[clr-ios] Fix SIGSEGV in open virtual delegate dispatch with interpreter - #126199

Merged
janvorli merged 13 commits into
dotnet:mainfrom
kotlarmilos:bugfix/clr-interpreter-open-delegate
Apr 14, 2026
Merged

[clr-ios] Fix SIGSEGV in open virtual delegate dispatch with interpreter#126199
janvorli merged 13 commits into
dotnet:mainfrom
kotlarmilos:bugfix/clr-interpreter-open-delegate

Conversation

@kotlarmilos

@kotlarmiloskotlarmilos commented Mar 27, 2026

Copy link
Copy Markdown
Member

Description

Fix a crash when the interpreter invokes a compiled open virtual delegate target.

When the interpreter's call delegate handler detects an open virtual delegate whose resolved target is compiled (targetIp == NULL), the code previously fell through to a generic path that called GetTarget() on the delegate. For open delegates, GetTarget() returns null, which corrupted the argument slot and caused a SIGSEGV.

The fix adds a dedicated path for open virtual delegates with compiled targets. It uses memmove to shift the call arguments down by one slot (removing the delegate object) while preserving 16-byte alignment for V128 arguments, then jumps to CALL_INTERP_METHOD to invoke the resolved targetMethod directly. The same shifting is applied for interpreted targets in the non-tail-call path. The alignment-preserving shift logic is extracted into a ShiftDelegateCallArgs() helper to avoid duplication.

Additionally, this re-enables test suites previously excluded under #124325 (except System.Runtime.Serialization.Xml.Tests, which hits a native stack overflow unrelated to this fix).

CopilotAI review requested due to automatic review settings March 27, 2026 13:09
@kotlarmiloskotlarmilos self-assigned this Mar 27, 2026
@kotlarmiloskotlarmilos added this to the 11.0.0 milestone Mar 27, 2026
@kotlarmiloskotlarmilos added the os-ios Apple iOS label Mar 27, 2026
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @BrzVlad, @janvorli, @kg
See info in area-owners.md if you want to be subscribed.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Fixes an interpreter crash on iOS when invoking compiled open virtual delegate targets, and updates AppleMobile/CoreCLR libraries test selection.

Changes:

  • Handle open virtual delegates whose resolved target has no interpreter bytecode (targetIp == NULL) by skipping the delegate argument slot and directly dispatching via CALL_INTERP_METHOD.
  • Remove several AppleMobile/CoreCLR test project exclusions from src/libraries/tests.proj.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 2 comments.

FileDescription
src/libraries/tests.projRemoves previously-added AppleMobile/CoreCLR test exclusions (re-enables several Serialization test projects).
src/coreclr/vm/interpexec.cppAdds a NULL-targetIp open-virtual delegate path that avoids GetTarget() and dispatches the resolved MethodDesc directly.

Comment threadsrc/libraries/tests.proj
Comment threadsrc/coreclr/vm/interpexec.cpp
Comment threadsrc/coreclr/vm/interpexec.cpp Outdated
@kotlarmilos

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-ioslike

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

Wrap the GetTarget/NonVirtualEntry2MethodDesc block in braces so the
CALL_DELEGATE_INVOKE goto can legally jump past the OBJECTREF variable
initialization.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings March 31, 2026 09:08

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.

Comment threadsrc/coreclr/vm/interpexec.cpp
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings April 8, 2026 08:36
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 6 out of 6 changed files in this pull request and generated 2 comments.

Comment threadsrc/coreclr/vm/interpexec.cpp
Comment threadsrc/coreclr/vm/interpexec.cpp Outdated
- Fix ShiftDelegateCallArgs memmove length to use totalArgsSize - firstAlignedDstOffset
instead of totalArgsSize - sizeOfArgsUpto16ByteAlignment to avoid reading past
actual argument data when pre-alignment size is not 16-byte aligned.
- Extend INTOP_CALLDELEGATE_TAIL to carry sizeOfArgsUpto16ByteAlignment and
targetArgsSize (oplength 4 -> 6) so the open virtual compiled target path
works correctly for tail calls.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@kotlarmilos

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-ioslike

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

Comment threadsrc/coreclr/vm/interpexec.cpp
Comment threadsrc/coreclr/interpreter/compiler.cpp Outdated
Comment threadsrc/coreclr/vm/interpexec.cpp
Comment threadsrc/coreclr/interpreter/inc/intops.def
…check
- Revert INTOP_CALLDELEGATE_TAIL to oplength 4; tail calls use the simpler
callArgsOffset += INTERP_STACK_SLOT_SIZE approach matching the interpreted
tail path.
already makes sizeOfArgsUpto16ByteAlignment == targetArgsSize when no V128
arg exists.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings April 10, 2026 16:07
- Expand INTOP_CALLDELEGATE_TAIL to oplength 6 with size metadata
- Use ShiftDelegateCallArgs in interpreted tail path instead of
callArgsOffset + INTERP_STACK_SLOT_SIZE which breaks 16-byte alignment
- Use ShiftDelegateCallArgs unconditionally in compiled open virtual path
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 6 out of 6 changed files in this pull request and generated 2 comments.

Comments suppressed due to low confidence (1)

src/coreclr/vm/interpexec.cpp:3224

  • In the open-virtual + compiled-target path, the tailcall case adjusts callArgsOffset by one slot and then jumps to CALL_INTERP_METHOD. If CALL_INTERP_METHOD ends up invoking a compiled method (targetIp == NULL), the call stub expects the argument block to follow interpreter stack alignment rules from offset 0 (including 16-byte alignment for V128). Bumping the base pointer by 8 can violate those assumptions. Consider either applying the same alignment-preserving shift for this tailcall case (which likely means carrying the size metadata on INTOP_CALLDELEGATE_TAIL too), or falling back to the normal delegate invoke/shuffle-thunk path for tail calls when the resolved target is compiled.

if ((targetMethod = NonVirtualEntry2MethodDesc(targetAddress)) != NULL)
{
// In this case targetMethod holds a pointer to the MethodDesc that will be called by using targetMethodObj as
// the this pointer. This may be the final method (in the case of instance method delegates), or it may be a

Comment threadsrc/libraries/tests.proj Outdated
Comment threadsrc/coreclr/vm/interpexec.cpp
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

@janvorlijanvorli left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thank you!

@janvorli
janvorli merged commit d8e9ae7 into dotnet:mainApr 14, 2026
136 of 139 checks passed
@github-actionsgithub-actionsBot locked and limited conversation to collaborators May 15, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@kotlarmilos@BrzVlad@jkotas@janvorli
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

[clr-ios] Fix SIGSEGV in open virtual delegate dispatch with interpreter - #126199

Merged
janvorli merged 13 commits into
dotnet:mainfrom
kotlarmilos:bugfix/clr-interpreter-open-delegate
Apr 14, 2026
Merged

[clr-ios] Fix SIGSEGV in open virtual delegate dispatch with interpreter#126199
janvorli merged 13 commits into
dotnet:mainfrom
kotlarmilos:bugfix/clr-interpreter-open-delegate

Conversation

@kotlarmilos

@kotlarmiloskotlarmilos commented Mar 27, 2026

Copy link
Copy Markdown
Member

Description

Fix a crash when the interpreter invokes a compiled open virtual delegate target.

When the interpreter's call delegate handler detects an open virtual delegate whose resolved target is compiled (targetIp == NULL), the code previously fell through to a generic path that called GetTarget() on the delegate. For open delegates, GetTarget() returns null, which corrupted the argument slot and caused a SIGSEGV.

The fix adds a dedicated path for open virtual delegates with compiled targets. It uses memmove to shift the call arguments down by one slot (removing the delegate object) while preserving 16-byte alignment for V128 arguments, then jumps to CALL_INTERP_METHOD to invoke the resolved targetMethod directly. The same shifting is applied for interpreted targets in the non-tail-call path. The alignment-preserving shift logic is extracted into a ShiftDelegateCallArgs() helper to avoid duplication.

Additionally, this re-enables test suites previously excluded under #124325 (except System.Runtime.Serialization.Xml.Tests, which hits a native stack overflow unrelated to this fix).

CopilotAI review requested due to automatic review settings March 27, 2026 13:09
@kotlarmiloskotlarmilos self-assigned this Mar 27, 2026
@kotlarmiloskotlarmilos added this to the 11.0.0 milestone Mar 27, 2026
@kotlarmiloskotlarmilos added the os-ios Apple iOS label Mar 27, 2026
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @BrzVlad, @janvorli, @kg
See info in area-owners.md if you want to be subscribed.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Fixes an interpreter crash on iOS when invoking compiled open virtual delegate targets, and updates AppleMobile/CoreCLR libraries test selection.

Changes:

  • Handle open virtual delegates whose resolved target has no interpreter bytecode (targetIp == NULL) by skipping the delegate argument slot and directly dispatching via CALL_INTERP_METHOD.
  • Remove several AppleMobile/CoreCLR test project exclusions from src/libraries/tests.proj.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 2 comments.

FileDescription
src/libraries/tests.projRemoves previously-added AppleMobile/CoreCLR test exclusions (re-enables several Serialization test projects).
src/coreclr/vm/interpexec.cppAdds a NULL-targetIp open-virtual delegate path that avoids GetTarget() and dispatches the resolved MethodDesc directly.

Comment threadsrc/libraries/tests.proj
Comment threadsrc/coreclr/vm/interpexec.cpp
Comment threadsrc/coreclr/vm/interpexec.cpp Outdated
@kotlarmilos

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-ioslike

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

Wrap the GetTarget/NonVirtualEntry2MethodDesc block in braces so the
CALL_DELEGATE_INVOKE goto can legally jump past the OBJECTREF variable
initialization.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings March 31, 2026 09:08

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.

Comment threadsrc/coreclr/vm/interpexec.cpp
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings April 8, 2026 08:36
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 6 out of 6 changed files in this pull request and generated 2 comments.

Comment threadsrc/coreclr/vm/interpexec.cpp
Comment threadsrc/coreclr/vm/interpexec.cpp Outdated
- Fix ShiftDelegateCallArgs memmove length to use totalArgsSize - firstAlignedDstOffset
instead of totalArgsSize - sizeOfArgsUpto16ByteAlignment to avoid reading past
actual argument data when pre-alignment size is not 16-byte aligned.
- Extend INTOP_CALLDELEGATE_TAIL to carry sizeOfArgsUpto16ByteAlignment and
targetArgsSize (oplength 4 -> 6) so the open virtual compiled target path
works correctly for tail calls.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@kotlarmilos

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-ioslike

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

Comment threadsrc/coreclr/vm/interpexec.cpp
Comment threadsrc/coreclr/interpreter/compiler.cpp Outdated
Comment threadsrc/coreclr/vm/interpexec.cpp
Comment threadsrc/coreclr/interpreter/inc/intops.def
…check
- Revert INTOP_CALLDELEGATE_TAIL to oplength 4; tail calls use the simpler
callArgsOffset += INTERP_STACK_SLOT_SIZE approach matching the interpreted
tail path.
already makes sizeOfArgsUpto16ByteAlignment == targetArgsSize when no V128
arg exists.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings April 10, 2026 16:07
- Expand INTOP_CALLDELEGATE_TAIL to oplength 6 with size metadata
- Use ShiftDelegateCallArgs in interpreted tail path instead of
callArgsOffset + INTERP_STACK_SLOT_SIZE which breaks 16-byte alignment
- Use ShiftDelegateCallArgs unconditionally in compiled open virtual path
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 6 out of 6 changed files in this pull request and generated 2 comments.

Comments suppressed due to low confidence (1)

src/coreclr/vm/interpexec.cpp:3224

  • In the open-virtual + compiled-target path, the tailcall case adjusts callArgsOffset by one slot and then jumps to CALL_INTERP_METHOD. If CALL_INTERP_METHOD ends up invoking a compiled method (targetIp == NULL), the call stub expects the argument block to follow interpreter stack alignment rules from offset 0 (including 16-byte alignment for V128). Bumping the base pointer by 8 can violate those assumptions. Consider either applying the same alignment-preserving shift for this tailcall case (which likely means carrying the size metadata on INTOP_CALLDELEGATE_TAIL too), or falling back to the normal delegate invoke/shuffle-thunk path for tail calls when the resolved target is compiled.

if ((targetMethod = NonVirtualEntry2MethodDesc(targetAddress)) != NULL)
{
// In this case targetMethod holds a pointer to the MethodDesc that will be called by using targetMethodObj as
// the this pointer. This may be the final method (in the case of instance method delegates), or it may be a

Comment threadsrc/libraries/tests.proj Outdated
Comment threadsrc/coreclr/vm/interpexec.cpp
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

@janvorlijanvorli left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thank you!

@janvorli
janvorli merged commit d8e9ae7 into dotnet:mainApr 14, 2026
136 of 139 checks passed
@github-actionsgithub-actionsBot locked and limited conversation to collaborators May 15, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@kotlarmilos@BrzVlad@jkotas@janvorli
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[clr-ios] Fix SIGSEGV in open virtual delegate dispatch with interpreter - #126199

Merged
janvorli merged 13 commits into
dotnet:mainfrom
kotlarmilos:bugfix/clr-interpreter-open-delegate
Apr 14, 2026
Merged

[clr-ios] Fix SIGSEGV in open virtual delegate dispatch with interpreter#126199
janvorli merged 13 commits into
dotnet:mainfrom
kotlarmilos:bugfix/clr-interpreter-open-delegate

Conversation

@kotlarmilos

@kotlarmiloskotlarmilos commented Mar 27, 2026

Copy link
Copy Markdown
Member

Description

Fix a crash when the interpreter invokes a compiled open virtual delegate target.

When the interpreter's call delegate handler detects an open virtual delegate whose resolved target is compiled (targetIp == NULL), the code previously fell through to a generic path that called GetTarget() on the delegate. For open delegates, GetTarget() returns null, which corrupted the argument slot and caused a SIGSEGV.

The fix adds a dedicated path for open virtual delegates with compiled targets. It uses memmove to shift the call arguments down by one slot (removing the delegate object) while preserving 16-byte alignment for V128 arguments, then jumps to CALL_INTERP_METHOD to invoke the resolved targetMethod directly. The same shifting is applied for interpreted targets in the non-tail-call path. The alignment-preserving shift logic is extracted into a ShiftDelegateCallArgs() helper to avoid duplication.

Additionally, this re-enables test suites previously excluded under #124325 (except System.Runtime.Serialization.Xml.Tests, which hits a native stack overflow unrelated to this fix).

CopilotAI review requested due to automatic review settings March 27, 2026 13:09
@kotlarmiloskotlarmilos self-assigned this Mar 27, 2026
@kotlarmiloskotlarmilos added this to the 11.0.0 milestone Mar 27, 2026
@kotlarmiloskotlarmilos added the os-ios Apple iOS label Mar 27, 2026
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @BrzVlad, @janvorli, @kg
See info in area-owners.md if you want to be subscribed.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Fixes an interpreter crash on iOS when invoking compiled open virtual delegate targets, and updates AppleMobile/CoreCLR libraries test selection.

Changes:

  • Handle open virtual delegates whose resolved target has no interpreter bytecode (targetIp == NULL) by skipping the delegate argument slot and directly dispatching via CALL_INTERP_METHOD.
  • Remove several AppleMobile/CoreCLR test project exclusions from src/libraries/tests.proj.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 2 comments.

FileDescription
src/libraries/tests.projRemoves previously-added AppleMobile/CoreCLR test exclusions (re-enables several Serialization test projects).
src/coreclr/vm/interpexec.cppAdds a NULL-targetIp open-virtual delegate path that avoids GetTarget() and dispatches the resolved MethodDesc directly.

Comment threadsrc/libraries/tests.proj
Comment threadsrc/coreclr/vm/interpexec.cpp
Comment threadsrc/coreclr/vm/interpexec.cpp Outdated
@kotlarmilos

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-ioslike

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

Wrap the GetTarget/NonVirtualEntry2MethodDesc block in braces so the
CALL_DELEGATE_INVOKE goto can legally jump past the OBJECTREF variable
initialization.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings March 31, 2026 09:08

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.

Comment threadsrc/coreclr/vm/interpexec.cpp
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings April 8, 2026 08:36
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 6 out of 6 changed files in this pull request and generated 2 comments.

Comment threadsrc/coreclr/vm/interpexec.cpp
Comment threadsrc/coreclr/vm/interpexec.cpp Outdated
- Fix ShiftDelegateCallArgs memmove length to use totalArgsSize - firstAlignedDstOffset
instead of totalArgsSize - sizeOfArgsUpto16ByteAlignment to avoid reading past
actual argument data when pre-alignment size is not 16-byte aligned.
- Extend INTOP_CALLDELEGATE_TAIL to carry sizeOfArgsUpto16ByteAlignment and
targetArgsSize (oplength 4 -> 6) so the open virtual compiled target path
works correctly for tail calls.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@kotlarmilos

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-ioslike

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

Comment threadsrc/coreclr/vm/interpexec.cpp
Comment threadsrc/coreclr/interpreter/compiler.cpp Outdated
Comment threadsrc/coreclr/vm/interpexec.cpp
Comment threadsrc/coreclr/interpreter/inc/intops.def
…check
- Revert INTOP_CALLDELEGATE_TAIL to oplength 4; tail calls use the simpler
callArgsOffset += INTERP_STACK_SLOT_SIZE approach matching the interpreted
tail path.
already makes sizeOfArgsUpto16ByteAlignment == targetArgsSize when no V128
arg exists.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings April 10, 2026 16:07
- Expand INTOP_CALLDELEGATE_TAIL to oplength 6 with size metadata
- Use ShiftDelegateCallArgs in interpreted tail path instead of
callArgsOffset + INTERP_STACK_SLOT_SIZE which breaks 16-byte alignment
- Use ShiftDelegateCallArgs unconditionally in compiled open virtual path
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 6 out of 6 changed files in this pull request and generated 2 comments.

Comments suppressed due to low confidence (1)

src/coreclr/vm/interpexec.cpp:3224

  • In the open-virtual + compiled-target path, the tailcall case adjusts callArgsOffset by one slot and then jumps to CALL_INTERP_METHOD. If CALL_INTERP_METHOD ends up invoking a compiled method (targetIp == NULL), the call stub expects the argument block to follow interpreter stack alignment rules from offset 0 (including 16-byte alignment for V128). Bumping the base pointer by 8 can violate those assumptions. Consider either applying the same alignment-preserving shift for this tailcall case (which likely means carrying the size metadata on INTOP_CALLDELEGATE_TAIL too), or falling back to the normal delegate invoke/shuffle-thunk path for tail calls when the resolved target is compiled.

if ((targetMethod = NonVirtualEntry2MethodDesc(targetAddress)) != NULL)
{
// In this case targetMethod holds a pointer to the MethodDesc that will be called by using targetMethodObj as
// the this pointer. This may be the final method (in the case of instance method delegates), or it may be a

Comment threadsrc/libraries/tests.proj Outdated
Comment threadsrc/coreclr/vm/interpexec.cpp
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

@janvorlijanvorli left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thank you!

@janvorli
janvorli merged commit d8e9ae7 into dotnet:mainApr 14, 2026
136 of 139 checks passed
@github-actionsgithub-actionsBot locked and limited conversation to collaborators May 15, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@kotlarmilos@BrzVlad@jkotas@janvorli
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[clr-ios] Fix SIGSEGV in open virtual delegate dispatch with interpreter - #126199

Merged
janvorli merged 13 commits into
dotnet:mainfrom
kotlarmilos:bugfix/clr-interpreter-open-delegate
Apr 14, 2026
Merged

[clr-ios] Fix SIGSEGV in open virtual delegate dispatch with interpreter#126199
janvorli merged 13 commits into
dotnet:mainfrom
kotlarmilos:bugfix/clr-interpreter-open-delegate

Conversation

@kotlarmilos

@kotlarmiloskotlarmilos commented Mar 27, 2026

Copy link
Copy Markdown
Member

Description

Fix a crash when the interpreter invokes a compiled open virtual delegate target.

When the interpreter's call delegate handler detects an open virtual delegate whose resolved target is compiled (targetIp == NULL), the code previously fell through to a generic path that called GetTarget() on the delegate. For open delegates, GetTarget() returns null, which corrupted the argument slot and caused a SIGSEGV.

The fix adds a dedicated path for open virtual delegates with compiled targets. It uses memmove to shift the call arguments down by one slot (removing the delegate object) while preserving 16-byte alignment for V128 arguments, then jumps to CALL_INTERP_METHOD to invoke the resolved targetMethod directly. The same shifting is applied for interpreted targets in the non-tail-call path. The alignment-preserving shift logic is extracted into a ShiftDelegateCallArgs() helper to avoid duplication.

Additionally, this re-enables test suites previously excluded under #124325 (except System.Runtime.Serialization.Xml.Tests, which hits a native stack overflow unrelated to this fix).

CopilotAI review requested due to automatic review settings March 27, 2026 13:09
@kotlarmiloskotlarmilos self-assigned this Mar 27, 2026
@kotlarmiloskotlarmilos added this to the 11.0.0 milestone Mar 27, 2026
@kotlarmiloskotlarmilos added the os-ios Apple iOS label Mar 27, 2026
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @BrzVlad, @janvorli, @kg
See info in area-owners.md if you want to be subscribed.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Fixes an interpreter crash on iOS when invoking compiled open virtual delegate targets, and updates AppleMobile/CoreCLR libraries test selection.

Changes:

  • Handle open virtual delegates whose resolved target has no interpreter bytecode (targetIp == NULL) by skipping the delegate argument slot and directly dispatching via CALL_INTERP_METHOD.
  • Remove several AppleMobile/CoreCLR test project exclusions from src/libraries/tests.proj.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 2 comments.

FileDescription
src/libraries/tests.projRemoves previously-added AppleMobile/CoreCLR test exclusions (re-enables several Serialization test projects).
src/coreclr/vm/interpexec.cppAdds a NULL-targetIp open-virtual delegate path that avoids GetTarget() and dispatches the resolved MethodDesc directly.

Comment threadsrc/libraries/tests.proj
Comment threadsrc/coreclr/vm/interpexec.cpp
Comment threadsrc/coreclr/vm/interpexec.cpp Outdated
@kotlarmilos

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-ioslike

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

Wrap the GetTarget/NonVirtualEntry2MethodDesc block in braces so the
CALL_DELEGATE_INVOKE goto can legally jump past the OBJECTREF variable
initialization.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings March 31, 2026 09:08

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.

Comment threadsrc/coreclr/vm/interpexec.cpp
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings April 8, 2026 08:36
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 6 out of 6 changed files in this pull request and generated 2 comments.

Comment threadsrc/coreclr/vm/interpexec.cpp
Comment threadsrc/coreclr/vm/interpexec.cpp Outdated
- Fix ShiftDelegateCallArgs memmove length to use totalArgsSize - firstAlignedDstOffset
instead of totalArgsSize - sizeOfArgsUpto16ByteAlignment to avoid reading past
actual argument data when pre-alignment size is not 16-byte aligned.
- Extend INTOP_CALLDELEGATE_TAIL to carry sizeOfArgsUpto16ByteAlignment and
targetArgsSize (oplength 4 -> 6) so the open virtual compiled target path
works correctly for tail calls.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@kotlarmilos

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-ioslike

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

Comment threadsrc/coreclr/vm/interpexec.cpp
Comment threadsrc/coreclr/interpreter/compiler.cpp Outdated
Comment threadsrc/coreclr/vm/interpexec.cpp
Comment threadsrc/coreclr/interpreter/inc/intops.def
…check
- Revert INTOP_CALLDELEGATE_TAIL to oplength 4; tail calls use the simpler
callArgsOffset += INTERP_STACK_SLOT_SIZE approach matching the interpreted
tail path.
already makes sizeOfArgsUpto16ByteAlignment == targetArgsSize when no V128
arg exists.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings April 10, 2026 16:07
- Expand INTOP_CALLDELEGATE_TAIL to oplength 6 with size metadata
- Use ShiftDelegateCallArgs in interpreted tail path instead of
callArgsOffset + INTERP_STACK_SLOT_SIZE which breaks 16-byte alignment
- Use ShiftDelegateCallArgs unconditionally in compiled open virtual path
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 6 out of 6 changed files in this pull request and generated 2 comments.

Comments suppressed due to low confidence (1)

src/coreclr/vm/interpexec.cpp:3224

  • In the open-virtual + compiled-target path, the tailcall case adjusts callArgsOffset by one slot and then jumps to CALL_INTERP_METHOD. If CALL_INTERP_METHOD ends up invoking a compiled method (targetIp == NULL), the call stub expects the argument block to follow interpreter stack alignment rules from offset 0 (including 16-byte alignment for V128). Bumping the base pointer by 8 can violate those assumptions. Consider either applying the same alignment-preserving shift for this tailcall case (which likely means carrying the size metadata on INTOP_CALLDELEGATE_TAIL too), or falling back to the normal delegate invoke/shuffle-thunk path for tail calls when the resolved target is compiled.

if ((targetMethod = NonVirtualEntry2MethodDesc(targetAddress)) != NULL)
{
// In this case targetMethod holds a pointer to the MethodDesc that will be called by using targetMethodObj as
// the this pointer. This may be the final method (in the case of instance method delegates), or it may be a

Comment threadsrc/libraries/tests.proj Outdated
Comment threadsrc/coreclr/vm/interpexec.cpp
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

@janvorlijanvorli left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thank you!

@janvorli
janvorli merged commit d8e9ae7 into dotnet:mainApr 14, 2026
136 of 139 checks passed
@github-actionsgithub-actionsBot locked and limited conversation to collaborators May 15, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@kotlarmilos@BrzVlad@jkotas@janvorli
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

[clr-ios] Fix SIGSEGV in open virtual delegate dispatch with interpreter - #126199

Merged
janvorli merged 13 commits into
dotnet:mainfrom
kotlarmilos:bugfix/clr-interpreter-open-delegate
Apr 14, 2026
Merged

[clr-ios] Fix SIGSEGV in open virtual delegate dispatch with interpreter#126199
janvorli merged 13 commits into
dotnet:mainfrom
kotlarmilos:bugfix/clr-interpreter-open-delegate

Conversation

@kotlarmilos

@kotlarmiloskotlarmilos commented Mar 27, 2026

Copy link
Copy Markdown
Member

Description

Fix a crash when the interpreter invokes a compiled open virtual delegate target.

When the interpreter's call delegate handler detects an open virtual delegate whose resolved target is compiled (targetIp == NULL), the code previously fell through to a generic path that called GetTarget() on the delegate. For open delegates, GetTarget() returns null, which corrupted the argument slot and caused a SIGSEGV.

The fix adds a dedicated path for open virtual delegates with compiled targets. It uses memmove to shift the call arguments down by one slot (removing the delegate object) while preserving 16-byte alignment for V128 arguments, then jumps to CALL_INTERP_METHOD to invoke the resolved targetMethod directly. The same shifting is applied for interpreted targets in the non-tail-call path. The alignment-preserving shift logic is extracted into a ShiftDelegateCallArgs() helper to avoid duplication.

Additionally, this re-enables test suites previously excluded under #124325 (except System.Runtime.Serialization.Xml.Tests, which hits a native stack overflow unrelated to this fix).

CopilotAI review requested due to automatic review settings March 27, 2026 13:09
@kotlarmiloskotlarmilos self-assigned this Mar 27, 2026
@kotlarmiloskotlarmilos added this to the 11.0.0 milestone Mar 27, 2026
@kotlarmiloskotlarmilos added the os-ios Apple iOS label Mar 27, 2026
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @BrzVlad, @janvorli, @kg
See info in area-owners.md if you want to be subscribed.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Fixes an interpreter crash on iOS when invoking compiled open virtual delegate targets, and updates AppleMobile/CoreCLR libraries test selection.

Changes:

  • Handle open virtual delegates whose resolved target has no interpreter bytecode (targetIp == NULL) by skipping the delegate argument slot and directly dispatching via CALL_INTERP_METHOD.
  • Remove several AppleMobile/CoreCLR test project exclusions from src/libraries/tests.proj.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 2 comments.

FileDescription
src/libraries/tests.projRemoves previously-added AppleMobile/CoreCLR test exclusions (re-enables several Serialization test projects).
src/coreclr/vm/interpexec.cppAdds a NULL-targetIp open-virtual delegate path that avoids GetTarget() and dispatches the resolved MethodDesc directly.

Comment threadsrc/libraries/tests.proj
Comment threadsrc/coreclr/vm/interpexec.cpp
Comment threadsrc/coreclr/vm/interpexec.cpp Outdated
@kotlarmilos

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-ioslike

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

Wrap the GetTarget/NonVirtualEntry2MethodDesc block in braces so the
CALL_DELEGATE_INVOKE goto can legally jump past the OBJECTREF variable
initialization.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings March 31, 2026 09:08

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.

Comment threadsrc/coreclr/vm/interpexec.cpp
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings April 8, 2026 08:36
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 6 out of 6 changed files in this pull request and generated 2 comments.

Comment threadsrc/coreclr/vm/interpexec.cpp
Comment threadsrc/coreclr/vm/interpexec.cpp Outdated
- Fix ShiftDelegateCallArgs memmove length to use totalArgsSize - firstAlignedDstOffset
instead of totalArgsSize - sizeOfArgsUpto16ByteAlignment to avoid reading past
actual argument data when pre-alignment size is not 16-byte aligned.
- Extend INTOP_CALLDELEGATE_TAIL to carry sizeOfArgsUpto16ByteAlignment and
targetArgsSize (oplength 4 -> 6) so the open virtual compiled target path
works correctly for tail calls.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@kotlarmilos

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-ioslike

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

Comment threadsrc/coreclr/vm/interpexec.cpp
Comment threadsrc/coreclr/interpreter/compiler.cpp Outdated
Comment threadsrc/coreclr/vm/interpexec.cpp
Comment threadsrc/coreclr/interpreter/inc/intops.def
…check
- Revert INTOP_CALLDELEGATE_TAIL to oplength 4; tail calls use the simpler
callArgsOffset += INTERP_STACK_SLOT_SIZE approach matching the interpreted
tail path.
already makes sizeOfArgsUpto16ByteAlignment == targetArgsSize when no V128
arg exists.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings April 10, 2026 16:07
- Expand INTOP_CALLDELEGATE_TAIL to oplength 6 with size metadata
- Use ShiftDelegateCallArgs in interpreted tail path instead of
callArgsOffset + INTERP_STACK_SLOT_SIZE which breaks 16-byte alignment
- Use ShiftDelegateCallArgs unconditionally in compiled open virtual path
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 6 out of 6 changed files in this pull request and generated 2 comments.

Comments suppressed due to low confidence (1)

src/coreclr/vm/interpexec.cpp:3224

  • In the open-virtual + compiled-target path, the tailcall case adjusts callArgsOffset by one slot and then jumps to CALL_INTERP_METHOD. If CALL_INTERP_METHOD ends up invoking a compiled method (targetIp == NULL), the call stub expects the argument block to follow interpreter stack alignment rules from offset 0 (including 16-byte alignment for V128). Bumping the base pointer by 8 can violate those assumptions. Consider either applying the same alignment-preserving shift for this tailcall case (which likely means carrying the size metadata on INTOP_CALLDELEGATE_TAIL too), or falling back to the normal delegate invoke/shuffle-thunk path for tail calls when the resolved target is compiled.

if ((targetMethod = NonVirtualEntry2MethodDesc(targetAddress)) != NULL)
{
// In this case targetMethod holds a pointer to the MethodDesc that will be called by using targetMethodObj as
// the this pointer. This may be the final method (in the case of instance method delegates), or it may be a

Comment threadsrc/libraries/tests.proj Outdated
Comment threadsrc/coreclr/vm/interpexec.cpp
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

@janvorlijanvorli left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thank you!

@janvorli
janvorli merged commit d8e9ae7 into dotnet:mainApr 14, 2026
136 of 139 checks passed
@github-actionsgithub-actionsBot locked and limited conversation to collaborators May 15, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@kotlarmilos@BrzVlad@jkotas@janvorli
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[clr-ios] Fix SIGSEGV in open virtual delegate dispatch with interpreter - #126199

Merged
janvorli merged 13 commits into
dotnet:mainfrom
kotlarmilos:bugfix/clr-interpreter-open-delegate
Apr 14, 2026
Merged

[clr-ios] Fix SIGSEGV in open virtual delegate dispatch with interpreter#126199
janvorli merged 13 commits into
dotnet:mainfrom
kotlarmilos:bugfix/clr-interpreter-open-delegate

Conversation

@kotlarmilos

@kotlarmiloskotlarmilos commented Mar 27, 2026

Copy link
Copy Markdown
Member

Description

Fix a crash when the interpreter invokes a compiled open virtual delegate target.

When the interpreter's call delegate handler detects an open virtual delegate whose resolved target is compiled (targetIp == NULL), the code previously fell through to a generic path that called GetTarget() on the delegate. For open delegates, GetTarget() returns null, which corrupted the argument slot and caused a SIGSEGV.

The fix adds a dedicated path for open virtual delegates with compiled targets. It uses memmove to shift the call arguments down by one slot (removing the delegate object) while preserving 16-byte alignment for V128 arguments, then jumps to CALL_INTERP_METHOD to invoke the resolved targetMethod directly. The same shifting is applied for interpreted targets in the non-tail-call path. The alignment-preserving shift logic is extracted into a ShiftDelegateCallArgs() helper to avoid duplication.

Additionally, this re-enables test suites previously excluded under #124325 (except System.Runtime.Serialization.Xml.Tests, which hits a native stack overflow unrelated to this fix).

CopilotAI review requested due to automatic review settings March 27, 2026 13:09
@kotlarmiloskotlarmilos self-assigned this Mar 27, 2026
@kotlarmiloskotlarmilos added this to the 11.0.0 milestone Mar 27, 2026
@kotlarmiloskotlarmilos added the os-ios Apple iOS label Mar 27, 2026
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @BrzVlad, @janvorli, @kg
See info in area-owners.md if you want to be subscribed.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Fixes an interpreter crash on iOS when invoking compiled open virtual delegate targets, and updates AppleMobile/CoreCLR libraries test selection.

Changes:

  • Handle open virtual delegates whose resolved target has no interpreter bytecode (targetIp == NULL) by skipping the delegate argument slot and directly dispatching via CALL_INTERP_METHOD.
  • Remove several AppleMobile/CoreCLR test project exclusions from src/libraries/tests.proj.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 2 comments.

FileDescription
src/libraries/tests.projRemoves previously-added AppleMobile/CoreCLR test exclusions (re-enables several Serialization test projects).
src/coreclr/vm/interpexec.cppAdds a NULL-targetIp open-virtual delegate path that avoids GetTarget() and dispatches the resolved MethodDesc directly.

Comment threadsrc/libraries/tests.proj
Comment threadsrc/coreclr/vm/interpexec.cpp
Comment threadsrc/coreclr/vm/interpexec.cpp Outdated
@kotlarmilos

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-ioslike

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

Wrap the GetTarget/NonVirtualEntry2MethodDesc block in braces so the
CALL_DELEGATE_INVOKE goto can legally jump past the OBJECTREF variable
initialization.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings March 31, 2026 09:08

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.

Comment threadsrc/coreclr/vm/interpexec.cpp
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings April 8, 2026 08:36
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 6 out of 6 changed files in this pull request and generated 2 comments.

Comment threadsrc/coreclr/vm/interpexec.cpp
Comment threadsrc/coreclr/vm/interpexec.cpp Outdated
- Fix ShiftDelegateCallArgs memmove length to use totalArgsSize - firstAlignedDstOffset
instead of totalArgsSize - sizeOfArgsUpto16ByteAlignment to avoid reading past
actual argument data when pre-alignment size is not 16-byte aligned.
- Extend INTOP_CALLDELEGATE_TAIL to carry sizeOfArgsUpto16ByteAlignment and
targetArgsSize (oplength 4 -> 6) so the open virtual compiled target path
works correctly for tail calls.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@kotlarmilos

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-ioslike

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

Comment threadsrc/coreclr/vm/interpexec.cpp
Comment threadsrc/coreclr/interpreter/compiler.cpp Outdated
Comment threadsrc/coreclr/vm/interpexec.cpp
Comment threadsrc/coreclr/interpreter/inc/intops.def
…check
- Revert INTOP_CALLDELEGATE_TAIL to oplength 4; tail calls use the simpler
callArgsOffset += INTERP_STACK_SLOT_SIZE approach matching the interpreted
tail path.
already makes sizeOfArgsUpto16ByteAlignment == targetArgsSize when no V128
arg exists.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings April 10, 2026 16:07
- Expand INTOP_CALLDELEGATE_TAIL to oplength 6 with size metadata
- Use ShiftDelegateCallArgs in interpreted tail path instead of
callArgsOffset + INTERP_STACK_SLOT_SIZE which breaks 16-byte alignment
- Use ShiftDelegateCallArgs unconditionally in compiled open virtual path
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 6 out of 6 changed files in this pull request and generated 2 comments.

Comments suppressed due to low confidence (1)

src/coreclr/vm/interpexec.cpp:3224

  • In the open-virtual + compiled-target path, the tailcall case adjusts callArgsOffset by one slot and then jumps to CALL_INTERP_METHOD. If CALL_INTERP_METHOD ends up invoking a compiled method (targetIp == NULL), the call stub expects the argument block to follow interpreter stack alignment rules from offset 0 (including 16-byte alignment for V128). Bumping the base pointer by 8 can violate those assumptions. Consider either applying the same alignment-preserving shift for this tailcall case (which likely means carrying the size metadata on INTOP_CALLDELEGATE_TAIL too), or falling back to the normal delegate invoke/shuffle-thunk path for tail calls when the resolved target is compiled.

if ((targetMethod = NonVirtualEntry2MethodDesc(targetAddress)) != NULL)
{
// In this case targetMethod holds a pointer to the MethodDesc that will be called by using targetMethodObj as
// the this pointer. This may be the final method (in the case of instance method delegates), or it may be a

Comment threadsrc/libraries/tests.proj Outdated
Comment threadsrc/coreclr/vm/interpexec.cpp
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

@janvorlijanvorli left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thank you!

@janvorli
janvorli merged commit d8e9ae7 into dotnet:mainApr 14, 2026
136 of 139 checks passed
@github-actionsgithub-actionsBot locked and limited conversation to collaborators May 15, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@kotlarmilos@BrzVlad@jkotas@janvorli
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[clr-ios] Fix SIGSEGV in open virtual delegate dispatch with interpreter - #126199

Merged
janvorli merged 13 commits into
dotnet:mainfrom
kotlarmilos:bugfix/clr-interpreter-open-delegate
Apr 14, 2026
Merged

[clr-ios] Fix SIGSEGV in open virtual delegate dispatch with interpreter#126199
janvorli merged 13 commits into
dotnet:mainfrom
kotlarmilos:bugfix/clr-interpreter-open-delegate

Conversation

@kotlarmilos

@kotlarmiloskotlarmilos commented Mar 27, 2026

Copy link
Copy Markdown
Member

Description

Fix a crash when the interpreter invokes a compiled open virtual delegate target.

When the interpreter's call delegate handler detects an open virtual delegate whose resolved target is compiled (targetIp == NULL), the code previously fell through to a generic path that called GetTarget() on the delegate. For open delegates, GetTarget() returns null, which corrupted the argument slot and caused a SIGSEGV.

The fix adds a dedicated path for open virtual delegates with compiled targets. It uses memmove to shift the call arguments down by one slot (removing the delegate object) while preserving 16-byte alignment for V128 arguments, then jumps to CALL_INTERP_METHOD to invoke the resolved targetMethod directly. The same shifting is applied for interpreted targets in the non-tail-call path. The alignment-preserving shift logic is extracted into a ShiftDelegateCallArgs() helper to avoid duplication.

Additionally, this re-enables test suites previously excluded under #124325 (except System.Runtime.Serialization.Xml.Tests, which hits a native stack overflow unrelated to this fix).

CopilotAI review requested due to automatic review settings March 27, 2026 13:09
@kotlarmiloskotlarmilos self-assigned this Mar 27, 2026
@kotlarmiloskotlarmilos added this to the 11.0.0 milestone Mar 27, 2026
@kotlarmiloskotlarmilos added the os-ios Apple iOS label Mar 27, 2026
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @BrzVlad, @janvorli, @kg
See info in area-owners.md if you want to be subscribed.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Fixes an interpreter crash on iOS when invoking compiled open virtual delegate targets, and updates AppleMobile/CoreCLR libraries test selection.

Changes:

  • Handle open virtual delegates whose resolved target has no interpreter bytecode (targetIp == NULL) by skipping the delegate argument slot and directly dispatching via CALL_INTERP_METHOD.
  • Remove several AppleMobile/CoreCLR test project exclusions from src/libraries/tests.proj.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 2 comments.

FileDescription
src/libraries/tests.projRemoves previously-added AppleMobile/CoreCLR test exclusions (re-enables several Serialization test projects).
src/coreclr/vm/interpexec.cppAdds a NULL-targetIp open-virtual delegate path that avoids GetTarget() and dispatches the resolved MethodDesc directly.

Comment threadsrc/libraries/tests.proj
Comment threadsrc/coreclr/vm/interpexec.cpp
Comment threadsrc/coreclr/vm/interpexec.cpp Outdated
@kotlarmilos

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-ioslike

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

Wrap the GetTarget/NonVirtualEntry2MethodDesc block in braces so the
CALL_DELEGATE_INVOKE goto can legally jump past the OBJECTREF variable
initialization.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings March 31, 2026 09:08

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.

Comment threadsrc/coreclr/vm/interpexec.cpp
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings April 8, 2026 08:36
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 6 out of 6 changed files in this pull request and generated 2 comments.

Comment threadsrc/coreclr/vm/interpexec.cpp
Comment threadsrc/coreclr/vm/interpexec.cpp Outdated
- Fix ShiftDelegateCallArgs memmove length to use totalArgsSize - firstAlignedDstOffset
instead of totalArgsSize - sizeOfArgsUpto16ByteAlignment to avoid reading past
actual argument data when pre-alignment size is not 16-byte aligned.
- Extend INTOP_CALLDELEGATE_TAIL to carry sizeOfArgsUpto16ByteAlignment and
targetArgsSize (oplength 4 -> 6) so the open virtual compiled target path
works correctly for tail calls.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@kotlarmilos

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-ioslike

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

Comment threadsrc/coreclr/vm/interpexec.cpp
Comment threadsrc/coreclr/interpreter/compiler.cpp Outdated
Comment threadsrc/coreclr/vm/interpexec.cpp
Comment threadsrc/coreclr/interpreter/inc/intops.def
…check
- Revert INTOP_CALLDELEGATE_TAIL to oplength 4; tail calls use the simpler
callArgsOffset += INTERP_STACK_SLOT_SIZE approach matching the interpreted
tail path.
already makes sizeOfArgsUpto16ByteAlignment == targetArgsSize when no V128
arg exists.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings April 10, 2026 16:07
- Expand INTOP_CALLDELEGATE_TAIL to oplength 6 with size metadata
- Use ShiftDelegateCallArgs in interpreted tail path instead of
callArgsOffset + INTERP_STACK_SLOT_SIZE which breaks 16-byte alignment
- Use ShiftDelegateCallArgs unconditionally in compiled open virtual path
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 6 out of 6 changed files in this pull request and generated 2 comments.

Comments suppressed due to low confidence (1)

src/coreclr/vm/interpexec.cpp:3224

  • In the open-virtual + compiled-target path, the tailcall case adjusts callArgsOffset by one slot and then jumps to CALL_INTERP_METHOD. If CALL_INTERP_METHOD ends up invoking a compiled method (targetIp == NULL), the call stub expects the argument block to follow interpreter stack alignment rules from offset 0 (including 16-byte alignment for V128). Bumping the base pointer by 8 can violate those assumptions. Consider either applying the same alignment-preserving shift for this tailcall case (which likely means carrying the size metadata on INTOP_CALLDELEGATE_TAIL too), or falling back to the normal delegate invoke/shuffle-thunk path for tail calls when the resolved target is compiled.

if ((targetMethod = NonVirtualEntry2MethodDesc(targetAddress)) != NULL)
{
// In this case targetMethod holds a pointer to the MethodDesc that will be called by using targetMethodObj as
// the this pointer. This may be the final method (in the case of instance method delegates), or it may be a

Comment threadsrc/libraries/tests.proj Outdated
Comment threadsrc/coreclr/vm/interpexec.cpp
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

@janvorlijanvorli left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thank you!

@janvorli
janvorli merged commit d8e9ae7 into dotnet:mainApr 14, 2026
136 of 139 checks passed
@github-actionsgithub-actionsBot locked and limited conversation to collaborators May 15, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@kotlarmilos@BrzVlad@jkotas@janvorli
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

[clr-ios] Fix SIGSEGV in open virtual delegate dispatch with interpreter - #126199

Merged
janvorli merged 13 commits into
dotnet:mainfrom
kotlarmilos:bugfix/clr-interpreter-open-delegate
Apr 14, 2026
Merged

[clr-ios] Fix SIGSEGV in open virtual delegate dispatch with interpreter#126199
janvorli merged 13 commits into
dotnet:mainfrom
kotlarmilos:bugfix/clr-interpreter-open-delegate

Conversation

@kotlarmilos

@kotlarmiloskotlarmilos commented Mar 27, 2026

Copy link
Copy Markdown
Member

Description

Fix a crash when the interpreter invokes a compiled open virtual delegate target.

When the interpreter's call delegate handler detects an open virtual delegate whose resolved target is compiled (targetIp == NULL), the code previously fell through to a generic path that called GetTarget() on the delegate. For open delegates, GetTarget() returns null, which corrupted the argument slot and caused a SIGSEGV.

The fix adds a dedicated path for open virtual delegates with compiled targets. It uses memmove to shift the call arguments down by one slot (removing the delegate object) while preserving 16-byte alignment for V128 arguments, then jumps to CALL_INTERP_METHOD to invoke the resolved targetMethod directly. The same shifting is applied for interpreted targets in the non-tail-call path. The alignment-preserving shift logic is extracted into a ShiftDelegateCallArgs() helper to avoid duplication.

Additionally, this re-enables test suites previously excluded under #124325 (except System.Runtime.Serialization.Xml.Tests, which hits a native stack overflow unrelated to this fix).

CopilotAI review requested due to automatic review settings March 27, 2026 13:09
@kotlarmiloskotlarmilos self-assigned this Mar 27, 2026
@kotlarmiloskotlarmilos added this to the 11.0.0 milestone Mar 27, 2026
@kotlarmiloskotlarmilos added the os-ios Apple iOS label Mar 27, 2026
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @BrzVlad, @janvorli, @kg
See info in area-owners.md if you want to be subscribed.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Fixes an interpreter crash on iOS when invoking compiled open virtual delegate targets, and updates AppleMobile/CoreCLR libraries test selection.

Changes:

  • Handle open virtual delegates whose resolved target has no interpreter bytecode (targetIp == NULL) by skipping the delegate argument slot and directly dispatching via CALL_INTERP_METHOD.
  • Remove several AppleMobile/CoreCLR test project exclusions from src/libraries/tests.proj.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 2 comments.

FileDescription
src/libraries/tests.projRemoves previously-added AppleMobile/CoreCLR test exclusions (re-enables several Serialization test projects).
src/coreclr/vm/interpexec.cppAdds a NULL-targetIp open-virtual delegate path that avoids GetTarget() and dispatches the resolved MethodDesc directly.

Comment threadsrc/libraries/tests.proj
Comment threadsrc/coreclr/vm/interpexec.cpp
Comment threadsrc/coreclr/vm/interpexec.cpp Outdated
@kotlarmilos

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-ioslike

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

Wrap the GetTarget/NonVirtualEntry2MethodDesc block in braces so the
CALL_DELEGATE_INVOKE goto can legally jump past the OBJECTREF variable
initialization.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings March 31, 2026 09:08

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.

Comment threadsrc/coreclr/vm/interpexec.cpp
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings April 8, 2026 08:36
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 6 out of 6 changed files in this pull request and generated 2 comments.

Comment threadsrc/coreclr/vm/interpexec.cpp
Comment threadsrc/coreclr/vm/interpexec.cpp Outdated
- Fix ShiftDelegateCallArgs memmove length to use totalArgsSize - firstAlignedDstOffset
instead of totalArgsSize - sizeOfArgsUpto16ByteAlignment to avoid reading past
actual argument data when pre-alignment size is not 16-byte aligned.
- Extend INTOP_CALLDELEGATE_TAIL to carry sizeOfArgsUpto16ByteAlignment and
targetArgsSize (oplength 4 -> 6) so the open virtual compiled target path
works correctly for tail calls.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@kotlarmilos

Copy link
Copy Markdown
MemberAuthor

/azp run runtime-ioslike

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines successfully started running 1 pipeline(s).

Comment threadsrc/coreclr/vm/interpexec.cpp
Comment threadsrc/coreclr/interpreter/compiler.cpp Outdated
Comment threadsrc/coreclr/vm/interpexec.cpp
Comment threadsrc/coreclr/interpreter/inc/intops.def
…check
- Revert INTOP_CALLDELEGATE_TAIL to oplength 4; tail calls use the simpler
callArgsOffset += INTERP_STACK_SLOT_SIZE approach matching the interpreted
tail path.
already makes sizeOfArgsUpto16ByteAlignment == targetArgsSize when no V128
arg exists.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings April 10, 2026 16:07
- Expand INTOP_CALLDELEGATE_TAIL to oplength 6 with size metadata
- Use ShiftDelegateCallArgs in interpreted tail path instead of
callArgsOffset + INTERP_STACK_SLOT_SIZE which breaks 16-byte alignment
- Use ShiftDelegateCallArgs unconditionally in compiled open virtual path
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 6 out of 6 changed files in this pull request and generated 2 comments.

Comments suppressed due to low confidence (1)

src/coreclr/vm/interpexec.cpp:3224

  • In the open-virtual + compiled-target path, the tailcall case adjusts callArgsOffset by one slot and then jumps to CALL_INTERP_METHOD. If CALL_INTERP_METHOD ends up invoking a compiled method (targetIp == NULL), the call stub expects the argument block to follow interpreter stack alignment rules from offset 0 (including 16-byte alignment for V128). Bumping the base pointer by 8 can violate those assumptions. Consider either applying the same alignment-preserving shift for this tailcall case (which likely means carrying the size metadata on INTOP_CALLDELEGATE_TAIL too), or falling back to the normal delegate invoke/shuffle-thunk path for tail calls when the resolved target is compiled.

if ((targetMethod = NonVirtualEntry2MethodDesc(targetAddress)) != NULL)
{
// In this case targetMethod holds a pointer to the MethodDesc that will be called by using targetMethodObj as
// the this pointer. This may be the final method (in the case of instance method delegates), or it may be a

Comment threadsrc/libraries/tests.proj Outdated
Comment threadsrc/coreclr/vm/interpexec.cpp
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

@janvorlijanvorli left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thank you!

@janvorli
janvorli merged commit d8e9ae7 into dotnet:mainApr 14, 2026
136 of 139 checks passed
@github-actionsgithub-actionsBot locked and limited conversation to collaborators May 15, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

@kotlarmilos@BrzVlad@jkotas@janvorli