Skip to content

[release/11.0] JIT - Fix 'OperIs...' assert during forward substitution - #135069

Open
github-actions[bot] wants to merge 1 commit into
release/11.0from
backport/pr-134962-to-release/11.0
Open

github-actions[bot] wants to merge 1 commit into
release/11.0from
backport/pr-134962-to-release/11.0

Conversation

@github-actions

@github-actions github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Backport of #134962 to release/11.0

/cc @dhartglassMSFT

Customer Impact

  • Customer reported
  • Found internally

Assertion during forward substitution on 32 bit architectures. A type-normalizing cast tree can be passed to a method expecting an address expression, hitting an assert or incorrect code generation in release.
Found by fuzzing and jitstress-random pipeline.

Regression

  • Yes
  • No

Introduced by #133703, which was also backported to Net11, so backporting this follow-up fix as well.

Testing

Checked in a dedicated unit test from fuzzing. Verified unit test fails without the fix. Also verified that a failing jitstress-random run now passes with the fix. SPMI diffs showed 0 diffs. PR testing.

Risk

Low. The change caused no codegen diffs, and only affects 32 bit targets.

Assertion on 32 bit targets during forward substitution. The JIT could
pass a cast node to code expecting an address expression, because on 32b
an int32 is both the address type and the normalizing type for small
types in the IR.

Fixes #134818
Also verified that this fixes duplicated issue #134829 (jitstress-random
pipeline)

Bug introduced from #133703
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@github-actions github-actions Bot added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label Oct 1, 2026
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
See info in area-owners.md if you want to be subscribed.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant