Fix !m_RedirectContextInUse assert in RestoreContextSimulated on win-x86 - #127638

Merged
jkotas merged 3 commits into
mainfrom
copilot/fix-m-redirectcontextinuse-assert-win-x86
May 1, 2026
Merged

Fix !m_RedirectContextInUse assert in RestoreContextSimulated on win-x86#127638
jkotas merged 3 commits into
mainfrom
copilot/fix-m-redirectcontextinuse-assert-win-x86

Conversation

CopilotAI commented May 1, 2026

Copy link
Copy Markdown
Contributor

main PR

Description

On x86 Windows without RtlRestoreContext, RestoreContextSimulated called HandleThreadAbort() while m_RedirectContextInUse was still true. HandleThreadAbort() constructs a ThreadAbortException by running managed code (resource string loading, etc.), during which a concurrent GC redirect fires MarkRedirectContextInUse() → assert !m_RedirectContextInUse.

Fix: Move the RestoreContextSimulated call in RedirectedHandledJITCase to after the existing COMPlusCheckForAbort() block, so both the x86 SEH path and the RtlRestoreContext path share a single abort-check code path:

  • CopyOSContext + COMPlusCheckForAbort() (both NOTHROW/GC_NOTRIGGER — no managed code) run unconditionally for all platforms
  • If abort is pending, pCtx IP is redirected to ThrowControlForThread and the resume PC is stored in m_OSContext
  • For x86 without RtlRestoreContext, RestoreContextSimulated is then called (using the already-computed abort redirect); the EXCEPTION_HIJACK path in its exception filter pops the RedirectedThreadFrame and calls UnmarkRedirectContextInUse before resuming

RestoreContextSimulated itself is kept minimal — it contains only the SEH-based context-restore machinery with no abort logic. No code is duplicated between the two paths.

The abort exception is now raised only after the redirect context is fully released, eliminating the re-entrancy window.

Customer Impact

Checked (debug) builds of .NET on Windows x86 crash with STATUS_FAIL_FAST_EXCEPTION when ControlledExecution.Run (or any code path that triggers a thread abort) races with a GC redirect on the same thread. Release builds are not protected by the assert but the re-entrant redirect corrupts the saved context.

Regression

Not a regression introduced in the most recent release; latent race in the x86-only RestoreContextSimulated path.

Testing

Built clr.runtime (checked) with 0 errors/0 warnings. The affected code path is x86 Windows–specific (#ifdef TARGET_X86 / #ifndef TARGET_UNIX) and not exercisable in a Linux x64 CI environment; the fix aligns the x86 SEH path with the existing non-x86 abort-redirect pattern that is already proven correct on all other platforms.

Risk

Low. The change moves the RestoreContextSimulated call to after the shared COMPlusCheckForAbort block in RedirectedHandledJITCase, eliminating code duplication while preserving identical runtime behaviour. No new mechanism is introduced.

Package authoring no longer needed in .NET 9

IMPORTANT: Starting with .NET 9, you no longer need to edit a NuGet package's csproj to enable building and bump the version.
Keep in mind that we still need package authoring in .NET 8 and older versions.

CopilotAI requested review from Copilot and removed request for CopilotMay 1, 2026 05:32
CopilotAI linked an issue May 1, 2026 that may be closed by this pull request
…ort() with COMPlusCheckForAbort() in RestoreContextSimulated
Agent-Logs-Url: https://github.com/dotnet/runtime/sessions/8fa490ef-11e1-443a-bf1d-8d2d2dc09add
Co-authored-by: jkotas <6668460+jkotas@users.noreply.github.com>
CopilotAI requested review from Copilot and removed request for CopilotMay 1, 2026 05:51
CopilotAI changed the title [WIP] Fix !m_RedirectContextInUse assert on win-x86Fix !m_RedirectContextInUse assert in RestoreContextSimulated on win-x86May 1, 2026
CopilotAI requested a review from jkotasMay 1, 2026 05:52
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @agocke
See info in area-owners.md if you want to be subscribed.

Comment threadsrc/coreclr/vm/threadsuspend.cpp Outdated
…rectedHandledJITCase
Agent-Logs-Url: https://github.com/dotnet/runtime/sessions/c055bf10-808a-4e92-9cee-1841d7cfd155
Co-authored-by: jkotas <6668460+jkotas@users.noreply.github.com>
CopilotAI requested review from Copilot and removed request for CopilotMay 1, 2026 19:08
CopilotAI requested a review from jkotasMay 1, 2026 19:09
@jkotas
jkotas marked this pull request as ready for review May 1, 2026 19:11
CopilotAI review requested due to automatic review settings May 1, 2026 19:11
@jkotas
jkotas requested review from VSadov and mangod9May 1, 2026 19:11

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes a win-x86-specific debug assert (!m_RedirectContextInUse) by removing a re-entrancy window where RestoreContextSimulated could call HandleThreadAbort() while the redirect context was still marked “in use”. The change aligns the x86 SEH-based restore path with the existing shared abort-check flow used by the RtlRestoreContext path.

Changes:

  • Remove the HandleThreadAbort() call from RestoreContextSimulated so it performs only the SEH-based context restore mechanics.
  • Move the x86 “no RtlRestoreContext” call to RestoreContextSimulated to after the shared CopyOSContext + COMPlusCheckForAbort() logic in RedirectedHandledJITCase.

@jkotas
jkotas enabled auto-merge (squash) May 1, 2026 19:18
@jkotas
jkotas merged commit bd9e85e into mainMay 1, 2026
111 checks passed
@jkotas
jkotas deleted the copilot/fix-m-redirectcontextinuse-assert-win-x86 branch May 1, 2026 21:47
@daigs

Copy link
Copy Markdown
40814980-e5ae-4bf4-b22f-ee1d240d9164

@VSadov

Copy link
Copy Markdown
Member

/backport to release/10.0

@github-actions

Copy link
Copy Markdown
Contributor

Started backporting to release/10.0 (link to workflow run)

@github-actionsgithub-actionsBot unlocked this conversation Jul 20, 2026
@github-actions

Copy link
Copy Markdown
Contributor

@VSadov backporting to release/10.0 failed, the patch most likely resulted in conflicts. Please backport manually!

git am output
$ git am --3way --empty=keep --ignore-whitespace --keep-non-patch changes.patchCreating an empty commit: Initial planApplying: Fix !m_RedirectContextInUse assert on win-x86: replace HandleThreadAbort() with COMPlusCheckForAbort() in RestoreContextSimulatedApplying: Refactor: move RestoreContextSimulated call after abort check in RedirectedHandledJITCaseerror: sha1 information is lacking or useless (src/coreclr/vm/threadsuspend.cpp).error: could not build fake ancestorhint: Use 'git am --show-current-patch=diff' to see the failed patchhint: When you have resolved this problem, run "git am --continue".hint: If you prefer to skip this patch, run "git am --skip" instead.hint: To restore the original branch and stop patching, run "git am --abort".hint: Disable this message with "git config set advice.mergeConflict false"Patch failed at 0003 Refactor: move RestoreContextSimulated call after abort check in RedirectedHandledJITCaseError: The process '/usr/bin/git' failed with exit code 128

Link to workflow output

@github-actionsgithub-actionsBot locked as resolved and limited conversation to collaborators Jul 20, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

!m_RedirectContextInUse Assert on win-x86

6 participants

@daigs@VSadov@jkotas@mangod9
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Fix !m_RedirectContextInUse assert in RestoreContextSimulated on win-x86 - #127638

Merged
jkotas merged 3 commits into
mainfrom
copilot/fix-m-redirectcontextinuse-assert-win-x86
May 1, 2026
Merged

Fix !m_RedirectContextInUse assert in RestoreContextSimulated on win-x86#127638
jkotas merged 3 commits into
mainfrom
copilot/fix-m-redirectcontextinuse-assert-win-x86

Conversation

CopilotAI commented May 1, 2026

Copy link
Copy Markdown
Contributor

main PR

Description

On x86 Windows without RtlRestoreContext, RestoreContextSimulated called HandleThreadAbort() while m_RedirectContextInUse was still true. HandleThreadAbort() constructs a ThreadAbortException by running managed code (resource string loading, etc.), during which a concurrent GC redirect fires MarkRedirectContextInUse() → assert !m_RedirectContextInUse.

Fix: Move the RestoreContextSimulated call in RedirectedHandledJITCase to after the existing COMPlusCheckForAbort() block, so both the x86 SEH path and the RtlRestoreContext path share a single abort-check code path:

  • CopyOSContext + COMPlusCheckForAbort() (both NOTHROW/GC_NOTRIGGER — no managed code) run unconditionally for all platforms
  • If abort is pending, pCtx IP is redirected to ThrowControlForThread and the resume PC is stored in m_OSContext
  • For x86 without RtlRestoreContext, RestoreContextSimulated is then called (using the already-computed abort redirect); the EXCEPTION_HIJACK path in its exception filter pops the RedirectedThreadFrame and calls UnmarkRedirectContextInUse before resuming

RestoreContextSimulated itself is kept minimal — it contains only the SEH-based context-restore machinery with no abort logic. No code is duplicated between the two paths.

The abort exception is now raised only after the redirect context is fully released, eliminating the re-entrancy window.

Customer Impact

Checked (debug) builds of .NET on Windows x86 crash with STATUS_FAIL_FAST_EXCEPTION when ControlledExecution.Run (or any code path that triggers a thread abort) races with a GC redirect on the same thread. Release builds are not protected by the assert but the re-entrant redirect corrupts the saved context.

Regression

Not a regression introduced in the most recent release; latent race in the x86-only RestoreContextSimulated path.

Testing

Built clr.runtime (checked) with 0 errors/0 warnings. The affected code path is x86 Windows–specific (#ifdef TARGET_X86 / #ifndef TARGET_UNIX) and not exercisable in a Linux x64 CI environment; the fix aligns the x86 SEH path with the existing non-x86 abort-redirect pattern that is already proven correct on all other platforms.

Risk

Low. The change moves the RestoreContextSimulated call to after the shared COMPlusCheckForAbort block in RedirectedHandledJITCase, eliminating code duplication while preserving identical runtime behaviour. No new mechanism is introduced.

Package authoring no longer needed in .NET 9

IMPORTANT: Starting with .NET 9, you no longer need to edit a NuGet package's csproj to enable building and bump the version.
Keep in mind that we still need package authoring in .NET 8 and older versions.

CopilotAI requested review from Copilot and removed request for CopilotMay 1, 2026 05:32
CopilotAI linked an issue May 1, 2026 that may be closed by this pull request
…ort() with COMPlusCheckForAbort() in RestoreContextSimulated
Agent-Logs-Url: https://github.com/dotnet/runtime/sessions/8fa490ef-11e1-443a-bf1d-8d2d2dc09add
Co-authored-by: jkotas <6668460+jkotas@users.noreply.github.com>
CopilotAI requested review from Copilot and removed request for CopilotMay 1, 2026 05:51
CopilotAI changed the title [WIP] Fix !m_RedirectContextInUse assert on win-x86Fix !m_RedirectContextInUse assert in RestoreContextSimulated on win-x86May 1, 2026
CopilotAI requested a review from jkotasMay 1, 2026 05:52
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @agocke
See info in area-owners.md if you want to be subscribed.

Comment threadsrc/coreclr/vm/threadsuspend.cpp Outdated
…rectedHandledJITCase
Agent-Logs-Url: https://github.com/dotnet/runtime/sessions/c055bf10-808a-4e92-9cee-1841d7cfd155
Co-authored-by: jkotas <6668460+jkotas@users.noreply.github.com>
CopilotAI requested review from Copilot and removed request for CopilotMay 1, 2026 19:08
CopilotAI requested a review from jkotasMay 1, 2026 19:09
@jkotas
jkotas marked this pull request as ready for review May 1, 2026 19:11
CopilotAI review requested due to automatic review settings May 1, 2026 19:11
@jkotas
jkotas requested review from VSadov and mangod9May 1, 2026 19:11

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes a win-x86-specific debug assert (!m_RedirectContextInUse) by removing a re-entrancy window where RestoreContextSimulated could call HandleThreadAbort() while the redirect context was still marked “in use”. The change aligns the x86 SEH-based restore path with the existing shared abort-check flow used by the RtlRestoreContext path.

Changes:

  • Remove the HandleThreadAbort() call from RestoreContextSimulated so it performs only the SEH-based context restore mechanics.
  • Move the x86 “no RtlRestoreContext” call to RestoreContextSimulated to after the shared CopyOSContext + COMPlusCheckForAbort() logic in RedirectedHandledJITCase.

@jkotas
jkotas enabled auto-merge (squash) May 1, 2026 19:18
@jkotas
jkotas merged commit bd9e85e into mainMay 1, 2026
111 checks passed
@jkotas
jkotas deleted the copilot/fix-m-redirectcontextinuse-assert-win-x86 branch May 1, 2026 21:47
@daigs

Copy link
Copy Markdown
40814980-e5ae-4bf4-b22f-ee1d240d9164

@VSadov

Copy link
Copy Markdown
Member

/backport to release/10.0

@github-actions

Copy link
Copy Markdown
Contributor

Started backporting to release/10.0 (link to workflow run)

@github-actionsgithub-actionsBot unlocked this conversation Jul 20, 2026
@github-actions

Copy link
Copy Markdown
Contributor

@VSadov backporting to release/10.0 failed, the patch most likely resulted in conflicts. Please backport manually!

git am output
$ git am --3way --empty=keep --ignore-whitespace --keep-non-patch changes.patchCreating an empty commit: Initial planApplying: Fix !m_RedirectContextInUse assert on win-x86: replace HandleThreadAbort() with COMPlusCheckForAbort() in RestoreContextSimulatedApplying: Refactor: move RestoreContextSimulated call after abort check in RedirectedHandledJITCaseerror: sha1 information is lacking or useless (src/coreclr/vm/threadsuspend.cpp).error: could not build fake ancestorhint: Use 'git am --show-current-patch=diff' to see the failed patchhint: When you have resolved this problem, run "git am --continue".hint: If you prefer to skip this patch, run "git am --skip" instead.hint: To restore the original branch and stop patching, run "git am --abort".hint: Disable this message with "git config set advice.mergeConflict false"Patch failed at 0003 Refactor: move RestoreContextSimulated call after abort check in RedirectedHandledJITCaseError: The process '/usr/bin/git' failed with exit code 128

Link to workflow output

@github-actionsgithub-actionsBot locked as resolved and limited conversation to collaborators Jul 20, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

!m_RedirectContextInUse Assert on win-x86

6 participants

@daigs@VSadov@jkotas@mangod9
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Fix !m_RedirectContextInUse assert in RestoreContextSimulated on win-x86 - #127638

Merged
jkotas merged 3 commits into
mainfrom
copilot/fix-m-redirectcontextinuse-assert-win-x86
May 1, 2026
Merged

Fix !m_RedirectContextInUse assert in RestoreContextSimulated on win-x86#127638
jkotas merged 3 commits into
mainfrom
copilot/fix-m-redirectcontextinuse-assert-win-x86

Conversation

CopilotAI commented May 1, 2026

Copy link
Copy Markdown
Contributor

main PR

Description

On x86 Windows without RtlRestoreContext, RestoreContextSimulated called HandleThreadAbort() while m_RedirectContextInUse was still true. HandleThreadAbort() constructs a ThreadAbortException by running managed code (resource string loading, etc.), during which a concurrent GC redirect fires MarkRedirectContextInUse() → assert !m_RedirectContextInUse.

Fix: Move the RestoreContextSimulated call in RedirectedHandledJITCase to after the existing COMPlusCheckForAbort() block, so both the x86 SEH path and the RtlRestoreContext path share a single abort-check code path:

  • CopyOSContext + COMPlusCheckForAbort() (both NOTHROW/GC_NOTRIGGER — no managed code) run unconditionally for all platforms
  • If abort is pending, pCtx IP is redirected to ThrowControlForThread and the resume PC is stored in m_OSContext
  • For x86 without RtlRestoreContext, RestoreContextSimulated is then called (using the already-computed abort redirect); the EXCEPTION_HIJACK path in its exception filter pops the RedirectedThreadFrame and calls UnmarkRedirectContextInUse before resuming

RestoreContextSimulated itself is kept minimal — it contains only the SEH-based context-restore machinery with no abort logic. No code is duplicated between the two paths.

The abort exception is now raised only after the redirect context is fully released, eliminating the re-entrancy window.

Customer Impact

Checked (debug) builds of .NET on Windows x86 crash with STATUS_FAIL_FAST_EXCEPTION when ControlledExecution.Run (or any code path that triggers a thread abort) races with a GC redirect on the same thread. Release builds are not protected by the assert but the re-entrant redirect corrupts the saved context.

Regression

Not a regression introduced in the most recent release; latent race in the x86-only RestoreContextSimulated path.

Testing

Built clr.runtime (checked) with 0 errors/0 warnings. The affected code path is x86 Windows–specific (#ifdef TARGET_X86 / #ifndef TARGET_UNIX) and not exercisable in a Linux x64 CI environment; the fix aligns the x86 SEH path with the existing non-x86 abort-redirect pattern that is already proven correct on all other platforms.

Risk

Low. The change moves the RestoreContextSimulated call to after the shared COMPlusCheckForAbort block in RedirectedHandledJITCase, eliminating code duplication while preserving identical runtime behaviour. No new mechanism is introduced.

Package authoring no longer needed in .NET 9

IMPORTANT: Starting with .NET 9, you no longer need to edit a NuGet package's csproj to enable building and bump the version.
Keep in mind that we still need package authoring in .NET 8 and older versions.

CopilotAI requested review from Copilot and removed request for CopilotMay 1, 2026 05:32
CopilotAI linked an issue May 1, 2026 that may be closed by this pull request
…ort() with COMPlusCheckForAbort() in RestoreContextSimulated
Agent-Logs-Url: https://github.com/dotnet/runtime/sessions/8fa490ef-11e1-443a-bf1d-8d2d2dc09add
Co-authored-by: jkotas <6668460+jkotas@users.noreply.github.com>
CopilotAI requested review from Copilot and removed request for CopilotMay 1, 2026 05:51
CopilotAI changed the title [WIP] Fix !m_RedirectContextInUse assert on win-x86Fix !m_RedirectContextInUse assert in RestoreContextSimulated on win-x86May 1, 2026
CopilotAI requested a review from jkotasMay 1, 2026 05:52
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @agocke
See info in area-owners.md if you want to be subscribed.

Comment threadsrc/coreclr/vm/threadsuspend.cpp Outdated
…rectedHandledJITCase
Agent-Logs-Url: https://github.com/dotnet/runtime/sessions/c055bf10-808a-4e92-9cee-1841d7cfd155
Co-authored-by: jkotas <6668460+jkotas@users.noreply.github.com>
CopilotAI requested review from Copilot and removed request for CopilotMay 1, 2026 19:08
CopilotAI requested a review from jkotasMay 1, 2026 19:09
@jkotas
jkotas marked this pull request as ready for review May 1, 2026 19:11
CopilotAI review requested due to automatic review settings May 1, 2026 19:11
@jkotas
jkotas requested review from VSadov and mangod9May 1, 2026 19:11

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes a win-x86-specific debug assert (!m_RedirectContextInUse) by removing a re-entrancy window where RestoreContextSimulated could call HandleThreadAbort() while the redirect context was still marked “in use”. The change aligns the x86 SEH-based restore path with the existing shared abort-check flow used by the RtlRestoreContext path.

Changes:

  • Remove the HandleThreadAbort() call from RestoreContextSimulated so it performs only the SEH-based context restore mechanics.
  • Move the x86 “no RtlRestoreContext” call to RestoreContextSimulated to after the shared CopyOSContext + COMPlusCheckForAbort() logic in RedirectedHandledJITCase.

@jkotas
jkotas enabled auto-merge (squash) May 1, 2026 19:18
@jkotas
jkotas merged commit bd9e85e into mainMay 1, 2026
111 checks passed
@jkotas
jkotas deleted the copilot/fix-m-redirectcontextinuse-assert-win-x86 branch May 1, 2026 21:47
@daigs

Copy link
Copy Markdown
40814980-e5ae-4bf4-b22f-ee1d240d9164

@VSadov

Copy link
Copy Markdown
Member

/backport to release/10.0

@github-actions

Copy link
Copy Markdown
Contributor

Started backporting to release/10.0 (link to workflow run)

@github-actionsgithub-actionsBot unlocked this conversation Jul 20, 2026
@github-actions

Copy link
Copy Markdown
Contributor

@VSadov backporting to release/10.0 failed, the patch most likely resulted in conflicts. Please backport manually!

git am output
$ git am --3way --empty=keep --ignore-whitespace --keep-non-patch changes.patchCreating an empty commit: Initial planApplying: Fix !m_RedirectContextInUse assert on win-x86: replace HandleThreadAbort() with COMPlusCheckForAbort() in RestoreContextSimulatedApplying: Refactor: move RestoreContextSimulated call after abort check in RedirectedHandledJITCaseerror: sha1 information is lacking or useless (src/coreclr/vm/threadsuspend.cpp).error: could not build fake ancestorhint: Use 'git am --show-current-patch=diff' to see the failed patchhint: When you have resolved this problem, run "git am --continue".hint: If you prefer to skip this patch, run "git am --skip" instead.hint: To restore the original branch and stop patching, run "git am --abort".hint: Disable this message with "git config set advice.mergeConflict false"Patch failed at 0003 Refactor: move RestoreContextSimulated call after abort check in RedirectedHandledJITCaseError: The process '/usr/bin/git' failed with exit code 128

Link to workflow output

@github-actionsgithub-actionsBot locked as resolved and limited conversation to collaborators Jul 20, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

!m_RedirectContextInUse Assert on win-x86

6 participants

@daigs@VSadov@jkotas@mangod9
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Fix !m_RedirectContextInUse assert in RestoreContextSimulated on win-x86 - #127638

Merged
jkotas merged 3 commits into
mainfrom
copilot/fix-m-redirectcontextinuse-assert-win-x86
May 1, 2026
Merged

Fix !m_RedirectContextInUse assert in RestoreContextSimulated on win-x86#127638
jkotas merged 3 commits into
mainfrom
copilot/fix-m-redirectcontextinuse-assert-win-x86

Conversation

CopilotAI commented May 1, 2026

Copy link
Copy Markdown
Contributor

main PR

Description

On x86 Windows without RtlRestoreContext, RestoreContextSimulated called HandleThreadAbort() while m_RedirectContextInUse was still true. HandleThreadAbort() constructs a ThreadAbortException by running managed code (resource string loading, etc.), during which a concurrent GC redirect fires MarkRedirectContextInUse() → assert !m_RedirectContextInUse.

Fix: Move the RestoreContextSimulated call in RedirectedHandledJITCase to after the existing COMPlusCheckForAbort() block, so both the x86 SEH path and the RtlRestoreContext path share a single abort-check code path:

  • CopyOSContext + COMPlusCheckForAbort() (both NOTHROW/GC_NOTRIGGER — no managed code) run unconditionally for all platforms
  • If abort is pending, pCtx IP is redirected to ThrowControlForThread and the resume PC is stored in m_OSContext
  • For x86 without RtlRestoreContext, RestoreContextSimulated is then called (using the already-computed abort redirect); the EXCEPTION_HIJACK path in its exception filter pops the RedirectedThreadFrame and calls UnmarkRedirectContextInUse before resuming

RestoreContextSimulated itself is kept minimal — it contains only the SEH-based context-restore machinery with no abort logic. No code is duplicated between the two paths.

The abort exception is now raised only after the redirect context is fully released, eliminating the re-entrancy window.

Customer Impact

Checked (debug) builds of .NET on Windows x86 crash with STATUS_FAIL_FAST_EXCEPTION when ControlledExecution.Run (or any code path that triggers a thread abort) races with a GC redirect on the same thread. Release builds are not protected by the assert but the re-entrant redirect corrupts the saved context.

Regression

Not a regression introduced in the most recent release; latent race in the x86-only RestoreContextSimulated path.

Testing

Built clr.runtime (checked) with 0 errors/0 warnings. The affected code path is x86 Windows–specific (#ifdef TARGET_X86 / #ifndef TARGET_UNIX) and not exercisable in a Linux x64 CI environment; the fix aligns the x86 SEH path with the existing non-x86 abort-redirect pattern that is already proven correct on all other platforms.

Risk

Low. The change moves the RestoreContextSimulated call to after the shared COMPlusCheckForAbort block in RedirectedHandledJITCase, eliminating code duplication while preserving identical runtime behaviour. No new mechanism is introduced.

Package authoring no longer needed in .NET 9

IMPORTANT: Starting with .NET 9, you no longer need to edit a NuGet package's csproj to enable building and bump the version.
Keep in mind that we still need package authoring in .NET 8 and older versions.

CopilotAI requested review from Copilot and removed request for CopilotMay 1, 2026 05:32
CopilotAI linked an issue May 1, 2026 that may be closed by this pull request
…ort() with COMPlusCheckForAbort() in RestoreContextSimulated
Agent-Logs-Url: https://github.com/dotnet/runtime/sessions/8fa490ef-11e1-443a-bf1d-8d2d2dc09add
Co-authored-by: jkotas <6668460+jkotas@users.noreply.github.com>
CopilotAI requested review from Copilot and removed request for CopilotMay 1, 2026 05:51
CopilotAI changed the title [WIP] Fix !m_RedirectContextInUse assert on win-x86Fix !m_RedirectContextInUse assert in RestoreContextSimulated on win-x86May 1, 2026
CopilotAI requested a review from jkotasMay 1, 2026 05:52
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @agocke
See info in area-owners.md if you want to be subscribed.

Comment threadsrc/coreclr/vm/threadsuspend.cpp Outdated
…rectedHandledJITCase
Agent-Logs-Url: https://github.com/dotnet/runtime/sessions/c055bf10-808a-4e92-9cee-1841d7cfd155
Co-authored-by: jkotas <6668460+jkotas@users.noreply.github.com>
CopilotAI requested review from Copilot and removed request for CopilotMay 1, 2026 19:08
CopilotAI requested a review from jkotasMay 1, 2026 19:09
@jkotas
jkotas marked this pull request as ready for review May 1, 2026 19:11
CopilotAI review requested due to automatic review settings May 1, 2026 19:11
@jkotas
jkotas requested review from VSadov and mangod9May 1, 2026 19:11

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes a win-x86-specific debug assert (!m_RedirectContextInUse) by removing a re-entrancy window where RestoreContextSimulated could call HandleThreadAbort() while the redirect context was still marked “in use”. The change aligns the x86 SEH-based restore path with the existing shared abort-check flow used by the RtlRestoreContext path.

Changes:

  • Remove the HandleThreadAbort() call from RestoreContextSimulated so it performs only the SEH-based context restore mechanics.
  • Move the x86 “no RtlRestoreContext” call to RestoreContextSimulated to after the shared CopyOSContext + COMPlusCheckForAbort() logic in RedirectedHandledJITCase.

@jkotas
jkotas enabled auto-merge (squash) May 1, 2026 19:18
@jkotas
jkotas merged commit bd9e85e into mainMay 1, 2026
111 checks passed
@jkotas
jkotas deleted the copilot/fix-m-redirectcontextinuse-assert-win-x86 branch May 1, 2026 21:47
@daigs

Copy link
Copy Markdown
40814980-e5ae-4bf4-b22f-ee1d240d9164

@VSadov

Copy link
Copy Markdown
Member

/backport to release/10.0

@github-actions

Copy link
Copy Markdown
Contributor

Started backporting to release/10.0 (link to workflow run)

@github-actionsgithub-actionsBot unlocked this conversation Jul 20, 2026
@github-actions

Copy link
Copy Markdown
Contributor

@VSadov backporting to release/10.0 failed, the patch most likely resulted in conflicts. Please backport manually!

git am output
$ git am --3way --empty=keep --ignore-whitespace --keep-non-patch changes.patchCreating an empty commit: Initial planApplying: Fix !m_RedirectContextInUse assert on win-x86: replace HandleThreadAbort() with COMPlusCheckForAbort() in RestoreContextSimulatedApplying: Refactor: move RestoreContextSimulated call after abort check in RedirectedHandledJITCaseerror: sha1 information is lacking or useless (src/coreclr/vm/threadsuspend.cpp).error: could not build fake ancestorhint: Use 'git am --show-current-patch=diff' to see the failed patchhint: When you have resolved this problem, run "git am --continue".hint: If you prefer to skip this patch, run "git am --skip" instead.hint: To restore the original branch and stop patching, run "git am --abort".hint: Disable this message with "git config set advice.mergeConflict false"Patch failed at 0003 Refactor: move RestoreContextSimulated call after abort check in RedirectedHandledJITCaseError: The process '/usr/bin/git' failed with exit code 128

Link to workflow output

@github-actionsgithub-actionsBot locked as resolved and limited conversation to collaborators Jul 20, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

!m_RedirectContextInUse Assert on win-x86

6 participants

@daigs@VSadov@jkotas@mangod9
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Fix !m_RedirectContextInUse assert in RestoreContextSimulated on win-x86 - #127638

Merged
jkotas merged 3 commits into
mainfrom
copilot/fix-m-redirectcontextinuse-assert-win-x86
May 1, 2026
Merged

Fix !m_RedirectContextInUse assert in RestoreContextSimulated on win-x86#127638
jkotas merged 3 commits into
mainfrom
copilot/fix-m-redirectcontextinuse-assert-win-x86

Conversation

CopilotAI commented May 1, 2026

Copy link
Copy Markdown
Contributor

main PR

Description

On x86 Windows without RtlRestoreContext, RestoreContextSimulated called HandleThreadAbort() while m_RedirectContextInUse was still true. HandleThreadAbort() constructs a ThreadAbortException by running managed code (resource string loading, etc.), during which a concurrent GC redirect fires MarkRedirectContextInUse() → assert !m_RedirectContextInUse.

Fix: Move the RestoreContextSimulated call in RedirectedHandledJITCase to after the existing COMPlusCheckForAbort() block, so both the x86 SEH path and the RtlRestoreContext path share a single abort-check code path:

  • CopyOSContext + COMPlusCheckForAbort() (both NOTHROW/GC_NOTRIGGER — no managed code) run unconditionally for all platforms
  • If abort is pending, pCtx IP is redirected to ThrowControlForThread and the resume PC is stored in m_OSContext
  • For x86 without RtlRestoreContext, RestoreContextSimulated is then called (using the already-computed abort redirect); the EXCEPTION_HIJACK path in its exception filter pops the RedirectedThreadFrame and calls UnmarkRedirectContextInUse before resuming

RestoreContextSimulated itself is kept minimal — it contains only the SEH-based context-restore machinery with no abort logic. No code is duplicated between the two paths.

The abort exception is now raised only after the redirect context is fully released, eliminating the re-entrancy window.

Customer Impact

Checked (debug) builds of .NET on Windows x86 crash with STATUS_FAIL_FAST_EXCEPTION when ControlledExecution.Run (or any code path that triggers a thread abort) races with a GC redirect on the same thread. Release builds are not protected by the assert but the re-entrant redirect corrupts the saved context.

Regression

Not a regression introduced in the most recent release; latent race in the x86-only RestoreContextSimulated path.

Testing

Built clr.runtime (checked) with 0 errors/0 warnings. The affected code path is x86 Windows–specific (#ifdef TARGET_X86 / #ifndef TARGET_UNIX) and not exercisable in a Linux x64 CI environment; the fix aligns the x86 SEH path with the existing non-x86 abort-redirect pattern that is already proven correct on all other platforms.

Risk

Low. The change moves the RestoreContextSimulated call to after the shared COMPlusCheckForAbort block in RedirectedHandledJITCase, eliminating code duplication while preserving identical runtime behaviour. No new mechanism is introduced.

Package authoring no longer needed in .NET 9

IMPORTANT: Starting with .NET 9, you no longer need to edit a NuGet package's csproj to enable building and bump the version.
Keep in mind that we still need package authoring in .NET 8 and older versions.

CopilotAI requested review from Copilot and removed request for CopilotMay 1, 2026 05:32
CopilotAI linked an issue May 1, 2026 that may be closed by this pull request
…ort() with COMPlusCheckForAbort() in RestoreContextSimulated
Agent-Logs-Url: https://github.com/dotnet/runtime/sessions/8fa490ef-11e1-443a-bf1d-8d2d2dc09add
Co-authored-by: jkotas <6668460+jkotas@users.noreply.github.com>
CopilotAI requested review from Copilot and removed request for CopilotMay 1, 2026 05:51
CopilotAI changed the title [WIP] Fix !m_RedirectContextInUse assert on win-x86Fix !m_RedirectContextInUse assert in RestoreContextSimulated on win-x86May 1, 2026
CopilotAI requested a review from jkotasMay 1, 2026 05:52
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @agocke
See info in area-owners.md if you want to be subscribed.

Comment threadsrc/coreclr/vm/threadsuspend.cpp Outdated
…rectedHandledJITCase
Agent-Logs-Url: https://github.com/dotnet/runtime/sessions/c055bf10-808a-4e92-9cee-1841d7cfd155
Co-authored-by: jkotas <6668460+jkotas@users.noreply.github.com>
CopilotAI requested review from Copilot and removed request for CopilotMay 1, 2026 19:08
CopilotAI requested a review from jkotasMay 1, 2026 19:09
@jkotas
jkotas marked this pull request as ready for review May 1, 2026 19:11
CopilotAI review requested due to automatic review settings May 1, 2026 19:11
@jkotas
jkotas requested review from VSadov and mangod9May 1, 2026 19:11

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes a win-x86-specific debug assert (!m_RedirectContextInUse) by removing a re-entrancy window where RestoreContextSimulated could call HandleThreadAbort() while the redirect context was still marked “in use”. The change aligns the x86 SEH-based restore path with the existing shared abort-check flow used by the RtlRestoreContext path.

Changes:

  • Remove the HandleThreadAbort() call from RestoreContextSimulated so it performs only the SEH-based context restore mechanics.
  • Move the x86 “no RtlRestoreContext” call to RestoreContextSimulated to after the shared CopyOSContext + COMPlusCheckForAbort() logic in RedirectedHandledJITCase.

@jkotas
jkotas enabled auto-merge (squash) May 1, 2026 19:18
@jkotas
jkotas merged commit bd9e85e into mainMay 1, 2026
111 checks passed
@jkotas
jkotas deleted the copilot/fix-m-redirectcontextinuse-assert-win-x86 branch May 1, 2026 21:47
@daigs

Copy link
Copy Markdown
40814980-e5ae-4bf4-b22f-ee1d240d9164

@VSadov

Copy link
Copy Markdown
Member

/backport to release/10.0

@github-actions

Copy link
Copy Markdown
Contributor

Started backporting to release/10.0 (link to workflow run)

@github-actionsgithub-actionsBot unlocked this conversation Jul 20, 2026
@github-actions

Copy link
Copy Markdown
Contributor

@VSadov backporting to release/10.0 failed, the patch most likely resulted in conflicts. Please backport manually!

git am output
$ git am --3way --empty=keep --ignore-whitespace --keep-non-patch changes.patchCreating an empty commit: Initial planApplying: Fix !m_RedirectContextInUse assert on win-x86: replace HandleThreadAbort() with COMPlusCheckForAbort() in RestoreContextSimulatedApplying: Refactor: move RestoreContextSimulated call after abort check in RedirectedHandledJITCaseerror: sha1 information is lacking or useless (src/coreclr/vm/threadsuspend.cpp).error: could not build fake ancestorhint: Use 'git am --show-current-patch=diff' to see the failed patchhint: When you have resolved this problem, run "git am --continue".hint: If you prefer to skip this patch, run "git am --skip" instead.hint: To restore the original branch and stop patching, run "git am --abort".hint: Disable this message with "git config set advice.mergeConflict false"Patch failed at 0003 Refactor: move RestoreContextSimulated call after abort check in RedirectedHandledJITCaseError: The process '/usr/bin/git' failed with exit code 128

Link to workflow output

@github-actionsgithub-actionsBot locked as resolved and limited conversation to collaborators Jul 20, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

!m_RedirectContextInUse Assert on win-x86

6 participants

@daigs@VSadov@jkotas@mangod9
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Fix !m_RedirectContextInUse assert in RestoreContextSimulated on win-x86 - #127638

Merged
jkotas merged 3 commits into
mainfrom
copilot/fix-m-redirectcontextinuse-assert-win-x86
May 1, 2026
Merged

Fix !m_RedirectContextInUse assert in RestoreContextSimulated on win-x86#127638
jkotas merged 3 commits into
mainfrom
copilot/fix-m-redirectcontextinuse-assert-win-x86

Conversation

CopilotAI commented May 1, 2026

Copy link
Copy Markdown
Contributor

main PR

Description

On x86 Windows without RtlRestoreContext, RestoreContextSimulated called HandleThreadAbort() while m_RedirectContextInUse was still true. HandleThreadAbort() constructs a ThreadAbortException by running managed code (resource string loading, etc.), during which a concurrent GC redirect fires MarkRedirectContextInUse() → assert !m_RedirectContextInUse.

Fix: Move the RestoreContextSimulated call in RedirectedHandledJITCase to after the existing COMPlusCheckForAbort() block, so both the x86 SEH path and the RtlRestoreContext path share a single abort-check code path:

  • CopyOSContext + COMPlusCheckForAbort() (both NOTHROW/GC_NOTRIGGER — no managed code) run unconditionally for all platforms
  • If abort is pending, pCtx IP is redirected to ThrowControlForThread and the resume PC is stored in m_OSContext
  • For x86 without RtlRestoreContext, RestoreContextSimulated is then called (using the already-computed abort redirect); the EXCEPTION_HIJACK path in its exception filter pops the RedirectedThreadFrame and calls UnmarkRedirectContextInUse before resuming

RestoreContextSimulated itself is kept minimal — it contains only the SEH-based context-restore machinery with no abort logic. No code is duplicated between the two paths.

The abort exception is now raised only after the redirect context is fully released, eliminating the re-entrancy window.

Customer Impact

Checked (debug) builds of .NET on Windows x86 crash with STATUS_FAIL_FAST_EXCEPTION when ControlledExecution.Run (or any code path that triggers a thread abort) races with a GC redirect on the same thread. Release builds are not protected by the assert but the re-entrant redirect corrupts the saved context.

Regression

Not a regression introduced in the most recent release; latent race in the x86-only RestoreContextSimulated path.

Testing

Built clr.runtime (checked) with 0 errors/0 warnings. The affected code path is x86 Windows–specific (#ifdef TARGET_X86 / #ifndef TARGET_UNIX) and not exercisable in a Linux x64 CI environment; the fix aligns the x86 SEH path with the existing non-x86 abort-redirect pattern that is already proven correct on all other platforms.

Risk

Low. The change moves the RestoreContextSimulated call to after the shared COMPlusCheckForAbort block in RedirectedHandledJITCase, eliminating code duplication while preserving identical runtime behaviour. No new mechanism is introduced.

Package authoring no longer needed in .NET 9

IMPORTANT: Starting with .NET 9, you no longer need to edit a NuGet package's csproj to enable building and bump the version.
Keep in mind that we still need package authoring in .NET 8 and older versions.

CopilotAI requested review from Copilot and removed request for CopilotMay 1, 2026 05:32
CopilotAI linked an issue May 1, 2026 that may be closed by this pull request
…ort() with COMPlusCheckForAbort() in RestoreContextSimulated
Agent-Logs-Url: https://github.com/dotnet/runtime/sessions/8fa490ef-11e1-443a-bf1d-8d2d2dc09add
Co-authored-by: jkotas <6668460+jkotas@users.noreply.github.com>
CopilotAI requested review from Copilot and removed request for CopilotMay 1, 2026 05:51
CopilotAI changed the title [WIP] Fix !m_RedirectContextInUse assert on win-x86Fix !m_RedirectContextInUse assert in RestoreContextSimulated on win-x86May 1, 2026
CopilotAI requested a review from jkotasMay 1, 2026 05:52
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @agocke
See info in area-owners.md if you want to be subscribed.

Comment threadsrc/coreclr/vm/threadsuspend.cpp Outdated
…rectedHandledJITCase
Agent-Logs-Url: https://github.com/dotnet/runtime/sessions/c055bf10-808a-4e92-9cee-1841d7cfd155
Co-authored-by: jkotas <6668460+jkotas@users.noreply.github.com>
CopilotAI requested review from Copilot and removed request for CopilotMay 1, 2026 19:08
CopilotAI requested a review from jkotasMay 1, 2026 19:09
@jkotas
jkotas marked this pull request as ready for review May 1, 2026 19:11
CopilotAI review requested due to automatic review settings May 1, 2026 19:11
@jkotas
jkotas requested review from VSadov and mangod9May 1, 2026 19:11

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes a win-x86-specific debug assert (!m_RedirectContextInUse) by removing a re-entrancy window where RestoreContextSimulated could call HandleThreadAbort() while the redirect context was still marked “in use”. The change aligns the x86 SEH-based restore path with the existing shared abort-check flow used by the RtlRestoreContext path.

Changes:

  • Remove the HandleThreadAbort() call from RestoreContextSimulated so it performs only the SEH-based context restore mechanics.
  • Move the x86 “no RtlRestoreContext” call to RestoreContextSimulated to after the shared CopyOSContext + COMPlusCheckForAbort() logic in RedirectedHandledJITCase.

@jkotas
jkotas enabled auto-merge (squash) May 1, 2026 19:18
@jkotas
jkotas merged commit bd9e85e into mainMay 1, 2026
111 checks passed
@jkotas
jkotas deleted the copilot/fix-m-redirectcontextinuse-assert-win-x86 branch May 1, 2026 21:47
@daigs

Copy link
Copy Markdown
40814980-e5ae-4bf4-b22f-ee1d240d9164

@VSadov

Copy link
Copy Markdown
Member

/backport to release/10.0

@github-actions

Copy link
Copy Markdown
Contributor

Started backporting to release/10.0 (link to workflow run)

@github-actionsgithub-actionsBot unlocked this conversation Jul 20, 2026
@github-actions

Copy link
Copy Markdown
Contributor

@VSadov backporting to release/10.0 failed, the patch most likely resulted in conflicts. Please backport manually!

git am output
$ git am --3way --empty=keep --ignore-whitespace --keep-non-patch changes.patchCreating an empty commit: Initial planApplying: Fix !m_RedirectContextInUse assert on win-x86: replace HandleThreadAbort() with COMPlusCheckForAbort() in RestoreContextSimulatedApplying: Refactor: move RestoreContextSimulated call after abort check in RedirectedHandledJITCaseerror: sha1 information is lacking or useless (src/coreclr/vm/threadsuspend.cpp).error: could not build fake ancestorhint: Use 'git am --show-current-patch=diff' to see the failed patchhint: When you have resolved this problem, run "git am --continue".hint: If you prefer to skip this patch, run "git am --skip" instead.hint: To restore the original branch and stop patching, run "git am --abort".hint: Disable this message with "git config set advice.mergeConflict false"Patch failed at 0003 Refactor: move RestoreContextSimulated call after abort check in RedirectedHandledJITCaseError: The process '/usr/bin/git' failed with exit code 128

Link to workflow output

@github-actionsgithub-actionsBot locked as resolved and limited conversation to collaborators Jul 20, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

!m_RedirectContextInUse Assert on win-x86

6 participants

@daigs@VSadov@jkotas@mangod9
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Fix !m_RedirectContextInUse assert in RestoreContextSimulated on win-x86 - #127638

Merged
jkotas merged 3 commits into
mainfrom
copilot/fix-m-redirectcontextinuse-assert-win-x86
May 1, 2026
Merged

Fix !m_RedirectContextInUse assert in RestoreContextSimulated on win-x86#127638
jkotas merged 3 commits into
mainfrom
copilot/fix-m-redirectcontextinuse-assert-win-x86

Conversation

CopilotAI commented May 1, 2026

Copy link
Copy Markdown
Contributor

main PR

Description

On x86 Windows without RtlRestoreContext, RestoreContextSimulated called HandleThreadAbort() while m_RedirectContextInUse was still true. HandleThreadAbort() constructs a ThreadAbortException by running managed code (resource string loading, etc.), during which a concurrent GC redirect fires MarkRedirectContextInUse() → assert !m_RedirectContextInUse.

Fix: Move the RestoreContextSimulated call in RedirectedHandledJITCase to after the existing COMPlusCheckForAbort() block, so both the x86 SEH path and the RtlRestoreContext path share a single abort-check code path:

  • CopyOSContext + COMPlusCheckForAbort() (both NOTHROW/GC_NOTRIGGER — no managed code) run unconditionally for all platforms
  • If abort is pending, pCtx IP is redirected to ThrowControlForThread and the resume PC is stored in m_OSContext
  • For x86 without RtlRestoreContext, RestoreContextSimulated is then called (using the already-computed abort redirect); the EXCEPTION_HIJACK path in its exception filter pops the RedirectedThreadFrame and calls UnmarkRedirectContextInUse before resuming

RestoreContextSimulated itself is kept minimal — it contains only the SEH-based context-restore machinery with no abort logic. No code is duplicated between the two paths.

The abort exception is now raised only after the redirect context is fully released, eliminating the re-entrancy window.

Customer Impact

Checked (debug) builds of .NET on Windows x86 crash with STATUS_FAIL_FAST_EXCEPTION when ControlledExecution.Run (or any code path that triggers a thread abort) races with a GC redirect on the same thread. Release builds are not protected by the assert but the re-entrant redirect corrupts the saved context.

Regression

Not a regression introduced in the most recent release; latent race in the x86-only RestoreContextSimulated path.

Testing

Built clr.runtime (checked) with 0 errors/0 warnings. The affected code path is x86 Windows–specific (#ifdef TARGET_X86 / #ifndef TARGET_UNIX) and not exercisable in a Linux x64 CI environment; the fix aligns the x86 SEH path with the existing non-x86 abort-redirect pattern that is already proven correct on all other platforms.

Risk

Low. The change moves the RestoreContextSimulated call to after the shared COMPlusCheckForAbort block in RedirectedHandledJITCase, eliminating code duplication while preserving identical runtime behaviour. No new mechanism is introduced.

Package authoring no longer needed in .NET 9

IMPORTANT: Starting with .NET 9, you no longer need to edit a NuGet package's csproj to enable building and bump the version.
Keep in mind that we still need package authoring in .NET 8 and older versions.

CopilotAI requested review from Copilot and removed request for CopilotMay 1, 2026 05:32
CopilotAI linked an issue May 1, 2026 that may be closed by this pull request
…ort() with COMPlusCheckForAbort() in RestoreContextSimulated
Agent-Logs-Url: https://github.com/dotnet/runtime/sessions/8fa490ef-11e1-443a-bf1d-8d2d2dc09add
Co-authored-by: jkotas <6668460+jkotas@users.noreply.github.com>
CopilotAI requested review from Copilot and removed request for CopilotMay 1, 2026 05:51
CopilotAI changed the title [WIP] Fix !m_RedirectContextInUse assert on win-x86Fix !m_RedirectContextInUse assert in RestoreContextSimulated on win-x86May 1, 2026
CopilotAI requested a review from jkotasMay 1, 2026 05:52
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @agocke
See info in area-owners.md if you want to be subscribed.

Comment threadsrc/coreclr/vm/threadsuspend.cpp Outdated
…rectedHandledJITCase
Agent-Logs-Url: https://github.com/dotnet/runtime/sessions/c055bf10-808a-4e92-9cee-1841d7cfd155
Co-authored-by: jkotas <6668460+jkotas@users.noreply.github.com>
CopilotAI requested review from Copilot and removed request for CopilotMay 1, 2026 19:08
CopilotAI requested a review from jkotasMay 1, 2026 19:09
@jkotas
jkotas marked this pull request as ready for review May 1, 2026 19:11
CopilotAI review requested due to automatic review settings May 1, 2026 19:11
@jkotas
jkotas requested review from VSadov and mangod9May 1, 2026 19:11

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes a win-x86-specific debug assert (!m_RedirectContextInUse) by removing a re-entrancy window where RestoreContextSimulated could call HandleThreadAbort() while the redirect context was still marked “in use”. The change aligns the x86 SEH-based restore path with the existing shared abort-check flow used by the RtlRestoreContext path.

Changes:

  • Remove the HandleThreadAbort() call from RestoreContextSimulated so it performs only the SEH-based context restore mechanics.
  • Move the x86 “no RtlRestoreContext” call to RestoreContextSimulated to after the shared CopyOSContext + COMPlusCheckForAbort() logic in RedirectedHandledJITCase.

@jkotas
jkotas enabled auto-merge (squash) May 1, 2026 19:18
@jkotas
jkotas merged commit bd9e85e into mainMay 1, 2026
111 checks passed
@jkotas
jkotas deleted the copilot/fix-m-redirectcontextinuse-assert-win-x86 branch May 1, 2026 21:47
@daigs

Copy link
Copy Markdown
40814980-e5ae-4bf4-b22f-ee1d240d9164

@VSadov

Copy link
Copy Markdown
Member

/backport to release/10.0

@github-actions

Copy link
Copy Markdown
Contributor

Started backporting to release/10.0 (link to workflow run)

@github-actionsgithub-actionsBot unlocked this conversation Jul 20, 2026
@github-actions

Copy link
Copy Markdown
Contributor

@VSadov backporting to release/10.0 failed, the patch most likely resulted in conflicts. Please backport manually!

git am output
$ git am --3way --empty=keep --ignore-whitespace --keep-non-patch changes.patchCreating an empty commit: Initial planApplying: Fix !m_RedirectContextInUse assert on win-x86: replace HandleThreadAbort() with COMPlusCheckForAbort() in RestoreContextSimulatedApplying: Refactor: move RestoreContextSimulated call after abort check in RedirectedHandledJITCaseerror: sha1 information is lacking or useless (src/coreclr/vm/threadsuspend.cpp).error: could not build fake ancestorhint: Use 'git am --show-current-patch=diff' to see the failed patchhint: When you have resolved this problem, run "git am --continue".hint: If you prefer to skip this patch, run "git am --skip" instead.hint: To restore the original branch and stop patching, run "git am --abort".hint: Disable this message with "git config set advice.mergeConflict false"Patch failed at 0003 Refactor: move RestoreContextSimulated call after abort check in RedirectedHandledJITCaseError: The process '/usr/bin/git' failed with exit code 128

Link to workflow output

@github-actionsgithub-actionsBot locked as resolved and limited conversation to collaborators Jul 20, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

!m_RedirectContextInUse Assert on win-x86

6 participants

@daigs@VSadov@jkotas@mangod9
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Fix !m_RedirectContextInUse assert in RestoreContextSimulated on win-x86 - #127638

Merged
jkotas merged 3 commits into
mainfrom
copilot/fix-m-redirectcontextinuse-assert-win-x86
May 1, 2026
Merged

Fix !m_RedirectContextInUse assert in RestoreContextSimulated on win-x86#127638
jkotas merged 3 commits into
mainfrom
copilot/fix-m-redirectcontextinuse-assert-win-x86

Conversation

CopilotAI commented May 1, 2026

Copy link
Copy Markdown
Contributor

main PR

Description

On x86 Windows without RtlRestoreContext, RestoreContextSimulated called HandleThreadAbort() while m_RedirectContextInUse was still true. HandleThreadAbort() constructs a ThreadAbortException by running managed code (resource string loading, etc.), during which a concurrent GC redirect fires MarkRedirectContextInUse() → assert !m_RedirectContextInUse.

Fix: Move the RestoreContextSimulated call in RedirectedHandledJITCase to after the existing COMPlusCheckForAbort() block, so both the x86 SEH path and the RtlRestoreContext path share a single abort-check code path:

  • CopyOSContext + COMPlusCheckForAbort() (both NOTHROW/GC_NOTRIGGER — no managed code) run unconditionally for all platforms
  • If abort is pending, pCtx IP is redirected to ThrowControlForThread and the resume PC is stored in m_OSContext
  • For x86 without RtlRestoreContext, RestoreContextSimulated is then called (using the already-computed abort redirect); the EXCEPTION_HIJACK path in its exception filter pops the RedirectedThreadFrame and calls UnmarkRedirectContextInUse before resuming

RestoreContextSimulated itself is kept minimal — it contains only the SEH-based context-restore machinery with no abort logic. No code is duplicated between the two paths.

The abort exception is now raised only after the redirect context is fully released, eliminating the re-entrancy window.

Customer Impact

Checked (debug) builds of .NET on Windows x86 crash with STATUS_FAIL_FAST_EXCEPTION when ControlledExecution.Run (or any code path that triggers a thread abort) races with a GC redirect on the same thread. Release builds are not protected by the assert but the re-entrant redirect corrupts the saved context.

Regression

Not a regression introduced in the most recent release; latent race in the x86-only RestoreContextSimulated path.

Testing

Built clr.runtime (checked) with 0 errors/0 warnings. The affected code path is x86 Windows–specific (#ifdef TARGET_X86 / #ifndef TARGET_UNIX) and not exercisable in a Linux x64 CI environment; the fix aligns the x86 SEH path with the existing non-x86 abort-redirect pattern that is already proven correct on all other platforms.

Risk

Low. The change moves the RestoreContextSimulated call to after the shared COMPlusCheckForAbort block in RedirectedHandledJITCase, eliminating code duplication while preserving identical runtime behaviour. No new mechanism is introduced.

Package authoring no longer needed in .NET 9

IMPORTANT: Starting with .NET 9, you no longer need to edit a NuGet package's csproj to enable building and bump the version.
Keep in mind that we still need package authoring in .NET 8 and older versions.

CopilotAI requested review from Copilot and removed request for CopilotMay 1, 2026 05:32
CopilotAI linked an issue May 1, 2026 that may be closed by this pull request
…ort() with COMPlusCheckForAbort() in RestoreContextSimulated
Agent-Logs-Url: https://github.com/dotnet/runtime/sessions/8fa490ef-11e1-443a-bf1d-8d2d2dc09add
Co-authored-by: jkotas <6668460+jkotas@users.noreply.github.com>
CopilotAI requested review from Copilot and removed request for CopilotMay 1, 2026 05:51
CopilotAI changed the title [WIP] Fix !m_RedirectContextInUse assert on win-x86Fix !m_RedirectContextInUse assert in RestoreContextSimulated on win-x86May 1, 2026
CopilotAI requested a review from jkotasMay 1, 2026 05:52
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @agocke
See info in area-owners.md if you want to be subscribed.

Comment threadsrc/coreclr/vm/threadsuspend.cpp Outdated
…rectedHandledJITCase
Agent-Logs-Url: https://github.com/dotnet/runtime/sessions/c055bf10-808a-4e92-9cee-1841d7cfd155
Co-authored-by: jkotas <6668460+jkotas@users.noreply.github.com>
CopilotAI requested review from Copilot and removed request for CopilotMay 1, 2026 19:08
CopilotAI requested a review from jkotasMay 1, 2026 19:09
@jkotas
jkotas marked this pull request as ready for review May 1, 2026 19:11
CopilotAI review requested due to automatic review settings May 1, 2026 19:11
@jkotas
jkotas requested review from VSadov and mangod9May 1, 2026 19:11

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes a win-x86-specific debug assert (!m_RedirectContextInUse) by removing a re-entrancy window where RestoreContextSimulated could call HandleThreadAbort() while the redirect context was still marked “in use”. The change aligns the x86 SEH-based restore path with the existing shared abort-check flow used by the RtlRestoreContext path.

Changes:

  • Remove the HandleThreadAbort() call from RestoreContextSimulated so it performs only the SEH-based context restore mechanics.
  • Move the x86 “no RtlRestoreContext” call to RestoreContextSimulated to after the shared CopyOSContext + COMPlusCheckForAbort() logic in RedirectedHandledJITCase.

@jkotas
jkotas enabled auto-merge (squash) May 1, 2026 19:18
@jkotas
jkotas merged commit bd9e85e into mainMay 1, 2026
111 checks passed
@jkotas
jkotas deleted the copilot/fix-m-redirectcontextinuse-assert-win-x86 branch May 1, 2026 21:47
@daigs

Copy link
Copy Markdown
40814980-e5ae-4bf4-b22f-ee1d240d9164

@VSadov

Copy link
Copy Markdown
Member

/backport to release/10.0

@github-actions

Copy link
Copy Markdown
Contributor

Started backporting to release/10.0 (link to workflow run)

@github-actionsgithub-actionsBot unlocked this conversation Jul 20, 2026
@github-actions

Copy link
Copy Markdown
Contributor

@VSadov backporting to release/10.0 failed, the patch most likely resulted in conflicts. Please backport manually!

git am output
$ git am --3way --empty=keep --ignore-whitespace --keep-non-patch changes.patchCreating an empty commit: Initial planApplying: Fix !m_RedirectContextInUse assert on win-x86: replace HandleThreadAbort() with COMPlusCheckForAbort() in RestoreContextSimulatedApplying: Refactor: move RestoreContextSimulated call after abort check in RedirectedHandledJITCaseerror: sha1 information is lacking or useless (src/coreclr/vm/threadsuspend.cpp).error: could not build fake ancestorhint: Use 'git am --show-current-patch=diff' to see the failed patchhint: When you have resolved this problem, run "git am --continue".hint: If you prefer to skip this patch, run "git am --skip" instead.hint: To restore the original branch and stop patching, run "git am --abort".hint: Disable this message with "git config set advice.mergeConflict false"Patch failed at 0003 Refactor: move RestoreContextSimulated call after abort check in RedirectedHandledJITCaseError: The process '/usr/bin/git' failed with exit code 128

Link to workflow output

@github-actionsgithub-actionsBot locked as resolved and limited conversation to collaborators Jul 20, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

!m_RedirectContextInUse Assert on win-x86

6 participants

@daigs@VSadov@jkotas@mangod9