Skip to content

JIT: (bug) Failed isinst to an interface is treated as non-null, folding a GetType() compare and swallowing a NullReferenceException #134193

Description

@EgorBo

The result of an isinst helper call inherits the isNonNull property of its input, but a failed isinst returns null. The optimizer then drops the null check and constant-folds a type comparison, producing a silently wrong answer.

Minimal Repro

using System;
using System.Runtime.CompilerServices;

public class Program
{
    [MethodImpl(MethodImplOptions.NoInlining)]
    public static bool Test<T>()
    {
        object o = "hi";
        IComparable<T>? c = o as IComparable<T>; // null when T is not string
        return c!.GetType() == typeof(string);
    }

    public static void Main()
    {
        Console.WriteLine("Test<string>() = " + Test<string>());
        try { Console.WriteLine("Test<object>() = " + Test<object>()); }
        catch (NullReferenceException) { Console.WriteLine("Test<object>(): NullReferenceException (expected)"); }
    }
}

Expected

Test<string>() = True
Test<object>(): NullReferenceException (expected)

Actual

Test<string>() = True
Test<object>() = True

Notes

Correct under DOTNET_JITMinOpts=1, so this is an optimizer bug. Also repros on released .NET 10.0.12.
The shared-generic (__Canon) instantiation folds to mov eax, 1 / ret: the isinst helper call is dead-coded, the implicit null check is gone and the comparison is constant-folded.
Compiler::gtGetHelperCallClassHandle falls back to the value argument for CORINFO_HELP_ISINSTANCEOF* with an interface/unknown target and copies its isNonNull; gtFoldTypeCompare then trusts it.

Activity

  1. added this to the 12.0.0 milestone on Sep 18, 2026
  2. added
    area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI
    on Sep 18, 2026
  3. dotnet-policy-service commented on Sep 18, 2026

    @dotnet-policy-service
    Contributor

    Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
    See info in area-owners.md if you want to be subscribed.

  4. EgorBo commented on Sep 18, 2026

    @EgorBo
    MemberAuthor

    Affected SDK versions:

    • 8.0.425
    • 9.0.318
    • 10.0.401
    • 11.0.100-rc.2.26467.112
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI

    Type

    No type

    Projects

    No projects

      Milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions