Skip to content

JIT: don't narrow relocatable handle constants in optNarrowTree - #129519

Merged
EgorBo merged 3 commits into
dotnet:mainfrom
EgorBo:fix-129504-narrow-reloc-handle
Jun 17, 2026
Merged

JIT: don't narrow relocatable handle constants in optNarrowTree#129519
EgorBo merged 3 commits into
dotnet:mainfrom
EgorBo:fix-129504-narrow-reloc-handle

Conversation

@EgorBo

@EgorBoEgorBo commented Jun 17, 2026

Copy link
Copy Markdown
Member

Fixes#129504.

Note

This PR (code and description) was generated with the assistance of GitHub Copilot.

optNarrowTree could narrow a GT_CNS_INT handle to TYP_INT whenever its
value happened to fit in 32 bits. For a relocatable handle (e.g. a
function-address handle that is the operand of the fat-pointer check
NE(AND(fptr, 2), 0)), this made ARM64 codegen materialize the address
with a 32-bit adrp+add (0x11000000) while still recording a 64-bit
PAGEOFFSET_12A relocation, tripping the (addInstr & 0xFFC00000) ==
0x91000000 assert in the NativeAOT relocation writer.
The bug was latent and only became observable on checked/debug NativeAOT
once handle values stopped carrying a high tag bit (so they fit in
int32). Guard the GT_CNS_INT narrowing on !ImmedValNeedsReloc so handle
constants keep their pointer width.
Fixesdotnet#129504
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 17, 2026 14:06
@github-actionsgithub-actionsBot added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label Jun 17, 2026
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
See info in area-owners.md if you want to be subscribed.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the CoreCLR JIT narrowing logic to avoid narrowing relocatable handle constants during optNarrowTree, preventing the backend from selecting 32-bit instruction forms for values that must be materialized as pointer-sized addresses (notably relevant for ARM64 NativeAOT relocations).

Changes:

  • Add an early-exit in Compiler::optNarrowTree for GT_CNS_INT when ImmedValNeedsReloc(this) is true, disallowing narrowing of relocatable icon-handle constants.

Comment threadsrc/coreclr/jit/optimizer.cpp Outdated
@EgorBo

Copy link
Copy Markdown
MemberAuthor

PTAL @dotnet/jit-contrib yet another transformation on a relocable CNS_INT handle

@EgorBo
EgorBo enabled auto-merge (squash) June 17, 2026 16:49
@EgorBo

Copy link
Copy Markdown
MemberAuthor

/ba-g timeouts

@EgorBo
EgorBo merged commit 0c15cff into dotnet:mainJun 17, 2026
131 of 137 checks passed
@EgorBo
EgorBo deleted the fix-129504-narrow-reloc-handle branch June 17, 2026 20:22
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-preview6 milestone Jun 18, 2026
eiriktsarpalis pushed a commit that referenced this pull request Jul 15, 2026
)
Fixes#129504.
> [!NOTE]
> This PR (code and description) was generated with the assistance of
GitHub Copilot.
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Jul 19, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Incorrect ARM64_PAGEOFFSET_12A relocations getting generated

3 participants

@EgorBo@jakobbotsch
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
JIT: don't narrow relocatable handle constants in optNarrowTree by EgorBo · Pull Request #129519 · dotnet/runtime · GitHub
Skip to content

JIT: don't narrow relocatable handle constants in optNarrowTree - #129519

Merged
EgorBo merged 3 commits into
dotnet:mainfrom
EgorBo:fix-129504-narrow-reloc-handle
Jun 17, 2026
Merged

JIT: don't narrow relocatable handle constants in optNarrowTree#129519
EgorBo merged 3 commits into
dotnet:mainfrom
EgorBo:fix-129504-narrow-reloc-handle

Conversation

@EgorBo

@EgorBoEgorBo commented Jun 17, 2026

Copy link
Copy Markdown
Member

Fixes#129504.

Note

This PR (code and description) was generated with the assistance of GitHub Copilot.

optNarrowTree could narrow a GT_CNS_INT handle to TYP_INT whenever its
value happened to fit in 32 bits. For a relocatable handle (e.g. a
function-address handle that is the operand of the fat-pointer check
NE(AND(fptr, 2), 0)), this made ARM64 codegen materialize the address
with a 32-bit adrp+add (0x11000000) while still recording a 64-bit
PAGEOFFSET_12A relocation, tripping the (addInstr & 0xFFC00000) ==
0x91000000 assert in the NativeAOT relocation writer.
The bug was latent and only became observable on checked/debug NativeAOT
once handle values stopped carrying a high tag bit (so they fit in
int32). Guard the GT_CNS_INT narrowing on !ImmedValNeedsReloc so handle
constants keep their pointer width.
Fixesdotnet#129504
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 17, 2026 14:06
@github-actionsgithub-actionsBot added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label Jun 17, 2026
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
See info in area-owners.md if you want to be subscribed.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the CoreCLR JIT narrowing logic to avoid narrowing relocatable handle constants during optNarrowTree, preventing the backend from selecting 32-bit instruction forms for values that must be materialized as pointer-sized addresses (notably relevant for ARM64 NativeAOT relocations).

Changes:

  • Add an early-exit in Compiler::optNarrowTree for GT_CNS_INT when ImmedValNeedsReloc(this) is true, disallowing narrowing of relocatable icon-handle constants.

Comment threadsrc/coreclr/jit/optimizer.cpp Outdated
@EgorBo

Copy link
Copy Markdown
MemberAuthor

PTAL @dotnet/jit-contrib yet another transformation on a relocable CNS_INT handle

@EgorBo
EgorBo enabled auto-merge (squash) June 17, 2026 16:49
@EgorBo

Copy link
Copy Markdown
MemberAuthor

/ba-g timeouts

@EgorBo
EgorBo merged commit 0c15cff into dotnet:mainJun 17, 2026
131 of 137 checks passed
@EgorBo
EgorBo deleted the fix-129504-narrow-reloc-handle branch June 17, 2026 20:22
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-preview6 milestone Jun 18, 2026
eiriktsarpalis pushed a commit that referenced this pull request Jul 15, 2026
)
Fixes#129504.
> [!NOTE]
> This PR (code and description) was generated with the assistance of
GitHub Copilot.
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Jul 19, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Incorrect ARM64_PAGEOFFSET_12A relocations getting generated

3 participants

@EgorBo@jakobbotsch
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' JIT: don't narrow relocatable handle constants in optNarrowTree by EgorBo · Pull Request #129519 · dotnet/runtime · GitHub
Skip to content

JIT: don't narrow relocatable handle constants in optNarrowTree - #129519

Merged
EgorBo merged 3 commits into
dotnet:mainfrom
EgorBo:fix-129504-narrow-reloc-handle
Jun 17, 2026
Merged

JIT: don't narrow relocatable handle constants in optNarrowTree#129519
EgorBo merged 3 commits into
dotnet:mainfrom
EgorBo:fix-129504-narrow-reloc-handle

Conversation

@EgorBo

@EgorBoEgorBo commented Jun 17, 2026

Copy link
Copy Markdown
Member

Fixes#129504.

Note

This PR (code and description) was generated with the assistance of GitHub Copilot.

optNarrowTree could narrow a GT_CNS_INT handle to TYP_INT whenever its
value happened to fit in 32 bits. For a relocatable handle (e.g. a
function-address handle that is the operand of the fat-pointer check
NE(AND(fptr, 2), 0)), this made ARM64 codegen materialize the address
with a 32-bit adrp+add (0x11000000) while still recording a 64-bit
PAGEOFFSET_12A relocation, tripping the (addInstr & 0xFFC00000) ==
0x91000000 assert in the NativeAOT relocation writer.
The bug was latent and only became observable on checked/debug NativeAOT
once handle values stopped carrying a high tag bit (so they fit in
int32). Guard the GT_CNS_INT narrowing on !ImmedValNeedsReloc so handle
constants keep their pointer width.
Fixesdotnet#129504
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 17, 2026 14:06
@github-actionsgithub-actionsBot added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label Jun 17, 2026
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
See info in area-owners.md if you want to be subscribed.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the CoreCLR JIT narrowing logic to avoid narrowing relocatable handle constants during optNarrowTree, preventing the backend from selecting 32-bit instruction forms for values that must be materialized as pointer-sized addresses (notably relevant for ARM64 NativeAOT relocations).

Changes:

  • Add an early-exit in Compiler::optNarrowTree for GT_CNS_INT when ImmedValNeedsReloc(this) is true, disallowing narrowing of relocatable icon-handle constants.

Comment threadsrc/coreclr/jit/optimizer.cpp Outdated
@EgorBo

Copy link
Copy Markdown
MemberAuthor

PTAL @dotnet/jit-contrib yet another transformation on a relocable CNS_INT handle

@EgorBo
EgorBo enabled auto-merge (squash) June 17, 2026 16:49
@EgorBo

Copy link
Copy Markdown
MemberAuthor

/ba-g timeouts

@EgorBo
EgorBo merged commit 0c15cff into dotnet:mainJun 17, 2026
131 of 137 checks passed
@EgorBo
EgorBo deleted the fix-129504-narrow-reloc-handle branch June 17, 2026 20:22
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-preview6 milestone Jun 18, 2026
eiriktsarpalis pushed a commit that referenced this pull request Jul 15, 2026
)
Fixes#129504.
> [!NOTE]
> This PR (code and description) was generated with the assistance of
GitHub Copilot.
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Jul 19, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Incorrect ARM64_PAGEOFFSET_12A relocations getting generated

3 participants

@EgorBo@jakobbotsch
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' JIT: don't narrow relocatable handle constants in optNarrowTree by EgorBo · Pull Request #129519 · dotnet/runtime · GitHub
Skip to content

JIT: don't narrow relocatable handle constants in optNarrowTree - #129519

Merged
EgorBo merged 3 commits into
dotnet:mainfrom
EgorBo:fix-129504-narrow-reloc-handle
Jun 17, 2026
Merged

JIT: don't narrow relocatable handle constants in optNarrowTree#129519
EgorBo merged 3 commits into
dotnet:mainfrom
EgorBo:fix-129504-narrow-reloc-handle

Conversation

@EgorBo

@EgorBoEgorBo commented Jun 17, 2026

Copy link
Copy Markdown
Member

Fixes#129504.

Note

This PR (code and description) was generated with the assistance of GitHub Copilot.

optNarrowTree could narrow a GT_CNS_INT handle to TYP_INT whenever its
value happened to fit in 32 bits. For a relocatable handle (e.g. a
function-address handle that is the operand of the fat-pointer check
NE(AND(fptr, 2), 0)), this made ARM64 codegen materialize the address
with a 32-bit adrp+add (0x11000000) while still recording a 64-bit
PAGEOFFSET_12A relocation, tripping the (addInstr & 0xFFC00000) ==
0x91000000 assert in the NativeAOT relocation writer.
The bug was latent and only became observable on checked/debug NativeAOT
once handle values stopped carrying a high tag bit (so they fit in
int32). Guard the GT_CNS_INT narrowing on !ImmedValNeedsReloc so handle
constants keep their pointer width.
Fixesdotnet#129504
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 17, 2026 14:06
@github-actionsgithub-actionsBot added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label Jun 17, 2026
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
See info in area-owners.md if you want to be subscribed.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the CoreCLR JIT narrowing logic to avoid narrowing relocatable handle constants during optNarrowTree, preventing the backend from selecting 32-bit instruction forms for values that must be materialized as pointer-sized addresses (notably relevant for ARM64 NativeAOT relocations).

Changes:

  • Add an early-exit in Compiler::optNarrowTree for GT_CNS_INT when ImmedValNeedsReloc(this) is true, disallowing narrowing of relocatable icon-handle constants.

Comment threadsrc/coreclr/jit/optimizer.cpp Outdated
@EgorBo

Copy link
Copy Markdown
MemberAuthor

PTAL @dotnet/jit-contrib yet another transformation on a relocable CNS_INT handle

@EgorBo
EgorBo enabled auto-merge (squash) June 17, 2026 16:49
@EgorBo

Copy link
Copy Markdown
MemberAuthor

/ba-g timeouts

@EgorBo
EgorBo merged commit 0c15cff into dotnet:mainJun 17, 2026
131 of 137 checks passed
@EgorBo
EgorBo deleted the fix-129504-narrow-reloc-handle branch June 17, 2026 20:22
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-preview6 milestone Jun 18, 2026
eiriktsarpalis pushed a commit that referenced this pull request Jul 15, 2026
)
Fixes#129504.
> [!NOTE]
> This PR (code and description) was generated with the assistance of
GitHub Copilot.
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Jul 19, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Incorrect ARM64_PAGEOFFSET_12A relocations getting generated

3 participants

@EgorBo@jakobbotsch
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' JIT: don't narrow relocatable handle constants in optNarrowTree by EgorBo · Pull Request #129519 · dotnet/runtime · GitHub
Skip to content

JIT: don't narrow relocatable handle constants in optNarrowTree - #129519

Merged
EgorBo merged 3 commits into
dotnet:mainfrom
EgorBo:fix-129504-narrow-reloc-handle
Jun 17, 2026
Merged

JIT: don't narrow relocatable handle constants in optNarrowTree#129519
EgorBo merged 3 commits into
dotnet:mainfrom
EgorBo:fix-129504-narrow-reloc-handle

Conversation

@EgorBo

@EgorBoEgorBo commented Jun 17, 2026

Copy link
Copy Markdown
Member

Fixes#129504.

Note

This PR (code and description) was generated with the assistance of GitHub Copilot.

optNarrowTree could narrow a GT_CNS_INT handle to TYP_INT whenever its
value happened to fit in 32 bits. For a relocatable handle (e.g. a
function-address handle that is the operand of the fat-pointer check
NE(AND(fptr, 2), 0)), this made ARM64 codegen materialize the address
with a 32-bit adrp+add (0x11000000) while still recording a 64-bit
PAGEOFFSET_12A relocation, tripping the (addInstr & 0xFFC00000) ==
0x91000000 assert in the NativeAOT relocation writer.
The bug was latent and only became observable on checked/debug NativeAOT
once handle values stopped carrying a high tag bit (so they fit in
int32). Guard the GT_CNS_INT narrowing on !ImmedValNeedsReloc so handle
constants keep their pointer width.
Fixesdotnet#129504
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 17, 2026 14:06
@github-actionsgithub-actionsBot added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label Jun 17, 2026
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
See info in area-owners.md if you want to be subscribed.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the CoreCLR JIT narrowing logic to avoid narrowing relocatable handle constants during optNarrowTree, preventing the backend from selecting 32-bit instruction forms for values that must be materialized as pointer-sized addresses (notably relevant for ARM64 NativeAOT relocations).

Changes:

  • Add an early-exit in Compiler::optNarrowTree for GT_CNS_INT when ImmedValNeedsReloc(this) is true, disallowing narrowing of relocatable icon-handle constants.

Comment threadsrc/coreclr/jit/optimizer.cpp Outdated
@EgorBo

Copy link
Copy Markdown
MemberAuthor

PTAL @dotnet/jit-contrib yet another transformation on a relocable CNS_INT handle

@EgorBo
EgorBo enabled auto-merge (squash) June 17, 2026 16:49
@EgorBo

Copy link
Copy Markdown
MemberAuthor

/ba-g timeouts

@EgorBo
EgorBo merged commit 0c15cff into dotnet:mainJun 17, 2026
131 of 137 checks passed
@EgorBo
EgorBo deleted the fix-129504-narrow-reloc-handle branch June 17, 2026 20:22
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-preview6 milestone Jun 18, 2026
eiriktsarpalis pushed a commit that referenced this pull request Jul 15, 2026
)
Fixes#129504.
> [!NOTE]
> This PR (code and description) was generated with the assistance of
GitHub Copilot.
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Jul 19, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Incorrect ARM64_PAGEOFFSET_12A relocations getting generated

3 participants

@EgorBo@jakobbotsch
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' JIT: don't narrow relocatable handle constants in optNarrowTree by EgorBo · Pull Request #129519 · dotnet/runtime · GitHub
Skip to content

JIT: don't narrow relocatable handle constants in optNarrowTree - #129519

Merged
EgorBo merged 3 commits into
dotnet:mainfrom
EgorBo:fix-129504-narrow-reloc-handle
Jun 17, 2026
Merged

JIT: don't narrow relocatable handle constants in optNarrowTree#129519
EgorBo merged 3 commits into
dotnet:mainfrom
EgorBo:fix-129504-narrow-reloc-handle

Conversation

@EgorBo

@EgorBoEgorBo commented Jun 17, 2026

Copy link
Copy Markdown
Member

Fixes#129504.

Note

This PR (code and description) was generated with the assistance of GitHub Copilot.

optNarrowTree could narrow a GT_CNS_INT handle to TYP_INT whenever its
value happened to fit in 32 bits. For a relocatable handle (e.g. a
function-address handle that is the operand of the fat-pointer check
NE(AND(fptr, 2), 0)), this made ARM64 codegen materialize the address
with a 32-bit adrp+add (0x11000000) while still recording a 64-bit
PAGEOFFSET_12A relocation, tripping the (addInstr & 0xFFC00000) ==
0x91000000 assert in the NativeAOT relocation writer.
The bug was latent and only became observable on checked/debug NativeAOT
once handle values stopped carrying a high tag bit (so they fit in
int32). Guard the GT_CNS_INT narrowing on !ImmedValNeedsReloc so handle
constants keep their pointer width.
Fixesdotnet#129504
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 17, 2026 14:06
@github-actionsgithub-actionsBot added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label Jun 17, 2026
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
See info in area-owners.md if you want to be subscribed.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the CoreCLR JIT narrowing logic to avoid narrowing relocatable handle constants during optNarrowTree, preventing the backend from selecting 32-bit instruction forms for values that must be materialized as pointer-sized addresses (notably relevant for ARM64 NativeAOT relocations).

Changes:

  • Add an early-exit in Compiler::optNarrowTree for GT_CNS_INT when ImmedValNeedsReloc(this) is true, disallowing narrowing of relocatable icon-handle constants.

Comment threadsrc/coreclr/jit/optimizer.cpp Outdated
@EgorBo

Copy link
Copy Markdown
MemberAuthor

PTAL @dotnet/jit-contrib yet another transformation on a relocable CNS_INT handle

@EgorBo
EgorBo enabled auto-merge (squash) June 17, 2026 16:49
@EgorBo

Copy link
Copy Markdown
MemberAuthor

/ba-g timeouts

@EgorBo
EgorBo merged commit 0c15cff into dotnet:mainJun 17, 2026
131 of 137 checks passed
@EgorBo
EgorBo deleted the fix-129504-narrow-reloc-handle branch June 17, 2026 20:22
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-preview6 milestone Jun 18, 2026
eiriktsarpalis pushed a commit that referenced this pull request Jul 15, 2026
)
Fixes#129504.
> [!NOTE]
> This PR (code and description) was generated with the assistance of
GitHub Copilot.
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Jul 19, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Incorrect ARM64_PAGEOFFSET_12A relocations getting generated

3 participants

@EgorBo@jakobbotsch
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' JIT: don't narrow relocatable handle constants in optNarrowTree by EgorBo · Pull Request #129519 · dotnet/runtime · GitHub
Skip to content

JIT: don't narrow relocatable handle constants in optNarrowTree - #129519

Merged
EgorBo merged 3 commits into
dotnet:mainfrom
EgorBo:fix-129504-narrow-reloc-handle
Jun 17, 2026
Merged

JIT: don't narrow relocatable handle constants in optNarrowTree#129519
EgorBo merged 3 commits into
dotnet:mainfrom
EgorBo:fix-129504-narrow-reloc-handle

Conversation

@EgorBo

@EgorBoEgorBo commented Jun 17, 2026

Copy link
Copy Markdown
Member

Fixes#129504.

Note

This PR (code and description) was generated with the assistance of GitHub Copilot.

optNarrowTree could narrow a GT_CNS_INT handle to TYP_INT whenever its
value happened to fit in 32 bits. For a relocatable handle (e.g. a
function-address handle that is the operand of the fat-pointer check
NE(AND(fptr, 2), 0)), this made ARM64 codegen materialize the address
with a 32-bit adrp+add (0x11000000) while still recording a 64-bit
PAGEOFFSET_12A relocation, tripping the (addInstr & 0xFFC00000) ==
0x91000000 assert in the NativeAOT relocation writer.
The bug was latent and only became observable on checked/debug NativeAOT
once handle values stopped carrying a high tag bit (so they fit in
int32). Guard the GT_CNS_INT narrowing on !ImmedValNeedsReloc so handle
constants keep their pointer width.
Fixesdotnet#129504
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 17, 2026 14:06
@github-actionsgithub-actionsBot added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label Jun 17, 2026
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
See info in area-owners.md if you want to be subscribed.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the CoreCLR JIT narrowing logic to avoid narrowing relocatable handle constants during optNarrowTree, preventing the backend from selecting 32-bit instruction forms for values that must be materialized as pointer-sized addresses (notably relevant for ARM64 NativeAOT relocations).

Changes:

  • Add an early-exit in Compiler::optNarrowTree for GT_CNS_INT when ImmedValNeedsReloc(this) is true, disallowing narrowing of relocatable icon-handle constants.

Comment threadsrc/coreclr/jit/optimizer.cpp Outdated
@EgorBo

Copy link
Copy Markdown
MemberAuthor

PTAL @dotnet/jit-contrib yet another transformation on a relocable CNS_INT handle

@EgorBo
EgorBo enabled auto-merge (squash) June 17, 2026 16:49
@EgorBo

Copy link
Copy Markdown
MemberAuthor

/ba-g timeouts

@EgorBo
EgorBo merged commit 0c15cff into dotnet:mainJun 17, 2026
131 of 137 checks passed
@EgorBo
EgorBo deleted the fix-129504-narrow-reloc-handle branch June 17, 2026 20:22
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-preview6 milestone Jun 18, 2026
eiriktsarpalis pushed a commit that referenced this pull request Jul 15, 2026
)
Fixes#129504.
> [!NOTE]
> This PR (code and description) was generated with the assistance of
GitHub Copilot.
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Jul 19, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Incorrect ARM64_PAGEOFFSET_12A relocations getting generated

3 participants

@EgorBo@jakobbotsch
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); JIT: don't narrow relocatable handle constants in optNarrowTree by EgorBo · Pull Request #129519 · dotnet/runtime · GitHub
Skip to content

JIT: don't narrow relocatable handle constants in optNarrowTree - #129519

Merged
EgorBo merged 3 commits into
dotnet:mainfrom
EgorBo:fix-129504-narrow-reloc-handle
Jun 17, 2026
Merged

JIT: don't narrow relocatable handle constants in optNarrowTree#129519
EgorBo merged 3 commits into
dotnet:mainfrom
EgorBo:fix-129504-narrow-reloc-handle

Conversation

@EgorBo

@EgorBoEgorBo commented Jun 17, 2026

Copy link
Copy Markdown
Member

Fixes#129504.

Note

This PR (code and description) was generated with the assistance of GitHub Copilot.

optNarrowTree could narrow a GT_CNS_INT handle to TYP_INT whenever its
value happened to fit in 32 bits. For a relocatable handle (e.g. a
function-address handle that is the operand of the fat-pointer check
NE(AND(fptr, 2), 0)), this made ARM64 codegen materialize the address
with a 32-bit adrp+add (0x11000000) while still recording a 64-bit
PAGEOFFSET_12A relocation, tripping the (addInstr & 0xFFC00000) ==
0x91000000 assert in the NativeAOT relocation writer.
The bug was latent and only became observable on checked/debug NativeAOT
once handle values stopped carrying a high tag bit (so they fit in
int32). Guard the GT_CNS_INT narrowing on !ImmedValNeedsReloc so handle
constants keep their pointer width.
Fixesdotnet#129504
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 17, 2026 14:06
@github-actionsgithub-actionsBot added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label Jun 17, 2026
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
See info in area-owners.md if you want to be subscribed.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the CoreCLR JIT narrowing logic to avoid narrowing relocatable handle constants during optNarrowTree, preventing the backend from selecting 32-bit instruction forms for values that must be materialized as pointer-sized addresses (notably relevant for ARM64 NativeAOT relocations).

Changes:

  • Add an early-exit in Compiler::optNarrowTree for GT_CNS_INT when ImmedValNeedsReloc(this) is true, disallowing narrowing of relocatable icon-handle constants.

Comment threadsrc/coreclr/jit/optimizer.cpp Outdated
@EgorBo

Copy link
Copy Markdown
MemberAuthor

PTAL @dotnet/jit-contrib yet another transformation on a relocable CNS_INT handle

@EgorBo
EgorBo enabled auto-merge (squash) June 17, 2026 16:49
@EgorBo

Copy link
Copy Markdown
MemberAuthor

/ba-g timeouts

@EgorBo
EgorBo merged commit 0c15cff into dotnet:mainJun 17, 2026
131 of 137 checks passed
@EgorBo
EgorBo deleted the fix-129504-narrow-reloc-handle branch June 17, 2026 20:22
@dotnet-milestone-botdotnet-milestone-botBot added this to the 11.0-preview6 milestone Jun 18, 2026
eiriktsarpalis pushed a commit that referenced this pull request Jul 15, 2026
)
Fixes#129504.
> [!NOTE]
> This PR (code and description) was generated with the assistance of
GitHub Copilot.
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@github-actionsgithub-actionsBot locked and limited conversation to collaborators Jul 19, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Incorrect ARM64_PAGEOFFSET_12A relocations getting generated

3 participants

@EgorBo@jakobbotsch