Skip to content

JIT: preserve local access type in relop assertion propagation - #134185

Merged
EgorBo merged 1 commit into
dotnet:mainfrom
EgorBo:fix-jit-133859-local-type
Oct 2, 2026
Merged

EgorBo merged 1 commit into
dotnet:mainfrom
EgorBo:fix-jit-133859-local-type

Conversation

@EgorBo

@EgorBo EgorBo commented Sep 18, 2026

Copy link
Copy Markdown
Member

Copy the replacement local's node type along with its local and SSA numbers. This allows the resulting self-comparison to fold instead of retaining a truncated load of an int local.

Fixes #133859.

Copilot AI lite review requested due to automatic review settings September 18, 2026 12:44
@github-actions github-actions Bot added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label Sep 18, 2026
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 5 pipeline(s).
11 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
See info in area-owners.md if you want to be subscribed.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The fix and regression coverage address the reported JIT miscompilation.

Pull request overview

Fixes JIT assertion propagation by preserving the replacement local’s access type, preventing incorrect narrow loads and comparisons.

Changes:

  • Preserves propagated local node types.
  • Adds regression coverage for mismatched byte/int comparisons.
File summaries
File Description
src/coreclr/jit/assertionprop.cpp Preserves the replacement local access type during relop propagation.
src/tests/JIT/Regression_ro_2/Runtime_133859.cs Adds regression tests for issue #133859.
Review details
  • Files reviewed: 2/2 changed files
  • Comments generated: 0
  • Review effort level: Lite

@EgorBo

EgorBo commented Sep 18, 2026

Copy link
Copy Markdown
Member Author

PTAL @jakobbotsch, no diffs

@EgorBo

EgorBo commented Sep 23, 2026

Copy link
Copy Markdown
Member Author

Ping @jakobbotsch

@jakobbotsch

Copy link
Copy Markdown
Member

What is the propagation that is happening here? Not totally sure that we would expect any propagation here in the first place given that it probably drops the normalize-on-store truncation that was happening implicitly?

Simplify optAssertionPropGlobal_RelOp: inline optGlobalAssertionIsEqualOrNotEqual and fold
a matching EQ/NE assertion straight into a constant instead of bashing op1 to a constant /
retargeting its local and re-morphing. The local-retargeting path kept op1's small type,
producing a truncated compare (dotnet#133859). Also drop the op1 side-effect/shape restrictions.

Fixes dotnet#133859.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: c20aa474-545f-4b8c-8143-b50e15f04910
@EgorBo

EgorBo commented Oct 2, 2026 •

Copy link
Copy Markdown
Member Author

@jakobbotsch I think it was actually correct, but I decided to just remove a bunch of code and inline optGlobalAssertionIsEqualOrNotEqual there. it also has some diffs because I removed unnecessary guards

    // Bail out if op1 is not side effect free. Note we'll be bashing it below, unlike op2.
    if ((op1->gtFlags & GTF_SIDE_EFFECT) != 0)
    {
        return nullptr;
    }

    if (!op1->OperIs(GT_LCL_VAR, GT_IND))
    {
        return nullptr;
    }

since we only work with VN there (global AP) and I deleted the path that relied on the o1 being side-effect free.

@jakobbotsch jakobbotsch left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice cleanup!

@EgorBo
EgorBo merged commit 779bd79 into dotnet:main Oct 2, 2026
142 of 144 checks passed
@EgorBo
EgorBo deleted the fix-jit-133859-local-type branch October 2, 2026 15:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI

Projects

None yet

Development

Successfully merging this pull request may close these issues.

JIT: (bug) assertion prop retargets a small-typed LCL_VAR to an int local, emitting a truncated compare (wrong result)

4 participants