Skip to content

JIT - Fix 'OperIs...' assert during forward substitution - #134962

Merged
dhartglassMSFT merged 3 commits into
dotnet:mainfrom
dhartglassMSFT:134818
Oct 1, 2026
Merged

dhartglassMSFT merged 3 commits into
dotnet:mainfrom
dhartglassMSFT:134818

Conversation

@dhartglassMSFT

Copy link
Copy Markdown
Contributor

Assertion on 32 bit targets during forward substitution. The JIT could pass a cast node to code expecting an address expression, because on 32b an int32 is both the address type and the normalizing type for small types in the IR.

Fixes #134818
Also verified that this fixes duplicated issue #134829 (jitstress-random pipeline)

Bug introduced from #133703

@github-actions github-actions Bot added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label Sep 30, 2026
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 5 pipeline(s).
11 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
See info in area-owners.md if you want to be subscribed.

@dhartglassMSFT
dhartglassMSFT enabled auto-merge (squash) October 1, 2026 17:18
@dhartglassMSFT

Copy link
Copy Markdown
Contributor Author

Failures are #135031

@dhartglassMSFT

Copy link
Copy Markdown
Contributor Author

/ba-g known System net security tests issues

@dhartglassMSFT

Copy link
Copy Markdown
Contributor Author

/backport to release/11.0

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Started backporting to release/11.0 (link to workflow run)

@dotnet-milestone-bot dotnet-milestone-bot Bot added this to the 12.0-preview1 milestone Oct 2, 2026
JulieLeeMSFT pushed a commit that referenced this pull request Oct 2, 2026
…on (#135069)

Backport of #134962 to release/11.0

/cc @dhartglassMSFT

## Customer Impact

- [ ] Customer reported
- [x] Found internally

Assertion during forward substitution on 32 bit architectures. A
type-normalizing cast tree can be passed to a method expecting an
address expression, hitting an assert or incorrect code generation in
release.
Found by fuzzing and jitstress-random pipeline.

## Regression

- [x] Yes
- [ ] No

Introduced by #133703, which was also backported to Net11, so
backporting this follow-up fix as well.

## Testing

Checked in a dedicated unit test from fuzzing. Verified unit test fails
without the fix. Also verified that a failing jitstress-random run now
passes with the fix. SPMI diffs showed 0 diffs. PR testing.

## Risk

Low. The change caused no codegen diffs, and only affects 32 bit
targets.

Co-authored-by: dhartglassMSFT <dhartglass+github@microsoft.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI

Projects

None yet

Development

Successfully merging this pull request may close these issues.

JIT: Assert OperIs(GT_LCL_VAR, GT_LCL_FLD, GT_PHI_ARG, ... during 'Forward Substitution'

2 participants