[release/11.0] JIT - Fix 'OperIs...' assert during forward substitution - #135069
Open
github-actions[bot] wants to merge 1 commit into
Open
github-actions[bot] wants to merge 1 commit into
github-actions[bot] wants to merge 1 commit into
Conversation
Assertion on 32 bit targets during forward substitution. The JIT could pass a cast node to code expecting an address expression, because on 32b an int32 is both the address type and the normalizing type for small types in the IR. Fixes #134818 Also verified that this fixes duplicated issue #134829 (jitstress-random pipeline) Bug introduced from #133703
|
Azure Pipelines: Successfully started running 3 pipeline(s). 13 pipeline(s) were filtered out due to trigger conditions. There may be pipelines that require an authorized user to comment /azp run to run. |
Contributor
|
Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Backport of #134962 to release/11.0
/cc @dhartglassMSFT
Customer Impact
Assertion during forward substitution on 32 bit architectures. A type-normalizing cast tree can be passed to a method expecting an address expression, hitting an assert or incorrect code generation in release.
Found by fuzzing and jitstress-random pipeline.
Regression
Introduced by #133703, which was also backported to Net11, so backporting this follow-up fix as well.
Testing
Checked in a dedicated unit test from fuzzing. Verified unit test fails without the fix. Also verified that a failing jitstress-random run now passes with the fix. SPMI diffs showed 0 diffs. PR testing.
Risk
Low. The change caused no codegen diffs, and only affects 32 bit targets.