Skip to content

Fix AV in gc_heap::init_heap_segment - #131947

Merged
janvorli merged 2 commits into
dotnet:mainfrom
janvorli:fix-av-in-init-heap-segment
Aug 7, 2026
Merged

Fix AV in gc_heap::init_heap_segment#131947
janvorli merged 2 commits into
dotnet:mainfrom
janvorli:fix-av-in-init-heap-segment

Conversation

@janvorli

Copy link
Copy Markdown
Member

There is a bug in get_card_table_element_layout /
get_card_table_commit_layout that results in the last page of the seg_mapping_table_element not being committed in case there was no mark_array_element. That happens when concurrent GC is disabled.

The change fixes that by ensuring that every layout[element] is aligned according to its alignment requirements even when its size is 0. That allows the get_card_table_commit_layout to set commit end of the seg_mapping_table_element to include the last page even when the mark_array_element is not present.

The problem happens because when a memory page is shared by multiple card table elements, the commit range for the first element on that page doesn't include that page and the next element is supposed to do the commit.

Close#129681

There is a bug in get_card_table_element_layout /
get_card_table_commit_layout that results in the last page of the
seg_mapping_table_element not being committed in case there was no
mark_array_element. That happens when concurrent GC is disabled.
The change fixes that by ensuring that every layout[element] is aligned
according to its alignment requirements even when its size is 0.
That allows the get_card_table_commit_layout to set commit end of
the seg_mapping_table_element to include the last page even when the
mark_array_element is not present.
The problem happens because when a memory page is shared by multiple
card table elements, the commit range for the first element on that page
doesn't include that page and the next element is supposed to do
the commit.
Closedotnet#129681
@janvorlijanvorli added this to the 11.0.0 milestone Aug 6, 2026
@janvorli
janvorli requested a review from kkokosaAugust 6, 2026 15:26
@janvorlijanvorli self-assigned this Aug 6, 2026
CopilotAI review requested due to automatic review settings August 6, 2026 15:26
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @anicka-net, @dotnet/gc
See info in area-owners.md if you want to be subscribed.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes a GC bookkeeping layout/commit bug in gc_heap::get_card_table_element_layout that can leave the last page of the seg-mapping table uncommitted when the background/mark array element is absent, which can later lead to an AV during heap segment initialization. It also adds a targeted regression test to exercise the problematic configuration.

Changes:

  • Always align each bookkeeping element’s start offset (except the terminal sentinel) even when the element’s size is 0, so later elements’ commit ranges correctly cover shared pages.
  • Add a new GC regression test project and test case intended to reproduce the failure under GC stress/heap hard-limit settings.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.

FileDescription
src/coreclr/gc/card_table.cppAdjusts bookkeeping element layout alignment so commit layout doesn’t skip the last shared page when a zero-sized element is present.
src/tests/GC/Regressions/Github/Runtime_129681/Runtime_129681.csprojAdds a process-isolated test project that sets GC stress / region / hard-limit environment variables.
src/tests/GC/Regressions/Github/Runtime_129681/Runtime_129681.csAdds a regression test that drives allocations to OOM under the configured GC constraints.
Suppressed comments (1)

src/tests/GC/Regressions/Github/Runtime_129681/Runtime_129681.csproj:18

  • Same as the batch pre-commands: explicitly disable concurrent GC in the bash pre-commands so the test reliably runs in the configuration where mark_array_element is absent (sizes[mark_array_element] == 0).
 $(CLRTestBashPreCommands)
export DOTNET_GCStress=0xC
export DOTNET_GCHeapHardLimit=0x4000000
export DOTNET_GCRegionRange=0x4000000
export DOTNET_GCRegionSize=0x100000

@kkokosakkokosa left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot suggested disabling this test for Mono - not sure if needed:

<!-- Mono doesn't enforce DOTNET_GCHeapHardLimit as a GC heap limit -->
<DisableProjectBuild Condition="'$(RuntimeFlavor)' == 'mono'">true</DisableProjectBuild>

CopilotAI review requested due to automatic review settings August 6, 2026 17:56
CopilotAI reviewed Aug 6, 2026

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Note

This error may be related to your runner configuration. You can now configure runners for Copilot code review separately from Copilot cloud agent by creating a copilot-code-review.yml file with your setup steps. Read the docs for details.

@janvorli

Copy link
Copy Markdown
MemberAuthor

/ba-g failure is #132000

@janvorli
janvorli merged commit be210a7 into dotnet:mainAug 7, 2026
114 of 117 checks passed
@dotnet-milestone-botdotnet-milestone-botBot modified the milestones: 11.0.0, 11.0-rc1Aug 7, 2026
jtschuster pushed a commit to jtschuster/runtime that referenced this pull request Aug 11, 2026
There is a bug in get_card_table_element_layout /
get_card_table_commit_layout that results in the last page of the
seg_mapping_table_element not being committed in case there was no
mark_array_element. That happens when concurrent GC is disabled.
The change fixes that by ensuring that every layout[element] is aligned
according to its alignment requirements even when its size is 0. That
allows the get_card_table_commit_layout to set commit end of the
seg_mapping_table_element to include the last page even when the
mark_array_element is not present.
The problem happens because when a memory page is shared by multiple
card table elements, the commit range for the first element on that page
doesn't include that page and the next element is supposed to do the
commit.
Closedotnet#129681
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Assert failure: Consistency check failed: AV in clr at this callstack

3 participants

@janvorli@kkokosa
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Fix AV in gc_heap::init_heap_segment by janvorli · Pull Request #131947 · dotnet/runtime · GitHub
Skip to content

Fix AV in gc_heap::init_heap_segment - #131947

Merged
janvorli merged 2 commits into
dotnet:mainfrom
janvorli:fix-av-in-init-heap-segment
Aug 7, 2026
Merged

Fix AV in gc_heap::init_heap_segment#131947
janvorli merged 2 commits into
dotnet:mainfrom
janvorli:fix-av-in-init-heap-segment

Conversation

@janvorli

Copy link
Copy Markdown
Member

There is a bug in get_card_table_element_layout /
get_card_table_commit_layout that results in the last page of the seg_mapping_table_element not being committed in case there was no mark_array_element. That happens when concurrent GC is disabled.

The change fixes that by ensuring that every layout[element] is aligned according to its alignment requirements even when its size is 0. That allows the get_card_table_commit_layout to set commit end of the seg_mapping_table_element to include the last page even when the mark_array_element is not present.

The problem happens because when a memory page is shared by multiple card table elements, the commit range for the first element on that page doesn't include that page and the next element is supposed to do the commit.

Close#129681

There is a bug in get_card_table_element_layout /
get_card_table_commit_layout that results in the last page of the
seg_mapping_table_element not being committed in case there was no
mark_array_element. That happens when concurrent GC is disabled.
The change fixes that by ensuring that every layout[element] is aligned
according to its alignment requirements even when its size is 0.
That allows the get_card_table_commit_layout to set commit end of
the seg_mapping_table_element to include the last page even when the
mark_array_element is not present.
The problem happens because when a memory page is shared by multiple
card table elements, the commit range for the first element on that page
doesn't include that page and the next element is supposed to do
the commit.
Closedotnet#129681
@janvorlijanvorli added this to the 11.0.0 milestone Aug 6, 2026
@janvorli
janvorli requested a review from kkokosaAugust 6, 2026 15:26
@janvorlijanvorli self-assigned this Aug 6, 2026
CopilotAI review requested due to automatic review settings August 6, 2026 15:26
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @anicka-net, @dotnet/gc
See info in area-owners.md if you want to be subscribed.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes a GC bookkeeping layout/commit bug in gc_heap::get_card_table_element_layout that can leave the last page of the seg-mapping table uncommitted when the background/mark array element is absent, which can later lead to an AV during heap segment initialization. It also adds a targeted regression test to exercise the problematic configuration.

Changes:

  • Always align each bookkeeping element’s start offset (except the terminal sentinel) even when the element’s size is 0, so later elements’ commit ranges correctly cover shared pages.
  • Add a new GC regression test project and test case intended to reproduce the failure under GC stress/heap hard-limit settings.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.

FileDescription
src/coreclr/gc/card_table.cppAdjusts bookkeeping element layout alignment so commit layout doesn’t skip the last shared page when a zero-sized element is present.
src/tests/GC/Regressions/Github/Runtime_129681/Runtime_129681.csprojAdds a process-isolated test project that sets GC stress / region / hard-limit environment variables.
src/tests/GC/Regressions/Github/Runtime_129681/Runtime_129681.csAdds a regression test that drives allocations to OOM under the configured GC constraints.
Suppressed comments (1)

src/tests/GC/Regressions/Github/Runtime_129681/Runtime_129681.csproj:18

  • Same as the batch pre-commands: explicitly disable concurrent GC in the bash pre-commands so the test reliably runs in the configuration where mark_array_element is absent (sizes[mark_array_element] == 0).
 $(CLRTestBashPreCommands)
export DOTNET_GCStress=0xC
export DOTNET_GCHeapHardLimit=0x4000000
export DOTNET_GCRegionRange=0x4000000
export DOTNET_GCRegionSize=0x100000

@kkokosakkokosa left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot suggested disabling this test for Mono - not sure if needed:

<!-- Mono doesn't enforce DOTNET_GCHeapHardLimit as a GC heap limit -->
<DisableProjectBuild Condition="'$(RuntimeFlavor)' == 'mono'">true</DisableProjectBuild>

CopilotAI review requested due to automatic review settings August 6, 2026 17:56
CopilotAI reviewed Aug 6, 2026

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Note

This error may be related to your runner configuration. You can now configure runners for Copilot code review separately from Copilot cloud agent by creating a copilot-code-review.yml file with your setup steps. Read the docs for details.

@janvorli

Copy link
Copy Markdown
MemberAuthor

/ba-g failure is #132000

@janvorli
janvorli merged commit be210a7 into dotnet:mainAug 7, 2026
114 of 117 checks passed
@dotnet-milestone-botdotnet-milestone-botBot modified the milestones: 11.0.0, 11.0-rc1Aug 7, 2026
jtschuster pushed a commit to jtschuster/runtime that referenced this pull request Aug 11, 2026
There is a bug in get_card_table_element_layout /
get_card_table_commit_layout that results in the last page of the
seg_mapping_table_element not being committed in case there was no
mark_array_element. That happens when concurrent GC is disabled.
The change fixes that by ensuring that every layout[element] is aligned
according to its alignment requirements even when its size is 0. That
allows the get_card_table_commit_layout to set commit end of the
seg_mapping_table_element to include the last page even when the
mark_array_element is not present.
The problem happens because when a memory page is shared by multiple
card table elements, the commit range for the first element on that page
doesn't include that page and the next element is supposed to do the
commit.
Closedotnet#129681
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Assert failure: Consistency check failed: AV in clr at this callstack

3 participants

@janvorli@kkokosa
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Fix AV in gc_heap::init_heap_segment by janvorli · Pull Request #131947 · dotnet/runtime · GitHub
Skip to content

Fix AV in gc_heap::init_heap_segment - #131947

Merged
janvorli merged 2 commits into
dotnet:mainfrom
janvorli:fix-av-in-init-heap-segment
Aug 7, 2026
Merged

Fix AV in gc_heap::init_heap_segment#131947
janvorli merged 2 commits into
dotnet:mainfrom
janvorli:fix-av-in-init-heap-segment

Conversation

@janvorli

Copy link
Copy Markdown
Member

There is a bug in get_card_table_element_layout /
get_card_table_commit_layout that results in the last page of the seg_mapping_table_element not being committed in case there was no mark_array_element. That happens when concurrent GC is disabled.

The change fixes that by ensuring that every layout[element] is aligned according to its alignment requirements even when its size is 0. That allows the get_card_table_commit_layout to set commit end of the seg_mapping_table_element to include the last page even when the mark_array_element is not present.

The problem happens because when a memory page is shared by multiple card table elements, the commit range for the first element on that page doesn't include that page and the next element is supposed to do the commit.

Close#129681

There is a bug in get_card_table_element_layout /
get_card_table_commit_layout that results in the last page of the
seg_mapping_table_element not being committed in case there was no
mark_array_element. That happens when concurrent GC is disabled.
The change fixes that by ensuring that every layout[element] is aligned
according to its alignment requirements even when its size is 0.
That allows the get_card_table_commit_layout to set commit end of
the seg_mapping_table_element to include the last page even when the
mark_array_element is not present.
The problem happens because when a memory page is shared by multiple
card table elements, the commit range for the first element on that page
doesn't include that page and the next element is supposed to do
the commit.
Closedotnet#129681
@janvorlijanvorli added this to the 11.0.0 milestone Aug 6, 2026
@janvorli
janvorli requested a review from kkokosaAugust 6, 2026 15:26
@janvorlijanvorli self-assigned this Aug 6, 2026
CopilotAI review requested due to automatic review settings August 6, 2026 15:26
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @anicka-net, @dotnet/gc
See info in area-owners.md if you want to be subscribed.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes a GC bookkeeping layout/commit bug in gc_heap::get_card_table_element_layout that can leave the last page of the seg-mapping table uncommitted when the background/mark array element is absent, which can later lead to an AV during heap segment initialization. It also adds a targeted regression test to exercise the problematic configuration.

Changes:

  • Always align each bookkeeping element’s start offset (except the terminal sentinel) even when the element’s size is 0, so later elements’ commit ranges correctly cover shared pages.
  • Add a new GC regression test project and test case intended to reproduce the failure under GC stress/heap hard-limit settings.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.

FileDescription
src/coreclr/gc/card_table.cppAdjusts bookkeeping element layout alignment so commit layout doesn’t skip the last shared page when a zero-sized element is present.
src/tests/GC/Regressions/Github/Runtime_129681/Runtime_129681.csprojAdds a process-isolated test project that sets GC stress / region / hard-limit environment variables.
src/tests/GC/Regressions/Github/Runtime_129681/Runtime_129681.csAdds a regression test that drives allocations to OOM under the configured GC constraints.
Suppressed comments (1)

src/tests/GC/Regressions/Github/Runtime_129681/Runtime_129681.csproj:18

  • Same as the batch pre-commands: explicitly disable concurrent GC in the bash pre-commands so the test reliably runs in the configuration where mark_array_element is absent (sizes[mark_array_element] == 0).
 $(CLRTestBashPreCommands)
export DOTNET_GCStress=0xC
export DOTNET_GCHeapHardLimit=0x4000000
export DOTNET_GCRegionRange=0x4000000
export DOTNET_GCRegionSize=0x100000

@kkokosakkokosa left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot suggested disabling this test for Mono - not sure if needed:

<!-- Mono doesn't enforce DOTNET_GCHeapHardLimit as a GC heap limit -->
<DisableProjectBuild Condition="'$(RuntimeFlavor)' == 'mono'">true</DisableProjectBuild>

CopilotAI review requested due to automatic review settings August 6, 2026 17:56
CopilotAI reviewed Aug 6, 2026

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Note

This error may be related to your runner configuration. You can now configure runners for Copilot code review separately from Copilot cloud agent by creating a copilot-code-review.yml file with your setup steps. Read the docs for details.

@janvorli

Copy link
Copy Markdown
MemberAuthor

/ba-g failure is #132000

@janvorli
janvorli merged commit be210a7 into dotnet:mainAug 7, 2026
114 of 117 checks passed
@dotnet-milestone-botdotnet-milestone-botBot modified the milestones: 11.0.0, 11.0-rc1Aug 7, 2026
jtschuster pushed a commit to jtschuster/runtime that referenced this pull request Aug 11, 2026
There is a bug in get_card_table_element_layout /
get_card_table_commit_layout that results in the last page of the
seg_mapping_table_element not being committed in case there was no
mark_array_element. That happens when concurrent GC is disabled.
The change fixes that by ensuring that every layout[element] is aligned
according to its alignment requirements even when its size is 0. That
allows the get_card_table_commit_layout to set commit end of the
seg_mapping_table_element to include the last page even when the
mark_array_element is not present.
The problem happens because when a memory page is shared by multiple
card table elements, the commit range for the first element on that page
doesn't include that page and the next element is supposed to do the
commit.
Closedotnet#129681
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Assert failure: Consistency check failed: AV in clr at this callstack

3 participants

@janvorli@kkokosa
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Fix AV in gc_heap::init_heap_segment by janvorli · Pull Request #131947 · dotnet/runtime · GitHub
Skip to content

Fix AV in gc_heap::init_heap_segment - #131947

Merged
janvorli merged 2 commits into
dotnet:mainfrom
janvorli:fix-av-in-init-heap-segment
Aug 7, 2026
Merged

Fix AV in gc_heap::init_heap_segment#131947
janvorli merged 2 commits into
dotnet:mainfrom
janvorli:fix-av-in-init-heap-segment

Conversation

@janvorli

Copy link
Copy Markdown
Member

There is a bug in get_card_table_element_layout /
get_card_table_commit_layout that results in the last page of the seg_mapping_table_element not being committed in case there was no mark_array_element. That happens when concurrent GC is disabled.

The change fixes that by ensuring that every layout[element] is aligned according to its alignment requirements even when its size is 0. That allows the get_card_table_commit_layout to set commit end of the seg_mapping_table_element to include the last page even when the mark_array_element is not present.

The problem happens because when a memory page is shared by multiple card table elements, the commit range for the first element on that page doesn't include that page and the next element is supposed to do the commit.

Close#129681

There is a bug in get_card_table_element_layout /
get_card_table_commit_layout that results in the last page of the
seg_mapping_table_element not being committed in case there was no
mark_array_element. That happens when concurrent GC is disabled.
The change fixes that by ensuring that every layout[element] is aligned
according to its alignment requirements even when its size is 0.
That allows the get_card_table_commit_layout to set commit end of
the seg_mapping_table_element to include the last page even when the
mark_array_element is not present.
The problem happens because when a memory page is shared by multiple
card table elements, the commit range for the first element on that page
doesn't include that page and the next element is supposed to do
the commit.
Closedotnet#129681
@janvorlijanvorli added this to the 11.0.0 milestone Aug 6, 2026
@janvorli
janvorli requested a review from kkokosaAugust 6, 2026 15:26
@janvorlijanvorli self-assigned this Aug 6, 2026
CopilotAI review requested due to automatic review settings August 6, 2026 15:26
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @anicka-net, @dotnet/gc
See info in area-owners.md if you want to be subscribed.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes a GC bookkeeping layout/commit bug in gc_heap::get_card_table_element_layout that can leave the last page of the seg-mapping table uncommitted when the background/mark array element is absent, which can later lead to an AV during heap segment initialization. It also adds a targeted regression test to exercise the problematic configuration.

Changes:

  • Always align each bookkeeping element’s start offset (except the terminal sentinel) even when the element’s size is 0, so later elements’ commit ranges correctly cover shared pages.
  • Add a new GC regression test project and test case intended to reproduce the failure under GC stress/heap hard-limit settings.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.

FileDescription
src/coreclr/gc/card_table.cppAdjusts bookkeeping element layout alignment so commit layout doesn’t skip the last shared page when a zero-sized element is present.
src/tests/GC/Regressions/Github/Runtime_129681/Runtime_129681.csprojAdds a process-isolated test project that sets GC stress / region / hard-limit environment variables.
src/tests/GC/Regressions/Github/Runtime_129681/Runtime_129681.csAdds a regression test that drives allocations to OOM under the configured GC constraints.
Suppressed comments (1)

src/tests/GC/Regressions/Github/Runtime_129681/Runtime_129681.csproj:18

  • Same as the batch pre-commands: explicitly disable concurrent GC in the bash pre-commands so the test reliably runs in the configuration where mark_array_element is absent (sizes[mark_array_element] == 0).
 $(CLRTestBashPreCommands)
export DOTNET_GCStress=0xC
export DOTNET_GCHeapHardLimit=0x4000000
export DOTNET_GCRegionRange=0x4000000
export DOTNET_GCRegionSize=0x100000

@kkokosakkokosa left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot suggested disabling this test for Mono - not sure if needed:

<!-- Mono doesn't enforce DOTNET_GCHeapHardLimit as a GC heap limit -->
<DisableProjectBuild Condition="'$(RuntimeFlavor)' == 'mono'">true</DisableProjectBuild>

CopilotAI review requested due to automatic review settings August 6, 2026 17:56
CopilotAI reviewed Aug 6, 2026

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Note

This error may be related to your runner configuration. You can now configure runners for Copilot code review separately from Copilot cloud agent by creating a copilot-code-review.yml file with your setup steps. Read the docs for details.

@janvorli

Copy link
Copy Markdown
MemberAuthor

/ba-g failure is #132000

@janvorli
janvorli merged commit be210a7 into dotnet:mainAug 7, 2026
114 of 117 checks passed
@dotnet-milestone-botdotnet-milestone-botBot modified the milestones: 11.0.0, 11.0-rc1Aug 7, 2026
jtschuster pushed a commit to jtschuster/runtime that referenced this pull request Aug 11, 2026
There is a bug in get_card_table_element_layout /
get_card_table_commit_layout that results in the last page of the
seg_mapping_table_element not being committed in case there was no
mark_array_element. That happens when concurrent GC is disabled.
The change fixes that by ensuring that every layout[element] is aligned
according to its alignment requirements even when its size is 0. That
allows the get_card_table_commit_layout to set commit end of the
seg_mapping_table_element to include the last page even when the
mark_array_element is not present.
The problem happens because when a memory page is shared by multiple
card table elements, the commit range for the first element on that page
doesn't include that page and the next element is supposed to do the
commit.
Closedotnet#129681
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Assert failure: Consistency check failed: AV in clr at this callstack

3 participants

@janvorli@kkokosa
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' Fix AV in gc_heap::init_heap_segment by janvorli · Pull Request #131947 · dotnet/runtime · GitHub
Skip to content

Fix AV in gc_heap::init_heap_segment - #131947

Merged
janvorli merged 2 commits into
dotnet:mainfrom
janvorli:fix-av-in-init-heap-segment
Aug 7, 2026
Merged

Fix AV in gc_heap::init_heap_segment#131947
janvorli merged 2 commits into
dotnet:mainfrom
janvorli:fix-av-in-init-heap-segment

Conversation

@janvorli

Copy link
Copy Markdown
Member

There is a bug in get_card_table_element_layout /
get_card_table_commit_layout that results in the last page of the seg_mapping_table_element not being committed in case there was no mark_array_element. That happens when concurrent GC is disabled.

The change fixes that by ensuring that every layout[element] is aligned according to its alignment requirements even when its size is 0. That allows the get_card_table_commit_layout to set commit end of the seg_mapping_table_element to include the last page even when the mark_array_element is not present.

The problem happens because when a memory page is shared by multiple card table elements, the commit range for the first element on that page doesn't include that page and the next element is supposed to do the commit.

Close#129681

There is a bug in get_card_table_element_layout /
get_card_table_commit_layout that results in the last page of the
seg_mapping_table_element not being committed in case there was no
mark_array_element. That happens when concurrent GC is disabled.
The change fixes that by ensuring that every layout[element] is aligned
according to its alignment requirements even when its size is 0.
That allows the get_card_table_commit_layout to set commit end of
the seg_mapping_table_element to include the last page even when the
mark_array_element is not present.
The problem happens because when a memory page is shared by multiple
card table elements, the commit range for the first element on that page
doesn't include that page and the next element is supposed to do
the commit.
Closedotnet#129681
@janvorlijanvorli added this to the 11.0.0 milestone Aug 6, 2026
@janvorli
janvorli requested a review from kkokosaAugust 6, 2026 15:26
@janvorlijanvorli self-assigned this Aug 6, 2026
CopilotAI review requested due to automatic review settings August 6, 2026 15:26
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @anicka-net, @dotnet/gc
See info in area-owners.md if you want to be subscribed.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes a GC bookkeeping layout/commit bug in gc_heap::get_card_table_element_layout that can leave the last page of the seg-mapping table uncommitted when the background/mark array element is absent, which can later lead to an AV during heap segment initialization. It also adds a targeted regression test to exercise the problematic configuration.

Changes:

  • Always align each bookkeeping element’s start offset (except the terminal sentinel) even when the element’s size is 0, so later elements’ commit ranges correctly cover shared pages.
  • Add a new GC regression test project and test case intended to reproduce the failure under GC stress/heap hard-limit settings.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.

FileDescription
src/coreclr/gc/card_table.cppAdjusts bookkeeping element layout alignment so commit layout doesn’t skip the last shared page when a zero-sized element is present.
src/tests/GC/Regressions/Github/Runtime_129681/Runtime_129681.csprojAdds a process-isolated test project that sets GC stress / region / hard-limit environment variables.
src/tests/GC/Regressions/Github/Runtime_129681/Runtime_129681.csAdds a regression test that drives allocations to OOM under the configured GC constraints.
Suppressed comments (1)

src/tests/GC/Regressions/Github/Runtime_129681/Runtime_129681.csproj:18

  • Same as the batch pre-commands: explicitly disable concurrent GC in the bash pre-commands so the test reliably runs in the configuration where mark_array_element is absent (sizes[mark_array_element] == 0).
 $(CLRTestBashPreCommands)
export DOTNET_GCStress=0xC
export DOTNET_GCHeapHardLimit=0x4000000
export DOTNET_GCRegionRange=0x4000000
export DOTNET_GCRegionSize=0x100000

@kkokosakkokosa left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot suggested disabling this test for Mono - not sure if needed:

<!-- Mono doesn't enforce DOTNET_GCHeapHardLimit as a GC heap limit -->
<DisableProjectBuild Condition="'$(RuntimeFlavor)' == 'mono'">true</DisableProjectBuild>

CopilotAI review requested due to automatic review settings August 6, 2026 17:56
CopilotAI reviewed Aug 6, 2026

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Note

This error may be related to your runner configuration. You can now configure runners for Copilot code review separately from Copilot cloud agent by creating a copilot-code-review.yml file with your setup steps. Read the docs for details.

@janvorli

Copy link
Copy Markdown
MemberAuthor

/ba-g failure is #132000

@janvorli
janvorli merged commit be210a7 into dotnet:mainAug 7, 2026
114 of 117 checks passed
@dotnet-milestone-botdotnet-milestone-botBot modified the milestones: 11.0.0, 11.0-rc1Aug 7, 2026
jtschuster pushed a commit to jtschuster/runtime that referenced this pull request Aug 11, 2026
There is a bug in get_card_table_element_layout /
get_card_table_commit_layout that results in the last page of the
seg_mapping_table_element not being committed in case there was no
mark_array_element. That happens when concurrent GC is disabled.
The change fixes that by ensuring that every layout[element] is aligned
according to its alignment requirements even when its size is 0. That
allows the get_card_table_commit_layout to set commit end of the
seg_mapping_table_element to include the last page even when the
mark_array_element is not present.
The problem happens because when a memory page is shared by multiple
card table elements, the commit range for the first element on that page
doesn't include that page and the next element is supposed to do the
commit.
Closedotnet#129681
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Assert failure: Consistency check failed: AV in clr at this callstack

3 participants

@janvorli@kkokosa
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Fix AV in gc_heap::init_heap_segment by janvorli · Pull Request #131947 · dotnet/runtime · GitHub
Skip to content

Fix AV in gc_heap::init_heap_segment - #131947

Merged
janvorli merged 2 commits into
dotnet:mainfrom
janvorli:fix-av-in-init-heap-segment
Aug 7, 2026
Merged

Fix AV in gc_heap::init_heap_segment#131947
janvorli merged 2 commits into
dotnet:mainfrom
janvorli:fix-av-in-init-heap-segment

Conversation

@janvorli

Copy link
Copy Markdown
Member

There is a bug in get_card_table_element_layout /
get_card_table_commit_layout that results in the last page of the seg_mapping_table_element not being committed in case there was no mark_array_element. That happens when concurrent GC is disabled.

The change fixes that by ensuring that every layout[element] is aligned according to its alignment requirements even when its size is 0. That allows the get_card_table_commit_layout to set commit end of the seg_mapping_table_element to include the last page even when the mark_array_element is not present.

The problem happens because when a memory page is shared by multiple card table elements, the commit range for the first element on that page doesn't include that page and the next element is supposed to do the commit.

Close#129681

There is a bug in get_card_table_element_layout /
get_card_table_commit_layout that results in the last page of the
seg_mapping_table_element not being committed in case there was no
mark_array_element. That happens when concurrent GC is disabled.
The change fixes that by ensuring that every layout[element] is aligned
according to its alignment requirements even when its size is 0.
That allows the get_card_table_commit_layout to set commit end of
the seg_mapping_table_element to include the last page even when the
mark_array_element is not present.
The problem happens because when a memory page is shared by multiple
card table elements, the commit range for the first element on that page
doesn't include that page and the next element is supposed to do
the commit.
Closedotnet#129681
@janvorlijanvorli added this to the 11.0.0 milestone Aug 6, 2026
@janvorli
janvorli requested a review from kkokosaAugust 6, 2026 15:26
@janvorlijanvorli self-assigned this Aug 6, 2026
CopilotAI review requested due to automatic review settings August 6, 2026 15:26
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @anicka-net, @dotnet/gc
See info in area-owners.md if you want to be subscribed.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes a GC bookkeeping layout/commit bug in gc_heap::get_card_table_element_layout that can leave the last page of the seg-mapping table uncommitted when the background/mark array element is absent, which can later lead to an AV during heap segment initialization. It also adds a targeted regression test to exercise the problematic configuration.

Changes:

  • Always align each bookkeeping element’s start offset (except the terminal sentinel) even when the element’s size is 0, so later elements’ commit ranges correctly cover shared pages.
  • Add a new GC regression test project and test case intended to reproduce the failure under GC stress/heap hard-limit settings.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.

FileDescription
src/coreclr/gc/card_table.cppAdjusts bookkeeping element layout alignment so commit layout doesn’t skip the last shared page when a zero-sized element is present.
src/tests/GC/Regressions/Github/Runtime_129681/Runtime_129681.csprojAdds a process-isolated test project that sets GC stress / region / hard-limit environment variables.
src/tests/GC/Regressions/Github/Runtime_129681/Runtime_129681.csAdds a regression test that drives allocations to OOM under the configured GC constraints.
Suppressed comments (1)

src/tests/GC/Regressions/Github/Runtime_129681/Runtime_129681.csproj:18

  • Same as the batch pre-commands: explicitly disable concurrent GC in the bash pre-commands so the test reliably runs in the configuration where mark_array_element is absent (sizes[mark_array_element] == 0).
 $(CLRTestBashPreCommands)
export DOTNET_GCStress=0xC
export DOTNET_GCHeapHardLimit=0x4000000
export DOTNET_GCRegionRange=0x4000000
export DOTNET_GCRegionSize=0x100000

@kkokosakkokosa left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot suggested disabling this test for Mono - not sure if needed:

<!-- Mono doesn't enforce DOTNET_GCHeapHardLimit as a GC heap limit -->
<DisableProjectBuild Condition="'$(RuntimeFlavor)' == 'mono'">true</DisableProjectBuild>

CopilotAI review requested due to automatic review settings August 6, 2026 17:56
CopilotAI reviewed Aug 6, 2026

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Note

This error may be related to your runner configuration. You can now configure runners for Copilot code review separately from Copilot cloud agent by creating a copilot-code-review.yml file with your setup steps. Read the docs for details.

@janvorli

Copy link
Copy Markdown
MemberAuthor

/ba-g failure is #132000

@janvorli
janvorli merged commit be210a7 into dotnet:mainAug 7, 2026
114 of 117 checks passed
@dotnet-milestone-botdotnet-milestone-botBot modified the milestones: 11.0.0, 11.0-rc1Aug 7, 2026
jtschuster pushed a commit to jtschuster/runtime that referenced this pull request Aug 11, 2026
There is a bug in get_card_table_element_layout /
get_card_table_commit_layout that results in the last page of the
seg_mapping_table_element not being committed in case there was no
mark_array_element. That happens when concurrent GC is disabled.
The change fixes that by ensuring that every layout[element] is aligned
according to its alignment requirements even when its size is 0. That
allows the get_card_table_commit_layout to set commit end of the
seg_mapping_table_element to include the last page even when the
mark_array_element is not present.
The problem happens because when a memory page is shared by multiple
card table elements, the commit range for the first element on that page
doesn't include that page and the next element is supposed to do the
commit.
Closedotnet#129681
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Assert failure: Consistency check failed: AV in clr at this callstack

3 participants

@janvorli@kkokosa
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Fix AV in gc_heap::init_heap_segment by janvorli · Pull Request #131947 · dotnet/runtime · GitHub
Skip to content

Fix AV in gc_heap::init_heap_segment - #131947

Merged
janvorli merged 2 commits into
dotnet:mainfrom
janvorli:fix-av-in-init-heap-segment
Aug 7, 2026
Merged

Fix AV in gc_heap::init_heap_segment#131947
janvorli merged 2 commits into
dotnet:mainfrom
janvorli:fix-av-in-init-heap-segment

Conversation

@janvorli

Copy link
Copy Markdown
Member

There is a bug in get_card_table_element_layout /
get_card_table_commit_layout that results in the last page of the seg_mapping_table_element not being committed in case there was no mark_array_element. That happens when concurrent GC is disabled.

The change fixes that by ensuring that every layout[element] is aligned according to its alignment requirements even when its size is 0. That allows the get_card_table_commit_layout to set commit end of the seg_mapping_table_element to include the last page even when the mark_array_element is not present.

The problem happens because when a memory page is shared by multiple card table elements, the commit range for the first element on that page doesn't include that page and the next element is supposed to do the commit.

Close#129681

There is a bug in get_card_table_element_layout /
get_card_table_commit_layout that results in the last page of the
seg_mapping_table_element not being committed in case there was no
mark_array_element. That happens when concurrent GC is disabled.
The change fixes that by ensuring that every layout[element] is aligned
according to its alignment requirements even when its size is 0.
That allows the get_card_table_commit_layout to set commit end of
the seg_mapping_table_element to include the last page even when the
mark_array_element is not present.
The problem happens because when a memory page is shared by multiple
card table elements, the commit range for the first element on that page
doesn't include that page and the next element is supposed to do
the commit.
Closedotnet#129681
@janvorlijanvorli added this to the 11.0.0 milestone Aug 6, 2026
@janvorli
janvorli requested a review from kkokosaAugust 6, 2026 15:26
@janvorlijanvorli self-assigned this Aug 6, 2026
CopilotAI review requested due to automatic review settings August 6, 2026 15:26
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @anicka-net, @dotnet/gc
See info in area-owners.md if you want to be subscribed.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes a GC bookkeeping layout/commit bug in gc_heap::get_card_table_element_layout that can leave the last page of the seg-mapping table uncommitted when the background/mark array element is absent, which can later lead to an AV during heap segment initialization. It also adds a targeted regression test to exercise the problematic configuration.

Changes:

  • Always align each bookkeeping element’s start offset (except the terminal sentinel) even when the element’s size is 0, so later elements’ commit ranges correctly cover shared pages.
  • Add a new GC regression test project and test case intended to reproduce the failure under GC stress/heap hard-limit settings.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.

FileDescription
src/coreclr/gc/card_table.cppAdjusts bookkeeping element layout alignment so commit layout doesn’t skip the last shared page when a zero-sized element is present.
src/tests/GC/Regressions/Github/Runtime_129681/Runtime_129681.csprojAdds a process-isolated test project that sets GC stress / region / hard-limit environment variables.
src/tests/GC/Regressions/Github/Runtime_129681/Runtime_129681.csAdds a regression test that drives allocations to OOM under the configured GC constraints.
Suppressed comments (1)

src/tests/GC/Regressions/Github/Runtime_129681/Runtime_129681.csproj:18

  • Same as the batch pre-commands: explicitly disable concurrent GC in the bash pre-commands so the test reliably runs in the configuration where mark_array_element is absent (sizes[mark_array_element] == 0).
 $(CLRTestBashPreCommands)
export DOTNET_GCStress=0xC
export DOTNET_GCHeapHardLimit=0x4000000
export DOTNET_GCRegionRange=0x4000000
export DOTNET_GCRegionSize=0x100000

@kkokosakkokosa left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot suggested disabling this test for Mono - not sure if needed:

<!-- Mono doesn't enforce DOTNET_GCHeapHardLimit as a GC heap limit -->
<DisableProjectBuild Condition="'$(RuntimeFlavor)' == 'mono'">true</DisableProjectBuild>

CopilotAI review requested due to automatic review settings August 6, 2026 17:56
CopilotAI reviewed Aug 6, 2026

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Note

This error may be related to your runner configuration. You can now configure runners for Copilot code review separately from Copilot cloud agent by creating a copilot-code-review.yml file with your setup steps. Read the docs for details.

@janvorli

Copy link
Copy Markdown
MemberAuthor

/ba-g failure is #132000

@janvorli
janvorli merged commit be210a7 into dotnet:mainAug 7, 2026
114 of 117 checks passed
@dotnet-milestone-botdotnet-milestone-botBot modified the milestones: 11.0.0, 11.0-rc1Aug 7, 2026
jtschuster pushed a commit to jtschuster/runtime that referenced this pull request Aug 11, 2026
There is a bug in get_card_table_element_layout /
get_card_table_commit_layout that results in the last page of the
seg_mapping_table_element not being committed in case there was no
mark_array_element. That happens when concurrent GC is disabled.
The change fixes that by ensuring that every layout[element] is aligned
according to its alignment requirements even when its size is 0. That
allows the get_card_table_commit_layout to set commit end of the
seg_mapping_table_element to include the last page even when the
mark_array_element is not present.
The problem happens because when a memory page is shared by multiple
card table elements, the commit range for the first element on that page
doesn't include that page and the next element is supposed to do the
commit.
Closedotnet#129681
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Assert failure: Consistency check failed: AV in clr at this callstack

3 participants

@janvorli@kkokosa
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); Fix AV in gc_heap::init_heap_segment by janvorli · Pull Request #131947 · dotnet/runtime · GitHub
Skip to content

Fix AV in gc_heap::init_heap_segment - #131947

Merged
janvorli merged 2 commits into
dotnet:mainfrom
janvorli:fix-av-in-init-heap-segment
Aug 7, 2026
Merged

Fix AV in gc_heap::init_heap_segment#131947
janvorli merged 2 commits into
dotnet:mainfrom
janvorli:fix-av-in-init-heap-segment

Conversation

@janvorli

Copy link
Copy Markdown
Member

There is a bug in get_card_table_element_layout /
get_card_table_commit_layout that results in the last page of the seg_mapping_table_element not being committed in case there was no mark_array_element. That happens when concurrent GC is disabled.

The change fixes that by ensuring that every layout[element] is aligned according to its alignment requirements even when its size is 0. That allows the get_card_table_commit_layout to set commit end of the seg_mapping_table_element to include the last page even when the mark_array_element is not present.

The problem happens because when a memory page is shared by multiple card table elements, the commit range for the first element on that page doesn't include that page and the next element is supposed to do the commit.

Close#129681

There is a bug in get_card_table_element_layout /
get_card_table_commit_layout that results in the last page of the
seg_mapping_table_element not being committed in case there was no
mark_array_element. That happens when concurrent GC is disabled.
The change fixes that by ensuring that every layout[element] is aligned
according to its alignment requirements even when its size is 0.
That allows the get_card_table_commit_layout to set commit end of
the seg_mapping_table_element to include the last page even when the
mark_array_element is not present.
The problem happens because when a memory page is shared by multiple
card table elements, the commit range for the first element on that page
doesn't include that page and the next element is supposed to do
the commit.
Closedotnet#129681
@janvorlijanvorli added this to the 11.0.0 milestone Aug 6, 2026
@janvorli
janvorli requested a review from kkokosaAugust 6, 2026 15:26
@janvorlijanvorli self-assigned this Aug 6, 2026
CopilotAI review requested due to automatic review settings August 6, 2026 15:26
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @anicka-net, @dotnet/gc
See info in area-owners.md if you want to be subscribed.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes a GC bookkeeping layout/commit bug in gc_heap::get_card_table_element_layout that can leave the last page of the seg-mapping table uncommitted when the background/mark array element is absent, which can later lead to an AV during heap segment initialization. It also adds a targeted regression test to exercise the problematic configuration.

Changes:

  • Always align each bookkeeping element’s start offset (except the terminal sentinel) even when the element’s size is 0, so later elements’ commit ranges correctly cover shared pages.
  • Add a new GC regression test project and test case intended to reproduce the failure under GC stress/heap hard-limit settings.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.

FileDescription
src/coreclr/gc/card_table.cppAdjusts bookkeeping element layout alignment so commit layout doesn’t skip the last shared page when a zero-sized element is present.
src/tests/GC/Regressions/Github/Runtime_129681/Runtime_129681.csprojAdds a process-isolated test project that sets GC stress / region / hard-limit environment variables.
src/tests/GC/Regressions/Github/Runtime_129681/Runtime_129681.csAdds a regression test that drives allocations to OOM under the configured GC constraints.
Suppressed comments (1)

src/tests/GC/Regressions/Github/Runtime_129681/Runtime_129681.csproj:18

  • Same as the batch pre-commands: explicitly disable concurrent GC in the bash pre-commands so the test reliably runs in the configuration where mark_array_element is absent (sizes[mark_array_element] == 0).
 $(CLRTestBashPreCommands)
export DOTNET_GCStress=0xC
export DOTNET_GCHeapHardLimit=0x4000000
export DOTNET_GCRegionRange=0x4000000
export DOTNET_GCRegionSize=0x100000

@kkokosakkokosa left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot suggested disabling this test for Mono - not sure if needed:

<!-- Mono doesn't enforce DOTNET_GCHeapHardLimit as a GC heap limit -->
<DisableProjectBuild Condition="'$(RuntimeFlavor)' == 'mono'">true</DisableProjectBuild>

CopilotAI review requested due to automatic review settings August 6, 2026 17:56
CopilotAI reviewed Aug 6, 2026

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Note

This error may be related to your runner configuration. You can now configure runners for Copilot code review separately from Copilot cloud agent by creating a copilot-code-review.yml file with your setup steps. Read the docs for details.

@janvorli

Copy link
Copy Markdown
MemberAuthor

/ba-g failure is #132000

@janvorli
janvorli merged commit be210a7 into dotnet:mainAug 7, 2026
114 of 117 checks passed
@dotnet-milestone-botdotnet-milestone-botBot modified the milestones: 11.0.0, 11.0-rc1Aug 7, 2026
jtschuster pushed a commit to jtschuster/runtime that referenced this pull request Aug 11, 2026
There is a bug in get_card_table_element_layout /
get_card_table_commit_layout that results in the last page of the
seg_mapping_table_element not being committed in case there was no
mark_array_element. That happens when concurrent GC is disabled.
The change fixes that by ensuring that every layout[element] is aligned
according to its alignment requirements even when its size is 0. That
allows the get_card_table_commit_layout to set commit end of the
seg_mapping_table_element to include the last page even when the
mark_array_element is not present.
The problem happens because when a memory page is shared by multiple
card table elements, the commit range for the first element on that page
doesn't include that page and the next element is supposed to do the
commit.
Closedotnet#129681
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Assert failure: Consistency check failed: AV in clr at this callstack

3 participants

@janvorli@kkokosa