From d25b7a1e044610a4edc7d28f3191045756f3478f Mon Sep 17 00:00:00 2001 From: Copilot <198982749+Copilot@users.noreply.github.com> Date: Wed, 23 Sep 2026 00:33:01 +0200 Subject: [PATCH] Fix null `vnStore` dereference in `optAssertionProp_HWIntrinsic` (#134441) - [x] Confirm the assertion-propagation precondition and build a clean baseline. - [x] Guard the hardware-intrinsic optimization and add focused regression coverage. - [x] Run targeted builds/tests, formatting, and code/security review. - [x] Finalize the minimal fix. Resolves dotnet/runtime#134435 - Fixes #134435 --------- Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: EgorBo <523221+EgorBo@users.noreply.github.com> --- src/coreclr/jit/assertionprop.cpp | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/src/coreclr/jit/assertionprop.cpp b/src/coreclr/jit/assertionprop.cpp index 92ec475f090f03..d8c8af81be1685 100644 --- a/src/coreclr/jit/assertionprop.cpp +++ b/src/coreclr/jit/assertionprop.cpp @@ -90,6 +90,9 @@ static Range GetRange(Compiler* comp, GenTree* tree, BasicBlock* block, ASSERT_V // static void optAssertionProp_HWIntrinsic(Compiler* comp, GenTreeHWIntrinsic* tree) { + // Only valid during global assertion prop, this relies on value numbers. + assert(comp->vnStore != nullptr); + NamedIntrinsic intrinsic = tree->GetHWIntrinsicId(); if (intrinsic != NI_Vector_ExtractMostSignificantBits) @@ -5928,7 +5931,11 @@ GenTree* Compiler::optAssertionProp(ASSERT_VALARG_TP assertions, GenTree* tree, #if defined(FEATURE_HW_INTRINSICS) case GT_HWINTRINSIC: - optAssertionProp_HWIntrinsic(this, tree->AsHWIntrinsic()); + // This optimization needs value numbers, which are not available during local assertion prop. + if (!optLocalAssertionProp) + { + optAssertionProp_HWIntrinsic(this, tree->AsHWIntrinsic()); + } return nullptr; #endif // FEATURE_HW_INTRINSICS