commented Sep 22, 2026

Copy link
Copy Markdown
Contributor Author

@copilot fix the bug

Fixed in ef7978d (comment tweak in 4ec109c).

optAssertionProp dispatched GT_HWINTRINSIC unconditionally, but optAssertionProp_HWIntrinsic reads comp->vnStore, which is still nullptr during local assertion prop in morph. Guarded with !optLocalAssertionProp, matching the neighbouring GT_ARR_LENGTH case, plus a precondition assert in the helper.

Reproduced on x64 rather than arm64 — for short/ushort base types without EVEX the importer leaves the node as NI_Vector_ExtractMostSignificantBits. With a temporary assert(comp->vnStore != nullptr) on a checked JIT:

Assertion failed 'comp->vnStore != nullptr' in 'Repro:Guarded(...)' during 'Morph - Global'

After the fix it's clean, and inverting the assert confirms the helper is still reached during the real Assertion prop phase — so the optimization itself is preserved. All 22 JIT/opt/InstructionCombining tests pass in default and DOTNET_EnableAVX512=0 configs.

I also audited the rest of that switch: every other helper already bails before touching vnStore during local AP, so GT_HWINTRINSIC was the only unguarded case.

I dropped the speculative test the previous session had added and did not add a regression test, per your standing preference — say the word if you'd like one.

@EgorBo
EgorBo marked this pull request as ready for review September 22, 2026 19:07
Copilot AI lite review requested due to automatic review settings September 22, 2026 19:07
@EgorBo EgorBo changed the title [WIP] Fix null vnStore dereference in optAssertionProp_HWIntrinsic Fix null vnStore dereference in optAssertionProp_HWIntrinsic Sep 22, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Add focused regression coverage for the local assertion-propagation case.

Review effort: Lite
Findings: None

What changed in this PR

Fixes a JIT null vnStore dereference by guarding hardware-intrinsic assertion propagation during local propagation.

Changes:

  • Adds a vnStore precondition assertion.
  • Skips the VN-dependent optimization during local assertion propagation.
File Summary
src/​coreclr/​jit/​assertionprop.cpp Guards VN-dependent hardware-intrinsic handling; focused regression coverage is still needed.

@EgorBo

EgorBo commented Sep 22, 2026

Copy link
Copy Markdown
Member

PTAL @tannergooding @dotnet/jit-contrib a quick fix to unblock the perf team

@EgorBo

EgorBo commented Sep 22, 2026

Copy link
Copy Markdown
Member

/ba-g unrelated LA64 build failure

@EgorBo
EgorBo enabled auto-merge (squash) September 22, 2026 22:32
@EgorBo
EgorBo merged commit 39af7c7 into main Sep 22, 2026
134 of 139 checks passed
@EgorBo
EgorBo deleted the copilot/fix-null-vnstore-dereference branch September 22, 2026 22:33
@LoopedBard3

Copy link
Copy Markdown
Member

Should this also be backported to release 11? I think we are currently using 11 feeds for opt so I will see if we can update to 12 to get this fix once it flows to VMR.

@LoopedBard3

Copy link
Copy Markdown
Member

After some more looking, I think this should also be backported to release/11.0 as the net12 feeds don't seem to have everything we will need before move optimization over yet, and based on last year, it was not until December that we did the first steps toward moving to running with net11's feeds.

@dotnet-milestone-bot dotnet-milestone-bot Bot added this to the 12.0-preview1 milestone Sep 23, 2026
@LoopedBard3

Copy link
Copy Markdown
Member

/backport to release/11.0

@github-actions

Copy link
Copy Markdown
Contributor

Started backporting to release/11.0 (link to workflow run)

JulieLeeMSFT pushed a commit that referenced this pull request Oct 1, 2026
…Intrinsic` (#134665)

Backport of #134441 to release/11.0

/cc @LoopedBard3 @Copilot

## Customer Impact

- [ ] Customer reported
- [x] Found internally

The JIT can crash while compiling SIMD `ExtractMostSignificantBits`
operations because local assertion propagation invokes an optimization
before its value-number store exists. This blocks Linux arm64 JIT PGO
training for .NET 11, preventing collection of fresh profiles for the
shipped arm64 JIT. The reported repro passes with the ordinary shipping
JIT. See #134435.

## Regression

- [x] Yes
- [ ] No

Introduced during .NET 11 development by #129688, which added the
hardware-intrinsic assertion-propagation helper and its unguarded call
during local assertion propagation.

## Testing

In the original PR, the failure was reproduced with a Checked x64 JIT
using a temporary `vnStore != nullptr` assertion, then verified fixed.
All 22 `JIT/opt/InstructionCombining` tests passed with default settings
and with `DOTNET_EnableAVX512=0`. Validation also confirmed that the
optimization still runs during global assertion propagation. No
dedicated regression test was added.

The issue was missed because the PGO pipeline had been pinned to an SDK
predating the regression, and the ordinary shipping JIT did not expose
the crash.

## Risk

Low. The change only adds a phase guard and a precondition assertion. It
skips the value-number-dependent optimization during local assertion
propagation, where value numbers are unavailable, matching the
neighboring array-length case. Global assertion propagation and its
optimization are unchanged.

Co-authored-by: Copilot <198982749+Copilot@users.noreply.github.com>
Co-authored-by: EgorBo <523221+EgorBo@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI

Projects

None yet

Development

Successfully merging this pull request may close these issues.

JIT: null vnStore dereference in optAssertionProp_HWIntrinsic during local assertion prop (arm64)

5 participants