Add more checking to GenTreeArrAddr::ParseArrayAddress() - #100327

Merged
BruceForstall merged 1 commit into
dotnet:mainfrom
BruceForstall:AddMoreCheckingToParseArrayAddress
Mar 29, 2024
Merged

Add more checking to GenTreeArrAddr::ParseArrayAddress()#100327
BruceForstall merged 1 commit into
dotnet:mainfrom
BruceForstall:AddMoreCheckingToParseArrayAddress

Conversation

@BruceForstall

Copy link
Copy Markdown
Contributor

If the ARR_ADDR node doesn't make sense, namely if the array offset does not appear to be in the array, then bail.

@ghostghost added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label Mar 27, 2024
@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

Extracted from #94250

@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

There are a few diffs in ILGEN tests that construct array index expressions with negative indices.

@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

With JitOptRepeat we end up with the following situation.

We hit the assert:

Assertion failed '(constIndexOffset % elemSize) == 0'

(e.g.,

System.Runtime.CompilerServices.PoolingAsyncValueTaskMethodBuilder`1+StateMachineBox`1[int,System.IO.Stream+<ReadAtLeastAsyncCore>d__46]:System.Threading.Tasks.Sources.IValueTaskSource.GetResult(short):this'

We start with:

[000895] -----O----- \--* ARR_ADDR byref Internal.PaddedReference[]
[000894] ----------- \--* ADD byref
[000885] ----------- +--* LCL_VAR ref V56 tmp54
[000893] ----------- \--* ADD long
[000891] ----------- +--* MUL long
[000889] ---------U- | +--* CAST long <- uint
[000886] ----------- | | \--* LCL_VAR int V14 tmp12
[000890] -------N--- | \--* CNS_INT long 128
[000892] ----------- \--* CNS_INT long 16

After optimization, this becomes:

N018 ( 2, 2) [000895] -A---O----- \--* ARR_ADDR byref Internal.PaddedReference[] $641
N017 ( 2, 2) [000894] -A-----N--- \--* ADD byref $199
N007 ( 1, 1) [000885] ----------- +--* LCL_VAR ref V56 tmp54 u:1 (last use) $84
N016 ( 7, 10) [000995] -A--------- \--* COMMA long $687
N014 ( 6, 9) [000993] DA--------- +--* STORE_LCL_VAR long V62 cse3 d:1 $VN.Void
N013 ( 6, 9) [000893] ----------- | \--* ADD long $687
N011 ( 4, 6) [000891] ----------- | +--* LSH long $686
N009 ( 2, 3) [000889] ---------U- | | +--* CAST long <- uint $685
N008 ( 1, 1) [000886] ----------- | | | \--* LCL_VAR int V14 tmp12 u:1 $1f5
N010 ( 1, 2) [000890] -------N--- | | \--* CNS_INT long 7 $14e
N012 ( 1, 2) [000892] ----------- | \--* CNS_INT long 16 $146
N015 ( 1, 1) [000994] ----------- \--* LCL_VAR long V62 cse3 u:1 $687

On the next iteration of JitOptRepeat, the CSE injected COMMA is not parseable by GenTreeArrAddr::ParseArrayAddress. We could add tunnel through for this CSE def.

However, it might be harder for the CSE use. In that case, we start with something similar:

[000941] -----O----- \--* ARR_ADDR byref Internal.PaddedReference[]
[000940] ----------- \--* ADD byref
[000931] ----------- +--* LCL_VAR ref V57 tmp55
[000939] ----------- \--* ADD long
[000937] ----------- +--* MUL long
[000935] ---------U- | +--* CAST long <- uint
[000932] ----------- | | \--* LCL_VAR int V14 tmp12 (last use)
[000936] -------N--- | \--* CNS_INT long 128
[000938] ----------- \--* CNS_INT long 16

and, after CSE, have:

N006 ( 2, 2) [000941] -----O-N--- \--* ARR_ADDR byref Internal.PaddedReference[]
N005 ( 2, 2) [000940] -------N--- \--* ADD byref
N003 ( 1, 1) [000931] ----------- +--* LCL_VAR ref V57 tmp55 u:1 (last use)
N004 ( 1, 1) [000996] ----------- \--* LCL_VAR long V62 cse3 u:1 (last use)

This would require parsing the CSE value number for [000996], not the tree.

Since this is VN iteration #2, I'm not sure we lose anything by assigning the ARR_ADDR a new, unique value number when we fail to parse the tree: we've already optimized it once.

@BruceForstall
BruceForstallforce-pushed the AddMoreCheckingToParseArrayAddress branch from f41383c to c5824f8CompareMarch 28, 2024 05:59
@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

@jakobbotsch PTAL
cc @dotnet/jit-contrib

@BruceForstall

BruceForstall commented Mar 28, 2024

Copy link
Copy Markdown
ContributorAuthor

It's interesting that there are diffs on x86, apparently because the offset of data of an array from the base of an array is 8 (it is 16 on 64-bit). This happens to be the same size as a pointer and a double. I see cases where we start with (loc5 - 1) * 8 + 8 which morph transforms to loc5 * 8 - 8 + 8 => loc5 * 8, thus we no longer have an "offset" into the array data (and at runtime loc5 better be > 0, which is checked by the bounds check).

The result is that we give the ARR_ADDR a new, unique VN and we lose some CSEs.

If the ARR_ADDR node doesn't make sense, namely if the array
offset does not appear to be in the array, then bail.
@BruceForstall
BruceForstallforce-pushed the AddMoreCheckingToParseArrayAddress branch from c5824f8 to fc5333dCompareMarch 28, 2024 20:51
@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

GitHub is confused; all the tests passed.

Diffsas described

BruceForstall added a commit to BruceForstall/runtime that referenced this pull request Mar 29, 2024
@BruceForstall
BruceForstall merged commit 0323995 into dotnet:mainMar 29, 2024
@BruceForstall
BruceForstall deleted the AddMoreCheckingToParseArrayAddress branch March 29, 2024 17:35
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Apr 29, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@BruceForstall@AndyAyersMS
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Add more checking to GenTreeArrAddr::ParseArrayAddress() - #100327

Merged
BruceForstall merged 1 commit into
dotnet:mainfrom
BruceForstall:AddMoreCheckingToParseArrayAddress
Mar 29, 2024
Merged

Add more checking to GenTreeArrAddr::ParseArrayAddress()#100327
BruceForstall merged 1 commit into
dotnet:mainfrom
BruceForstall:AddMoreCheckingToParseArrayAddress

Conversation

@BruceForstall

Copy link
Copy Markdown
Contributor

If the ARR_ADDR node doesn't make sense, namely if the array offset does not appear to be in the array, then bail.

@ghostghost added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label Mar 27, 2024
@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

Extracted from #94250

@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

There are a few diffs in ILGEN tests that construct array index expressions with negative indices.

@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

With JitOptRepeat we end up with the following situation.

We hit the assert:

Assertion failed '(constIndexOffset % elemSize) == 0'

(e.g.,

System.Runtime.CompilerServices.PoolingAsyncValueTaskMethodBuilder`1+StateMachineBox`1[int,System.IO.Stream+<ReadAtLeastAsyncCore>d__46]:System.Threading.Tasks.Sources.IValueTaskSource.GetResult(short):this'

We start with:

[000895] -----O----- \--* ARR_ADDR byref Internal.PaddedReference[]
[000894] ----------- \--* ADD byref
[000885] ----------- +--* LCL_VAR ref V56 tmp54
[000893] ----------- \--* ADD long
[000891] ----------- +--* MUL long
[000889] ---------U- | +--* CAST long <- uint
[000886] ----------- | | \--* LCL_VAR int V14 tmp12
[000890] -------N--- | \--* CNS_INT long 128
[000892] ----------- \--* CNS_INT long 16

After optimization, this becomes:

N018 ( 2, 2) [000895] -A---O----- \--* ARR_ADDR byref Internal.PaddedReference[] $641
N017 ( 2, 2) [000894] -A-----N--- \--* ADD byref $199
N007 ( 1, 1) [000885] ----------- +--* LCL_VAR ref V56 tmp54 u:1 (last use) $84
N016 ( 7, 10) [000995] -A--------- \--* COMMA long $687
N014 ( 6, 9) [000993] DA--------- +--* STORE_LCL_VAR long V62 cse3 d:1 $VN.Void
N013 ( 6, 9) [000893] ----------- | \--* ADD long $687
N011 ( 4, 6) [000891] ----------- | +--* LSH long $686
N009 ( 2, 3) [000889] ---------U- | | +--* CAST long <- uint $685
N008 ( 1, 1) [000886] ----------- | | | \--* LCL_VAR int V14 tmp12 u:1 $1f5
N010 ( 1, 2) [000890] -------N--- | | \--* CNS_INT long 7 $14e
N012 ( 1, 2) [000892] ----------- | \--* CNS_INT long 16 $146
N015 ( 1, 1) [000994] ----------- \--* LCL_VAR long V62 cse3 u:1 $687

On the next iteration of JitOptRepeat, the CSE injected COMMA is not parseable by GenTreeArrAddr::ParseArrayAddress. We could add tunnel through for this CSE def.

However, it might be harder for the CSE use. In that case, we start with something similar:

[000941] -----O----- \--* ARR_ADDR byref Internal.PaddedReference[]
[000940] ----------- \--* ADD byref
[000931] ----------- +--* LCL_VAR ref V57 tmp55
[000939] ----------- \--* ADD long
[000937] ----------- +--* MUL long
[000935] ---------U- | +--* CAST long <- uint
[000932] ----------- | | \--* LCL_VAR int V14 tmp12 (last use)
[000936] -------N--- | \--* CNS_INT long 128
[000938] ----------- \--* CNS_INT long 16

and, after CSE, have:

N006 ( 2, 2) [000941] -----O-N--- \--* ARR_ADDR byref Internal.PaddedReference[]
N005 ( 2, 2) [000940] -------N--- \--* ADD byref
N003 ( 1, 1) [000931] ----------- +--* LCL_VAR ref V57 tmp55 u:1 (last use)
N004 ( 1, 1) [000996] ----------- \--* LCL_VAR long V62 cse3 u:1 (last use)

This would require parsing the CSE value number for [000996], not the tree.

Since this is VN iteration #2, I'm not sure we lose anything by assigning the ARR_ADDR a new, unique value number when we fail to parse the tree: we've already optimized it once.

@BruceForstall
BruceForstallforce-pushed the AddMoreCheckingToParseArrayAddress branch from f41383c to c5824f8CompareMarch 28, 2024 05:59
@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

@jakobbotsch PTAL
cc @dotnet/jit-contrib

@BruceForstall

BruceForstall commented Mar 28, 2024

Copy link
Copy Markdown
ContributorAuthor

It's interesting that there are diffs on x86, apparently because the offset of data of an array from the base of an array is 8 (it is 16 on 64-bit). This happens to be the same size as a pointer and a double. I see cases where we start with (loc5 - 1) * 8 + 8 which morph transforms to loc5 * 8 - 8 + 8 => loc5 * 8, thus we no longer have an "offset" into the array data (and at runtime loc5 better be > 0, which is checked by the bounds check).

The result is that we give the ARR_ADDR a new, unique VN and we lose some CSEs.

If the ARR_ADDR node doesn't make sense, namely if the array
offset does not appear to be in the array, then bail.
@BruceForstall
BruceForstallforce-pushed the AddMoreCheckingToParseArrayAddress branch from c5824f8 to fc5333dCompareMarch 28, 2024 20:51
@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

GitHub is confused; all the tests passed.

Diffsas described

BruceForstall added a commit to BruceForstall/runtime that referenced this pull request Mar 29, 2024
@BruceForstall
BruceForstall merged commit 0323995 into dotnet:mainMar 29, 2024
@BruceForstall
BruceForstall deleted the AddMoreCheckingToParseArrayAddress branch March 29, 2024 17:35
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Apr 29, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@BruceForstall@AndyAyersMS
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add more checking to GenTreeArrAddr::ParseArrayAddress() - #100327

Merged
BruceForstall merged 1 commit into
dotnet:mainfrom
BruceForstall:AddMoreCheckingToParseArrayAddress
Mar 29, 2024
Merged

Add more checking to GenTreeArrAddr::ParseArrayAddress()#100327
BruceForstall merged 1 commit into
dotnet:mainfrom
BruceForstall:AddMoreCheckingToParseArrayAddress

Conversation

@BruceForstall

Copy link
Copy Markdown
Contributor

If the ARR_ADDR node doesn't make sense, namely if the array offset does not appear to be in the array, then bail.

@ghostghost added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label Mar 27, 2024
@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

Extracted from #94250

@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

There are a few diffs in ILGEN tests that construct array index expressions with negative indices.

@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

With JitOptRepeat we end up with the following situation.

We hit the assert:

Assertion failed '(constIndexOffset % elemSize) == 0'

(e.g.,

System.Runtime.CompilerServices.PoolingAsyncValueTaskMethodBuilder`1+StateMachineBox`1[int,System.IO.Stream+<ReadAtLeastAsyncCore>d__46]:System.Threading.Tasks.Sources.IValueTaskSource.GetResult(short):this'

We start with:

[000895] -----O----- \--* ARR_ADDR byref Internal.PaddedReference[]
[000894] ----------- \--* ADD byref
[000885] ----------- +--* LCL_VAR ref V56 tmp54
[000893] ----------- \--* ADD long
[000891] ----------- +--* MUL long
[000889] ---------U- | +--* CAST long <- uint
[000886] ----------- | | \--* LCL_VAR int V14 tmp12
[000890] -------N--- | \--* CNS_INT long 128
[000892] ----------- \--* CNS_INT long 16

After optimization, this becomes:

N018 ( 2, 2) [000895] -A---O----- \--* ARR_ADDR byref Internal.PaddedReference[] $641
N017 ( 2, 2) [000894] -A-----N--- \--* ADD byref $199
N007 ( 1, 1) [000885] ----------- +--* LCL_VAR ref V56 tmp54 u:1 (last use) $84
N016 ( 7, 10) [000995] -A--------- \--* COMMA long $687
N014 ( 6, 9) [000993] DA--------- +--* STORE_LCL_VAR long V62 cse3 d:1 $VN.Void
N013 ( 6, 9) [000893] ----------- | \--* ADD long $687
N011 ( 4, 6) [000891] ----------- | +--* LSH long $686
N009 ( 2, 3) [000889] ---------U- | | +--* CAST long <- uint $685
N008 ( 1, 1) [000886] ----------- | | | \--* LCL_VAR int V14 tmp12 u:1 $1f5
N010 ( 1, 2) [000890] -------N--- | | \--* CNS_INT long 7 $14e
N012 ( 1, 2) [000892] ----------- | \--* CNS_INT long 16 $146
N015 ( 1, 1) [000994] ----------- \--* LCL_VAR long V62 cse3 u:1 $687

On the next iteration of JitOptRepeat, the CSE injected COMMA is not parseable by GenTreeArrAddr::ParseArrayAddress. We could add tunnel through for this CSE def.

However, it might be harder for the CSE use. In that case, we start with something similar:

[000941] -----O----- \--* ARR_ADDR byref Internal.PaddedReference[]
[000940] ----------- \--* ADD byref
[000931] ----------- +--* LCL_VAR ref V57 tmp55
[000939] ----------- \--* ADD long
[000937] ----------- +--* MUL long
[000935] ---------U- | +--* CAST long <- uint
[000932] ----------- | | \--* LCL_VAR int V14 tmp12 (last use)
[000936] -------N--- | \--* CNS_INT long 128
[000938] ----------- \--* CNS_INT long 16

and, after CSE, have:

N006 ( 2, 2) [000941] -----O-N--- \--* ARR_ADDR byref Internal.PaddedReference[]
N005 ( 2, 2) [000940] -------N--- \--* ADD byref
N003 ( 1, 1) [000931] ----------- +--* LCL_VAR ref V57 tmp55 u:1 (last use)
N004 ( 1, 1) [000996] ----------- \--* LCL_VAR long V62 cse3 u:1 (last use)

This would require parsing the CSE value number for [000996], not the tree.

Since this is VN iteration #2, I'm not sure we lose anything by assigning the ARR_ADDR a new, unique value number when we fail to parse the tree: we've already optimized it once.

@BruceForstall
BruceForstallforce-pushed the AddMoreCheckingToParseArrayAddress branch from f41383c to c5824f8CompareMarch 28, 2024 05:59
@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

@jakobbotsch PTAL
cc @dotnet/jit-contrib

@BruceForstall

BruceForstall commented Mar 28, 2024

Copy link
Copy Markdown
ContributorAuthor

It's interesting that there are diffs on x86, apparently because the offset of data of an array from the base of an array is 8 (it is 16 on 64-bit). This happens to be the same size as a pointer and a double. I see cases where we start with (loc5 - 1) * 8 + 8 which morph transforms to loc5 * 8 - 8 + 8 => loc5 * 8, thus we no longer have an "offset" into the array data (and at runtime loc5 better be > 0, which is checked by the bounds check).

The result is that we give the ARR_ADDR a new, unique VN and we lose some CSEs.

If the ARR_ADDR node doesn't make sense, namely if the array
offset does not appear to be in the array, then bail.
@BruceForstall
BruceForstallforce-pushed the AddMoreCheckingToParseArrayAddress branch from c5824f8 to fc5333dCompareMarch 28, 2024 20:51
@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

GitHub is confused; all the tests passed.

Diffsas described

BruceForstall added a commit to BruceForstall/runtime that referenced this pull request Mar 29, 2024
@BruceForstall
BruceForstall merged commit 0323995 into dotnet:mainMar 29, 2024
@BruceForstall
BruceForstall deleted the AddMoreCheckingToParseArrayAddress branch March 29, 2024 17:35
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Apr 29, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@BruceForstall@AndyAyersMS
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add more checking to GenTreeArrAddr::ParseArrayAddress() - #100327

Merged
BruceForstall merged 1 commit into
dotnet:mainfrom
BruceForstall:AddMoreCheckingToParseArrayAddress
Mar 29, 2024
Merged

Add more checking to GenTreeArrAddr::ParseArrayAddress()#100327
BruceForstall merged 1 commit into
dotnet:mainfrom
BruceForstall:AddMoreCheckingToParseArrayAddress

Conversation

@BruceForstall

Copy link
Copy Markdown
Contributor

If the ARR_ADDR node doesn't make sense, namely if the array offset does not appear to be in the array, then bail.

@ghostghost added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label Mar 27, 2024
@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

Extracted from #94250

@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

There are a few diffs in ILGEN tests that construct array index expressions with negative indices.

@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

With JitOptRepeat we end up with the following situation.

We hit the assert:

Assertion failed '(constIndexOffset % elemSize) == 0'

(e.g.,

System.Runtime.CompilerServices.PoolingAsyncValueTaskMethodBuilder`1+StateMachineBox`1[int,System.IO.Stream+<ReadAtLeastAsyncCore>d__46]:System.Threading.Tasks.Sources.IValueTaskSource.GetResult(short):this'

We start with:

[000895] -----O----- \--* ARR_ADDR byref Internal.PaddedReference[]
[000894] ----------- \--* ADD byref
[000885] ----------- +--* LCL_VAR ref V56 tmp54
[000893] ----------- \--* ADD long
[000891] ----------- +--* MUL long
[000889] ---------U- | +--* CAST long <- uint
[000886] ----------- | | \--* LCL_VAR int V14 tmp12
[000890] -------N--- | \--* CNS_INT long 128
[000892] ----------- \--* CNS_INT long 16

After optimization, this becomes:

N018 ( 2, 2) [000895] -A---O----- \--* ARR_ADDR byref Internal.PaddedReference[] $641
N017 ( 2, 2) [000894] -A-----N--- \--* ADD byref $199
N007 ( 1, 1) [000885] ----------- +--* LCL_VAR ref V56 tmp54 u:1 (last use) $84
N016 ( 7, 10) [000995] -A--------- \--* COMMA long $687
N014 ( 6, 9) [000993] DA--------- +--* STORE_LCL_VAR long V62 cse3 d:1 $VN.Void
N013 ( 6, 9) [000893] ----------- | \--* ADD long $687
N011 ( 4, 6) [000891] ----------- | +--* LSH long $686
N009 ( 2, 3) [000889] ---------U- | | +--* CAST long <- uint $685
N008 ( 1, 1) [000886] ----------- | | | \--* LCL_VAR int V14 tmp12 u:1 $1f5
N010 ( 1, 2) [000890] -------N--- | | \--* CNS_INT long 7 $14e
N012 ( 1, 2) [000892] ----------- | \--* CNS_INT long 16 $146
N015 ( 1, 1) [000994] ----------- \--* LCL_VAR long V62 cse3 u:1 $687

On the next iteration of JitOptRepeat, the CSE injected COMMA is not parseable by GenTreeArrAddr::ParseArrayAddress. We could add tunnel through for this CSE def.

However, it might be harder for the CSE use. In that case, we start with something similar:

[000941] -----O----- \--* ARR_ADDR byref Internal.PaddedReference[]
[000940] ----------- \--* ADD byref
[000931] ----------- +--* LCL_VAR ref V57 tmp55
[000939] ----------- \--* ADD long
[000937] ----------- +--* MUL long
[000935] ---------U- | +--* CAST long <- uint
[000932] ----------- | | \--* LCL_VAR int V14 tmp12 (last use)
[000936] -------N--- | \--* CNS_INT long 128
[000938] ----------- \--* CNS_INT long 16

and, after CSE, have:

N006 ( 2, 2) [000941] -----O-N--- \--* ARR_ADDR byref Internal.PaddedReference[]
N005 ( 2, 2) [000940] -------N--- \--* ADD byref
N003 ( 1, 1) [000931] ----------- +--* LCL_VAR ref V57 tmp55 u:1 (last use)
N004 ( 1, 1) [000996] ----------- \--* LCL_VAR long V62 cse3 u:1 (last use)

This would require parsing the CSE value number for [000996], not the tree.

Since this is VN iteration #2, I'm not sure we lose anything by assigning the ARR_ADDR a new, unique value number when we fail to parse the tree: we've already optimized it once.

@BruceForstall
BruceForstallforce-pushed the AddMoreCheckingToParseArrayAddress branch from f41383c to c5824f8CompareMarch 28, 2024 05:59
@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

@jakobbotsch PTAL
cc @dotnet/jit-contrib

@BruceForstall

BruceForstall commented Mar 28, 2024

Copy link
Copy Markdown
ContributorAuthor

It's interesting that there are diffs on x86, apparently because the offset of data of an array from the base of an array is 8 (it is 16 on 64-bit). This happens to be the same size as a pointer and a double. I see cases where we start with (loc5 - 1) * 8 + 8 which morph transforms to loc5 * 8 - 8 + 8 => loc5 * 8, thus we no longer have an "offset" into the array data (and at runtime loc5 better be > 0, which is checked by the bounds check).

The result is that we give the ARR_ADDR a new, unique VN and we lose some CSEs.

If the ARR_ADDR node doesn't make sense, namely if the array
offset does not appear to be in the array, then bail.
@BruceForstall
BruceForstallforce-pushed the AddMoreCheckingToParseArrayAddress branch from c5824f8 to fc5333dCompareMarch 28, 2024 20:51
@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

GitHub is confused; all the tests passed.

Diffsas described

BruceForstall added a commit to BruceForstall/runtime that referenced this pull request Mar 29, 2024
@BruceForstall
BruceForstall merged commit 0323995 into dotnet:mainMar 29, 2024
@BruceForstall
BruceForstall deleted the AddMoreCheckingToParseArrayAddress branch March 29, 2024 17:35
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Apr 29, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@BruceForstall@AndyAyersMS
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Add more checking to GenTreeArrAddr::ParseArrayAddress() - #100327

Merged
BruceForstall merged 1 commit into
dotnet:mainfrom
BruceForstall:AddMoreCheckingToParseArrayAddress
Mar 29, 2024
Merged

Add more checking to GenTreeArrAddr::ParseArrayAddress()#100327
BruceForstall merged 1 commit into
dotnet:mainfrom
BruceForstall:AddMoreCheckingToParseArrayAddress

Conversation

@BruceForstall

Copy link
Copy Markdown
Contributor

If the ARR_ADDR node doesn't make sense, namely if the array offset does not appear to be in the array, then bail.

@ghostghost added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label Mar 27, 2024
@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

Extracted from #94250

@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

There are a few diffs in ILGEN tests that construct array index expressions with negative indices.

@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

With JitOptRepeat we end up with the following situation.

We hit the assert:

Assertion failed '(constIndexOffset % elemSize) == 0'

(e.g.,

System.Runtime.CompilerServices.PoolingAsyncValueTaskMethodBuilder`1+StateMachineBox`1[int,System.IO.Stream+<ReadAtLeastAsyncCore>d__46]:System.Threading.Tasks.Sources.IValueTaskSource.GetResult(short):this'

We start with:

[000895] -----O----- \--* ARR_ADDR byref Internal.PaddedReference[]
[000894] ----------- \--* ADD byref
[000885] ----------- +--* LCL_VAR ref V56 tmp54
[000893] ----------- \--* ADD long
[000891] ----------- +--* MUL long
[000889] ---------U- | +--* CAST long <- uint
[000886] ----------- | | \--* LCL_VAR int V14 tmp12
[000890] -------N--- | \--* CNS_INT long 128
[000892] ----------- \--* CNS_INT long 16

After optimization, this becomes:

N018 ( 2, 2) [000895] -A---O----- \--* ARR_ADDR byref Internal.PaddedReference[] $641
N017 ( 2, 2) [000894] -A-----N--- \--* ADD byref $199
N007 ( 1, 1) [000885] ----------- +--* LCL_VAR ref V56 tmp54 u:1 (last use) $84
N016 ( 7, 10) [000995] -A--------- \--* COMMA long $687
N014 ( 6, 9) [000993] DA--------- +--* STORE_LCL_VAR long V62 cse3 d:1 $VN.Void
N013 ( 6, 9) [000893] ----------- | \--* ADD long $687
N011 ( 4, 6) [000891] ----------- | +--* LSH long $686
N009 ( 2, 3) [000889] ---------U- | | +--* CAST long <- uint $685
N008 ( 1, 1) [000886] ----------- | | | \--* LCL_VAR int V14 tmp12 u:1 $1f5
N010 ( 1, 2) [000890] -------N--- | | \--* CNS_INT long 7 $14e
N012 ( 1, 2) [000892] ----------- | \--* CNS_INT long 16 $146
N015 ( 1, 1) [000994] ----------- \--* LCL_VAR long V62 cse3 u:1 $687

On the next iteration of JitOptRepeat, the CSE injected COMMA is not parseable by GenTreeArrAddr::ParseArrayAddress. We could add tunnel through for this CSE def.

However, it might be harder for the CSE use. In that case, we start with something similar:

[000941] -----O----- \--* ARR_ADDR byref Internal.PaddedReference[]
[000940] ----------- \--* ADD byref
[000931] ----------- +--* LCL_VAR ref V57 tmp55
[000939] ----------- \--* ADD long
[000937] ----------- +--* MUL long
[000935] ---------U- | +--* CAST long <- uint
[000932] ----------- | | \--* LCL_VAR int V14 tmp12 (last use)
[000936] -------N--- | \--* CNS_INT long 128
[000938] ----------- \--* CNS_INT long 16

and, after CSE, have:

N006 ( 2, 2) [000941] -----O-N--- \--* ARR_ADDR byref Internal.PaddedReference[]
N005 ( 2, 2) [000940] -------N--- \--* ADD byref
N003 ( 1, 1) [000931] ----------- +--* LCL_VAR ref V57 tmp55 u:1 (last use)
N004 ( 1, 1) [000996] ----------- \--* LCL_VAR long V62 cse3 u:1 (last use)

This would require parsing the CSE value number for [000996], not the tree.

Since this is VN iteration #2, I'm not sure we lose anything by assigning the ARR_ADDR a new, unique value number when we fail to parse the tree: we've already optimized it once.

@BruceForstall
BruceForstallforce-pushed the AddMoreCheckingToParseArrayAddress branch from f41383c to c5824f8CompareMarch 28, 2024 05:59
@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

@jakobbotsch PTAL
cc @dotnet/jit-contrib

@BruceForstall

BruceForstall commented Mar 28, 2024

Copy link
Copy Markdown
ContributorAuthor

It's interesting that there are diffs on x86, apparently because the offset of data of an array from the base of an array is 8 (it is 16 on 64-bit). This happens to be the same size as a pointer and a double. I see cases where we start with (loc5 - 1) * 8 + 8 which morph transforms to loc5 * 8 - 8 + 8 => loc5 * 8, thus we no longer have an "offset" into the array data (and at runtime loc5 better be > 0, which is checked by the bounds check).

The result is that we give the ARR_ADDR a new, unique VN and we lose some CSEs.

If the ARR_ADDR node doesn't make sense, namely if the array
offset does not appear to be in the array, then bail.
@BruceForstall
BruceForstallforce-pushed the AddMoreCheckingToParseArrayAddress branch from c5824f8 to fc5333dCompareMarch 28, 2024 20:51
@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

GitHub is confused; all the tests passed.

Diffsas described

BruceForstall added a commit to BruceForstall/runtime that referenced this pull request Mar 29, 2024
@BruceForstall
BruceForstall merged commit 0323995 into dotnet:mainMar 29, 2024
@BruceForstall
BruceForstall deleted the AddMoreCheckingToParseArrayAddress branch March 29, 2024 17:35
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Apr 29, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@BruceForstall@AndyAyersMS
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add more checking to GenTreeArrAddr::ParseArrayAddress() - #100327

Merged
BruceForstall merged 1 commit into
dotnet:mainfrom
BruceForstall:AddMoreCheckingToParseArrayAddress
Mar 29, 2024
Merged

Add more checking to GenTreeArrAddr::ParseArrayAddress()#100327
BruceForstall merged 1 commit into
dotnet:mainfrom
BruceForstall:AddMoreCheckingToParseArrayAddress

Conversation

@BruceForstall

Copy link
Copy Markdown
Contributor

If the ARR_ADDR node doesn't make sense, namely if the array offset does not appear to be in the array, then bail.

@ghostghost added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label Mar 27, 2024
@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

Extracted from #94250

@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

There are a few diffs in ILGEN tests that construct array index expressions with negative indices.

@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

With JitOptRepeat we end up with the following situation.

We hit the assert:

Assertion failed '(constIndexOffset % elemSize) == 0'

(e.g.,

System.Runtime.CompilerServices.PoolingAsyncValueTaskMethodBuilder`1+StateMachineBox`1[int,System.IO.Stream+<ReadAtLeastAsyncCore>d__46]:System.Threading.Tasks.Sources.IValueTaskSource.GetResult(short):this'

We start with:

[000895] -----O----- \--* ARR_ADDR byref Internal.PaddedReference[]
[000894] ----------- \--* ADD byref
[000885] ----------- +--* LCL_VAR ref V56 tmp54
[000893] ----------- \--* ADD long
[000891] ----------- +--* MUL long
[000889] ---------U- | +--* CAST long <- uint
[000886] ----------- | | \--* LCL_VAR int V14 tmp12
[000890] -------N--- | \--* CNS_INT long 128
[000892] ----------- \--* CNS_INT long 16

After optimization, this becomes:

N018 ( 2, 2) [000895] -A---O----- \--* ARR_ADDR byref Internal.PaddedReference[] $641
N017 ( 2, 2) [000894] -A-----N--- \--* ADD byref $199
N007 ( 1, 1) [000885] ----------- +--* LCL_VAR ref V56 tmp54 u:1 (last use) $84
N016 ( 7, 10) [000995] -A--------- \--* COMMA long $687
N014 ( 6, 9) [000993] DA--------- +--* STORE_LCL_VAR long V62 cse3 d:1 $VN.Void
N013 ( 6, 9) [000893] ----------- | \--* ADD long $687
N011 ( 4, 6) [000891] ----------- | +--* LSH long $686
N009 ( 2, 3) [000889] ---------U- | | +--* CAST long <- uint $685
N008 ( 1, 1) [000886] ----------- | | | \--* LCL_VAR int V14 tmp12 u:1 $1f5
N010 ( 1, 2) [000890] -------N--- | | \--* CNS_INT long 7 $14e
N012 ( 1, 2) [000892] ----------- | \--* CNS_INT long 16 $146
N015 ( 1, 1) [000994] ----------- \--* LCL_VAR long V62 cse3 u:1 $687

On the next iteration of JitOptRepeat, the CSE injected COMMA is not parseable by GenTreeArrAddr::ParseArrayAddress. We could add tunnel through for this CSE def.

However, it might be harder for the CSE use. In that case, we start with something similar:

[000941] -----O----- \--* ARR_ADDR byref Internal.PaddedReference[]
[000940] ----------- \--* ADD byref
[000931] ----------- +--* LCL_VAR ref V57 tmp55
[000939] ----------- \--* ADD long
[000937] ----------- +--* MUL long
[000935] ---------U- | +--* CAST long <- uint
[000932] ----------- | | \--* LCL_VAR int V14 tmp12 (last use)
[000936] -------N--- | \--* CNS_INT long 128
[000938] ----------- \--* CNS_INT long 16

and, after CSE, have:

N006 ( 2, 2) [000941] -----O-N--- \--* ARR_ADDR byref Internal.PaddedReference[]
N005 ( 2, 2) [000940] -------N--- \--* ADD byref
N003 ( 1, 1) [000931] ----------- +--* LCL_VAR ref V57 tmp55 u:1 (last use)
N004 ( 1, 1) [000996] ----------- \--* LCL_VAR long V62 cse3 u:1 (last use)

This would require parsing the CSE value number for [000996], not the tree.

Since this is VN iteration #2, I'm not sure we lose anything by assigning the ARR_ADDR a new, unique value number when we fail to parse the tree: we've already optimized it once.

@BruceForstall
BruceForstallforce-pushed the AddMoreCheckingToParseArrayAddress branch from f41383c to c5824f8CompareMarch 28, 2024 05:59
@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

@jakobbotsch PTAL
cc @dotnet/jit-contrib

@BruceForstall

BruceForstall commented Mar 28, 2024

Copy link
Copy Markdown
ContributorAuthor

It's interesting that there are diffs on x86, apparently because the offset of data of an array from the base of an array is 8 (it is 16 on 64-bit). This happens to be the same size as a pointer and a double. I see cases where we start with (loc5 - 1) * 8 + 8 which morph transforms to loc5 * 8 - 8 + 8 => loc5 * 8, thus we no longer have an "offset" into the array data (and at runtime loc5 better be > 0, which is checked by the bounds check).

The result is that we give the ARR_ADDR a new, unique VN and we lose some CSEs.

If the ARR_ADDR node doesn't make sense, namely if the array
offset does not appear to be in the array, then bail.
@BruceForstall
BruceForstallforce-pushed the AddMoreCheckingToParseArrayAddress branch from c5824f8 to fc5333dCompareMarch 28, 2024 20:51
@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

GitHub is confused; all the tests passed.

Diffsas described

BruceForstall added a commit to BruceForstall/runtime that referenced this pull request Mar 29, 2024
@BruceForstall
BruceForstall merged commit 0323995 into dotnet:mainMar 29, 2024
@BruceForstall
BruceForstall deleted the AddMoreCheckingToParseArrayAddress branch March 29, 2024 17:35
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Apr 29, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@BruceForstall@AndyAyersMS
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Add more checking to GenTreeArrAddr::ParseArrayAddress() - #100327

Merged
BruceForstall merged 1 commit into
dotnet:mainfrom
BruceForstall:AddMoreCheckingToParseArrayAddress
Mar 29, 2024
Merged

Add more checking to GenTreeArrAddr::ParseArrayAddress()#100327
BruceForstall merged 1 commit into
dotnet:mainfrom
BruceForstall:AddMoreCheckingToParseArrayAddress

Conversation

@BruceForstall

Copy link
Copy Markdown
Contributor

If the ARR_ADDR node doesn't make sense, namely if the array offset does not appear to be in the array, then bail.

@ghostghost added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label Mar 27, 2024
@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

Extracted from #94250

@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

There are a few diffs in ILGEN tests that construct array index expressions with negative indices.

@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

With JitOptRepeat we end up with the following situation.

We hit the assert:

Assertion failed '(constIndexOffset % elemSize) == 0'

(e.g.,

System.Runtime.CompilerServices.PoolingAsyncValueTaskMethodBuilder`1+StateMachineBox`1[int,System.IO.Stream+<ReadAtLeastAsyncCore>d__46]:System.Threading.Tasks.Sources.IValueTaskSource.GetResult(short):this'

We start with:

[000895] -----O----- \--* ARR_ADDR byref Internal.PaddedReference[]
[000894] ----------- \--* ADD byref
[000885] ----------- +--* LCL_VAR ref V56 tmp54
[000893] ----------- \--* ADD long
[000891] ----------- +--* MUL long
[000889] ---------U- | +--* CAST long <- uint
[000886] ----------- | | \--* LCL_VAR int V14 tmp12
[000890] -------N--- | \--* CNS_INT long 128
[000892] ----------- \--* CNS_INT long 16

After optimization, this becomes:

N018 ( 2, 2) [000895] -A---O----- \--* ARR_ADDR byref Internal.PaddedReference[] $641
N017 ( 2, 2) [000894] -A-----N--- \--* ADD byref $199
N007 ( 1, 1) [000885] ----------- +--* LCL_VAR ref V56 tmp54 u:1 (last use) $84
N016 ( 7, 10) [000995] -A--------- \--* COMMA long $687
N014 ( 6, 9) [000993] DA--------- +--* STORE_LCL_VAR long V62 cse3 d:1 $VN.Void
N013 ( 6, 9) [000893] ----------- | \--* ADD long $687
N011 ( 4, 6) [000891] ----------- | +--* LSH long $686
N009 ( 2, 3) [000889] ---------U- | | +--* CAST long <- uint $685
N008 ( 1, 1) [000886] ----------- | | | \--* LCL_VAR int V14 tmp12 u:1 $1f5
N010 ( 1, 2) [000890] -------N--- | | \--* CNS_INT long 7 $14e
N012 ( 1, 2) [000892] ----------- | \--* CNS_INT long 16 $146
N015 ( 1, 1) [000994] ----------- \--* LCL_VAR long V62 cse3 u:1 $687

On the next iteration of JitOptRepeat, the CSE injected COMMA is not parseable by GenTreeArrAddr::ParseArrayAddress. We could add tunnel through for this CSE def.

However, it might be harder for the CSE use. In that case, we start with something similar:

[000941] -----O----- \--* ARR_ADDR byref Internal.PaddedReference[]
[000940] ----------- \--* ADD byref
[000931] ----------- +--* LCL_VAR ref V57 tmp55
[000939] ----------- \--* ADD long
[000937] ----------- +--* MUL long
[000935] ---------U- | +--* CAST long <- uint
[000932] ----------- | | \--* LCL_VAR int V14 tmp12 (last use)
[000936] -------N--- | \--* CNS_INT long 128
[000938] ----------- \--* CNS_INT long 16

and, after CSE, have:

N006 ( 2, 2) [000941] -----O-N--- \--* ARR_ADDR byref Internal.PaddedReference[]
N005 ( 2, 2) [000940] -------N--- \--* ADD byref
N003 ( 1, 1) [000931] ----------- +--* LCL_VAR ref V57 tmp55 u:1 (last use)
N004 ( 1, 1) [000996] ----------- \--* LCL_VAR long V62 cse3 u:1 (last use)

This would require parsing the CSE value number for [000996], not the tree.

Since this is VN iteration #2, I'm not sure we lose anything by assigning the ARR_ADDR a new, unique value number when we fail to parse the tree: we've already optimized it once.

@BruceForstall
BruceForstallforce-pushed the AddMoreCheckingToParseArrayAddress branch from f41383c to c5824f8CompareMarch 28, 2024 05:59
@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

@jakobbotsch PTAL
cc @dotnet/jit-contrib

@BruceForstall

BruceForstall commented Mar 28, 2024

Copy link
Copy Markdown
ContributorAuthor

It's interesting that there are diffs on x86, apparently because the offset of data of an array from the base of an array is 8 (it is 16 on 64-bit). This happens to be the same size as a pointer and a double. I see cases where we start with (loc5 - 1) * 8 + 8 which morph transforms to loc5 * 8 - 8 + 8 => loc5 * 8, thus we no longer have an "offset" into the array data (and at runtime loc5 better be > 0, which is checked by the bounds check).

The result is that we give the ARR_ADDR a new, unique VN and we lose some CSEs.

If the ARR_ADDR node doesn't make sense, namely if the array
offset does not appear to be in the array, then bail.
@BruceForstall
BruceForstallforce-pushed the AddMoreCheckingToParseArrayAddress branch from c5824f8 to fc5333dCompareMarch 28, 2024 20:51
@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

GitHub is confused; all the tests passed.

Diffsas described

BruceForstall added a commit to BruceForstall/runtime that referenced this pull request Mar 29, 2024
@BruceForstall
BruceForstall merged commit 0323995 into dotnet:mainMar 29, 2024
@BruceForstall
BruceForstall deleted the AddMoreCheckingToParseArrayAddress branch March 29, 2024 17:35
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Apr 29, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@BruceForstall@AndyAyersMS
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Add more checking to GenTreeArrAddr::ParseArrayAddress() - #100327

Merged
BruceForstall merged 1 commit into
dotnet:mainfrom
BruceForstall:AddMoreCheckingToParseArrayAddress
Mar 29, 2024
Merged

Add more checking to GenTreeArrAddr::ParseArrayAddress()#100327
BruceForstall merged 1 commit into
dotnet:mainfrom
BruceForstall:AddMoreCheckingToParseArrayAddress

Conversation

@BruceForstall

Copy link
Copy Markdown
Contributor

If the ARR_ADDR node doesn't make sense, namely if the array offset does not appear to be in the array, then bail.

@ghostghost added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label Mar 27, 2024
@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

Extracted from #94250

@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

There are a few diffs in ILGEN tests that construct array index expressions with negative indices.

@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

With JitOptRepeat we end up with the following situation.

We hit the assert:

Assertion failed '(constIndexOffset % elemSize) == 0'

(e.g.,

System.Runtime.CompilerServices.PoolingAsyncValueTaskMethodBuilder`1+StateMachineBox`1[int,System.IO.Stream+<ReadAtLeastAsyncCore>d__46]:System.Threading.Tasks.Sources.IValueTaskSource.GetResult(short):this'

We start with:

[000895] -----O----- \--* ARR_ADDR byref Internal.PaddedReference[]
[000894] ----------- \--* ADD byref
[000885] ----------- +--* LCL_VAR ref V56 tmp54
[000893] ----------- \--* ADD long
[000891] ----------- +--* MUL long
[000889] ---------U- | +--* CAST long <- uint
[000886] ----------- | | \--* LCL_VAR int V14 tmp12
[000890] -------N--- | \--* CNS_INT long 128
[000892] ----------- \--* CNS_INT long 16

After optimization, this becomes:

N018 ( 2, 2) [000895] -A---O----- \--* ARR_ADDR byref Internal.PaddedReference[] $641
N017 ( 2, 2) [000894] -A-----N--- \--* ADD byref $199
N007 ( 1, 1) [000885] ----------- +--* LCL_VAR ref V56 tmp54 u:1 (last use) $84
N016 ( 7, 10) [000995] -A--------- \--* COMMA long $687
N014 ( 6, 9) [000993] DA--------- +--* STORE_LCL_VAR long V62 cse3 d:1 $VN.Void
N013 ( 6, 9) [000893] ----------- | \--* ADD long $687
N011 ( 4, 6) [000891] ----------- | +--* LSH long $686
N009 ( 2, 3) [000889] ---------U- | | +--* CAST long <- uint $685
N008 ( 1, 1) [000886] ----------- | | | \--* LCL_VAR int V14 tmp12 u:1 $1f5
N010 ( 1, 2) [000890] -------N--- | | \--* CNS_INT long 7 $14e
N012 ( 1, 2) [000892] ----------- | \--* CNS_INT long 16 $146
N015 ( 1, 1) [000994] ----------- \--* LCL_VAR long V62 cse3 u:1 $687

On the next iteration of JitOptRepeat, the CSE injected COMMA is not parseable by GenTreeArrAddr::ParseArrayAddress. We could add tunnel through for this CSE def.

However, it might be harder for the CSE use. In that case, we start with something similar:

[000941] -----O----- \--* ARR_ADDR byref Internal.PaddedReference[]
[000940] ----------- \--* ADD byref
[000931] ----------- +--* LCL_VAR ref V57 tmp55
[000939] ----------- \--* ADD long
[000937] ----------- +--* MUL long
[000935] ---------U- | +--* CAST long <- uint
[000932] ----------- | | \--* LCL_VAR int V14 tmp12 (last use)
[000936] -------N--- | \--* CNS_INT long 128
[000938] ----------- \--* CNS_INT long 16

and, after CSE, have:

N006 ( 2, 2) [000941] -----O-N--- \--* ARR_ADDR byref Internal.PaddedReference[]
N005 ( 2, 2) [000940] -------N--- \--* ADD byref
N003 ( 1, 1) [000931] ----------- +--* LCL_VAR ref V57 tmp55 u:1 (last use)
N004 ( 1, 1) [000996] ----------- \--* LCL_VAR long V62 cse3 u:1 (last use)

This would require parsing the CSE value number for [000996], not the tree.

Since this is VN iteration #2, I'm not sure we lose anything by assigning the ARR_ADDR a new, unique value number when we fail to parse the tree: we've already optimized it once.

@BruceForstall
BruceForstallforce-pushed the AddMoreCheckingToParseArrayAddress branch from f41383c to c5824f8CompareMarch 28, 2024 05:59
@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

@jakobbotsch PTAL
cc @dotnet/jit-contrib

@BruceForstall

BruceForstall commented Mar 28, 2024

Copy link
Copy Markdown
ContributorAuthor

It's interesting that there are diffs on x86, apparently because the offset of data of an array from the base of an array is 8 (it is 16 on 64-bit). This happens to be the same size as a pointer and a double. I see cases where we start with (loc5 - 1) * 8 + 8 which morph transforms to loc5 * 8 - 8 + 8 => loc5 * 8, thus we no longer have an "offset" into the array data (and at runtime loc5 better be > 0, which is checked by the bounds check).

The result is that we give the ARR_ADDR a new, unique VN and we lose some CSEs.

If the ARR_ADDR node doesn't make sense, namely if the array
offset does not appear to be in the array, then bail.
@BruceForstall
BruceForstallforce-pushed the AddMoreCheckingToParseArrayAddress branch from c5824f8 to fc5333dCompareMarch 28, 2024 20:51
@BruceForstall

Copy link
Copy Markdown
ContributorAuthor

GitHub is confused; all the tests passed.

Diffsas described

BruceForstall added a commit to BruceForstall/runtime that referenced this pull request Mar 29, 2024
@BruceForstall
BruceForstall merged commit 0323995 into dotnet:mainMar 29, 2024
@BruceForstall
BruceForstall deleted the AddMoreCheckingToParseArrayAddress branch March 29, 2024 17:35
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Apr 29, 2024
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@BruceForstall@AndyAyersMS