Skip to content

[release/8.0] JIT: Disallow mismatched GC-ness for physical promotions - #90739

Merged
carlossanlop merged 2 commits into
release/8.0from
backport/pr-90694-to-release/8.0
Aug 17, 2023
Merged

[release/8.0] JIT: Disallow mismatched GC-ness for physical promotions#90739
carlossanlop merged 2 commits into
release/8.0from
backport/pr-90694-to-release/8.0

Conversation

@github-actions

@github-actionsgithub-actionsBot commented Aug 17, 2023

Copy link
Copy Markdown
Contributor

Backport of #90694 to release/8.0

/cc @jakobbotsch

Customer Impact

Code that involves illegal reinterpretations of GC pointers in unreachable code paths can cause the JIT to generate code with incorrect GC reporting, even in the reachable paths.
For example, MemoryMarshal.Contains is a case. When value is a GC pointer, RuntimeHelpers.IsBitwiseEquatable<T>() will return false, but under some stress scenarios the JIT will still see the later Unsafe.As<T, long>(ref value). This can cause it to mistakenly reinterpret value as a long without any GC reporting, even outside the RuntimeHelpers.IsBitwiseEquatable<T>() branch.
For this particular case, in normal circumstances (no stress modes) the unreachable code is folded away early enough that the JIT does not see the reinterpretation, so no issue happens.

Testing

Verified that the failing test case now generates correct code and GC reporting, even when the stress variables are set.

Risk

Low. Targeted fix with no diffs in any of our own code (under non stress circumstances) that disables physical promotion when the case is detected.

Physical promotion was working under the assumption that reinterpreting
GC pointers is undefined behavior, and would happily promote GC pointers
as integers if it saw such accesses. However, physical promotion is
function wide while the UB accesses can be happening in a restricted
(dynamically unreachable) scope. This exact situation happens in
MemoryExtensions.Contains. The issue was uncovered under jit stress
where we did not fold away the guard early enough, meaning that
promotion then saw a `TYP_LONG` access of a `struct { object, int }` and
proceeded to promote it as such.
Fix#90602
@ghostghost added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label Aug 17, 2023
@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
See info in area-owners.md if you want to be subscribed.

Issue Details

Backport of #90694 to release/8.0

/cc @jakobbotsch

Customer Impact

Testing

Risk

IMPORTANT: If this backport is for a servicing release, please verify that:

  • The PR target branch is release/X.0-staging, not release/X.0.

  • If the change touches code that ships in a NuGet package, you have added the necessary package authoring and gotten it explicitly reviewed.

Author:github-actions[bot]
Assignees:-
Labels:

area-CodeGen-coreclr

Milestone:-

@jeffschwMSFTjeffschwMSFT left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

approved. please get a code review, you are good to merge

@carlossanlop

Copy link
Copy Markdown
Contributor

FYI this is going into RC2 (release/8.0). If that's your intention, @jakobbotsch , then I can merge right away, since it has been signed-off and approved by @jeffschwMSFT .

If you intended to send it to RC1, please retarget the PR to release/8.0-rc1 and send an email to Tactics requesting approval.

@jakobbotsch

Copy link
Copy Markdown
Member

FYI this is going into RC2 (release/8.0). If that's your intention, @jakobbotsch , then I can merge right away, since it has been signed-off and approved by @jeffschwMSFT .

I think RC2 only is just fine.

@carlossanlopcarlossanlop added Servicing-consider Issue for next servicing release review Servicing-approved Approved for servicing release and removed Servicing-consider Issue for next servicing release review labels Aug 17, 2023
@carlossanlop
carlossanlop merged commit 3ab4246 into release/8.0Aug 17, 2023
@carlossanlop
carlossanlop deleted the backport/pr-90694-to-release/8.0 branch August 17, 2023 17:27
@ghostghost locked as resolved and limited conversation to collaborators Sep 16, 2023
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMIServicing-approvedApproved for servicing release

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@carlossanlop@jakobbotsch@EgorBo@jeffschwMSFT
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
[release/8.0] JIT: Disallow mismatched GC-ness for physical promotions by github-actions[bot] · Pull Request #90739 · dotnet/runtime · GitHub
Skip to content

[release/8.0] JIT: Disallow mismatched GC-ness for physical promotions - #90739

Merged
carlossanlop merged 2 commits into
release/8.0from
backport/pr-90694-to-release/8.0
Aug 17, 2023
Merged

[release/8.0] JIT: Disallow mismatched GC-ness for physical promotions#90739
carlossanlop merged 2 commits into
release/8.0from
backport/pr-90694-to-release/8.0

Conversation

@github-actions

@github-actionsgithub-actionsBot commented Aug 17, 2023

Copy link
Copy Markdown
Contributor

Backport of #90694 to release/8.0

/cc @jakobbotsch

Customer Impact

Code that involves illegal reinterpretations of GC pointers in unreachable code paths can cause the JIT to generate code with incorrect GC reporting, even in the reachable paths.
For example, MemoryMarshal.Contains is a case. When value is a GC pointer, RuntimeHelpers.IsBitwiseEquatable<T>() will return false, but under some stress scenarios the JIT will still see the later Unsafe.As<T, long>(ref value). This can cause it to mistakenly reinterpret value as a long without any GC reporting, even outside the RuntimeHelpers.IsBitwiseEquatable<T>() branch.
For this particular case, in normal circumstances (no stress modes) the unreachable code is folded away early enough that the JIT does not see the reinterpretation, so no issue happens.

Testing

Verified that the failing test case now generates correct code and GC reporting, even when the stress variables are set.

Risk

Low. Targeted fix with no diffs in any of our own code (under non stress circumstances) that disables physical promotion when the case is detected.

Physical promotion was working under the assumption that reinterpreting
GC pointers is undefined behavior, and would happily promote GC pointers
as integers if it saw such accesses. However, physical promotion is
function wide while the UB accesses can be happening in a restricted
(dynamically unreachable) scope. This exact situation happens in
MemoryExtensions.Contains. The issue was uncovered under jit stress
where we did not fold away the guard early enough, meaning that
promotion then saw a `TYP_LONG` access of a `struct { object, int }` and
proceeded to promote it as such.
Fix#90602
@ghostghost added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label Aug 17, 2023
@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
See info in area-owners.md if you want to be subscribed.

Issue Details

Backport of #90694 to release/8.0

/cc @jakobbotsch

Customer Impact

Testing

Risk

IMPORTANT: If this backport is for a servicing release, please verify that:

  • The PR target branch is release/X.0-staging, not release/X.0.

  • If the change touches code that ships in a NuGet package, you have added the necessary package authoring and gotten it explicitly reviewed.

Author:github-actions[bot]
Assignees:-
Labels:

area-CodeGen-coreclr

Milestone:-

@jeffschwMSFTjeffschwMSFT left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

approved. please get a code review, you are good to merge

@carlossanlop

Copy link
Copy Markdown
Contributor

FYI this is going into RC2 (release/8.0). If that's your intention, @jakobbotsch , then I can merge right away, since it has been signed-off and approved by @jeffschwMSFT .

If you intended to send it to RC1, please retarget the PR to release/8.0-rc1 and send an email to Tactics requesting approval.

@jakobbotsch

Copy link
Copy Markdown
Member

FYI this is going into RC2 (release/8.0). If that's your intention, @jakobbotsch , then I can merge right away, since it has been signed-off and approved by @jeffschwMSFT .

I think RC2 only is just fine.

@carlossanlopcarlossanlop added Servicing-consider Issue for next servicing release review Servicing-approved Approved for servicing release and removed Servicing-consider Issue for next servicing release review labels Aug 17, 2023
@carlossanlop
carlossanlop merged commit 3ab4246 into release/8.0Aug 17, 2023
@carlossanlop
carlossanlop deleted the backport/pr-90694-to-release/8.0 branch August 17, 2023 17:27
@ghostghost locked as resolved and limited conversation to collaborators Sep 16, 2023
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMIServicing-approvedApproved for servicing release

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@carlossanlop@jakobbotsch@EgorBo@jeffschwMSFT
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' [release/8.0] JIT: Disallow mismatched GC-ness for physical promotions by github-actions[bot] · Pull Request #90739 · dotnet/runtime · GitHub
Skip to content

[release/8.0] JIT: Disallow mismatched GC-ness for physical promotions - #90739

Merged
carlossanlop merged 2 commits into
release/8.0from
backport/pr-90694-to-release/8.0
Aug 17, 2023
Merged

[release/8.0] JIT: Disallow mismatched GC-ness for physical promotions#90739
carlossanlop merged 2 commits into
release/8.0from
backport/pr-90694-to-release/8.0

Conversation

@github-actions

@github-actionsgithub-actionsBot commented Aug 17, 2023

Copy link
Copy Markdown
Contributor

Backport of #90694 to release/8.0

/cc @jakobbotsch

Customer Impact

Code that involves illegal reinterpretations of GC pointers in unreachable code paths can cause the JIT to generate code with incorrect GC reporting, even in the reachable paths.
For example, MemoryMarshal.Contains is a case. When value is a GC pointer, RuntimeHelpers.IsBitwiseEquatable<T>() will return false, but under some stress scenarios the JIT will still see the later Unsafe.As<T, long>(ref value). This can cause it to mistakenly reinterpret value as a long without any GC reporting, even outside the RuntimeHelpers.IsBitwiseEquatable<T>() branch.
For this particular case, in normal circumstances (no stress modes) the unreachable code is folded away early enough that the JIT does not see the reinterpretation, so no issue happens.

Testing

Verified that the failing test case now generates correct code and GC reporting, even when the stress variables are set.

Risk

Low. Targeted fix with no diffs in any of our own code (under non stress circumstances) that disables physical promotion when the case is detected.

Physical promotion was working under the assumption that reinterpreting
GC pointers is undefined behavior, and would happily promote GC pointers
as integers if it saw such accesses. However, physical promotion is
function wide while the UB accesses can be happening in a restricted
(dynamically unreachable) scope. This exact situation happens in
MemoryExtensions.Contains. The issue was uncovered under jit stress
where we did not fold away the guard early enough, meaning that
promotion then saw a `TYP_LONG` access of a `struct { object, int }` and
proceeded to promote it as such.
Fix#90602
@ghostghost added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label Aug 17, 2023
@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
See info in area-owners.md if you want to be subscribed.

Issue Details

Backport of #90694 to release/8.0

/cc @jakobbotsch

Customer Impact

Testing

Risk

IMPORTANT: If this backport is for a servicing release, please verify that:

  • The PR target branch is release/X.0-staging, not release/X.0.

  • If the change touches code that ships in a NuGet package, you have added the necessary package authoring and gotten it explicitly reviewed.

Author:github-actions[bot]
Assignees:-
Labels:

area-CodeGen-coreclr

Milestone:-

@jeffschwMSFTjeffschwMSFT left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

approved. please get a code review, you are good to merge

@carlossanlop

Copy link
Copy Markdown
Contributor

FYI this is going into RC2 (release/8.0). If that's your intention, @jakobbotsch , then I can merge right away, since it has been signed-off and approved by @jeffschwMSFT .

If you intended to send it to RC1, please retarget the PR to release/8.0-rc1 and send an email to Tactics requesting approval.

@jakobbotsch

Copy link
Copy Markdown
Member

FYI this is going into RC2 (release/8.0). If that's your intention, @jakobbotsch , then I can merge right away, since it has been signed-off and approved by @jeffschwMSFT .

I think RC2 only is just fine.

@carlossanlopcarlossanlop added Servicing-consider Issue for next servicing release review Servicing-approved Approved for servicing release and removed Servicing-consider Issue for next servicing release review labels Aug 17, 2023
@carlossanlop
carlossanlop merged commit 3ab4246 into release/8.0Aug 17, 2023
@carlossanlop
carlossanlop deleted the backport/pr-90694-to-release/8.0 branch August 17, 2023 17:27
@ghostghost locked as resolved and limited conversation to collaborators Sep 16, 2023
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMIServicing-approvedApproved for servicing release

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@carlossanlop@jakobbotsch@EgorBo@jeffschwMSFT
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' [release/8.0] JIT: Disallow mismatched GC-ness for physical promotions by github-actions[bot] · Pull Request #90739 · dotnet/runtime · GitHub
Skip to content

[release/8.0] JIT: Disallow mismatched GC-ness for physical promotions - #90739

Merged
carlossanlop merged 2 commits into
release/8.0from
backport/pr-90694-to-release/8.0
Aug 17, 2023
Merged

[release/8.0] JIT: Disallow mismatched GC-ness for physical promotions#90739
carlossanlop merged 2 commits into
release/8.0from
backport/pr-90694-to-release/8.0

Conversation

@github-actions

@github-actionsgithub-actionsBot commented Aug 17, 2023

Copy link
Copy Markdown
Contributor

Backport of #90694 to release/8.0

/cc @jakobbotsch

Customer Impact

Code that involves illegal reinterpretations of GC pointers in unreachable code paths can cause the JIT to generate code with incorrect GC reporting, even in the reachable paths.
For example, MemoryMarshal.Contains is a case. When value is a GC pointer, RuntimeHelpers.IsBitwiseEquatable<T>() will return false, but under some stress scenarios the JIT will still see the later Unsafe.As<T, long>(ref value). This can cause it to mistakenly reinterpret value as a long without any GC reporting, even outside the RuntimeHelpers.IsBitwiseEquatable<T>() branch.
For this particular case, in normal circumstances (no stress modes) the unreachable code is folded away early enough that the JIT does not see the reinterpretation, so no issue happens.

Testing

Verified that the failing test case now generates correct code and GC reporting, even when the stress variables are set.

Risk

Low. Targeted fix with no diffs in any of our own code (under non stress circumstances) that disables physical promotion when the case is detected.

Physical promotion was working under the assumption that reinterpreting
GC pointers is undefined behavior, and would happily promote GC pointers
as integers if it saw such accesses. However, physical promotion is
function wide while the UB accesses can be happening in a restricted
(dynamically unreachable) scope. This exact situation happens in
MemoryExtensions.Contains. The issue was uncovered under jit stress
where we did not fold away the guard early enough, meaning that
promotion then saw a `TYP_LONG` access of a `struct { object, int }` and
proceeded to promote it as such.
Fix#90602
@ghostghost added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label Aug 17, 2023
@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
See info in area-owners.md if you want to be subscribed.

Issue Details

Backport of #90694 to release/8.0

/cc @jakobbotsch

Customer Impact

Testing

Risk

IMPORTANT: If this backport is for a servicing release, please verify that:

  • The PR target branch is release/X.0-staging, not release/X.0.

  • If the change touches code that ships in a NuGet package, you have added the necessary package authoring and gotten it explicitly reviewed.

Author:github-actions[bot]
Assignees:-
Labels:

area-CodeGen-coreclr

Milestone:-

@jeffschwMSFTjeffschwMSFT left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

approved. please get a code review, you are good to merge

@carlossanlop

Copy link
Copy Markdown
Contributor

FYI this is going into RC2 (release/8.0). If that's your intention, @jakobbotsch , then I can merge right away, since it has been signed-off and approved by @jeffschwMSFT .

If you intended to send it to RC1, please retarget the PR to release/8.0-rc1 and send an email to Tactics requesting approval.

@jakobbotsch

Copy link
Copy Markdown
Member

FYI this is going into RC2 (release/8.0). If that's your intention, @jakobbotsch , then I can merge right away, since it has been signed-off and approved by @jeffschwMSFT .

I think RC2 only is just fine.

@carlossanlopcarlossanlop added Servicing-consider Issue for next servicing release review Servicing-approved Approved for servicing release and removed Servicing-consider Issue for next servicing release review labels Aug 17, 2023
@carlossanlop
carlossanlop merged commit 3ab4246 into release/8.0Aug 17, 2023
@carlossanlop
carlossanlop deleted the backport/pr-90694-to-release/8.0 branch August 17, 2023 17:27
@ghostghost locked as resolved and limited conversation to collaborators Sep 16, 2023
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMIServicing-approvedApproved for servicing release

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@carlossanlop@jakobbotsch@EgorBo@jeffschwMSFT
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' [release/8.0] JIT: Disallow mismatched GC-ness for physical promotions by github-actions[bot] · Pull Request #90739 · dotnet/runtime · GitHub
Skip to content

[release/8.0] JIT: Disallow mismatched GC-ness for physical promotions - #90739

Merged
carlossanlop merged 2 commits into
release/8.0from
backport/pr-90694-to-release/8.0
Aug 17, 2023
Merged

[release/8.0] JIT: Disallow mismatched GC-ness for physical promotions#90739
carlossanlop merged 2 commits into
release/8.0from
backport/pr-90694-to-release/8.0

Conversation

@github-actions

@github-actionsgithub-actionsBot commented Aug 17, 2023

Copy link
Copy Markdown
Contributor

Backport of #90694 to release/8.0

/cc @jakobbotsch

Customer Impact

Code that involves illegal reinterpretations of GC pointers in unreachable code paths can cause the JIT to generate code with incorrect GC reporting, even in the reachable paths.
For example, MemoryMarshal.Contains is a case. When value is a GC pointer, RuntimeHelpers.IsBitwiseEquatable<T>() will return false, but under some stress scenarios the JIT will still see the later Unsafe.As<T, long>(ref value). This can cause it to mistakenly reinterpret value as a long without any GC reporting, even outside the RuntimeHelpers.IsBitwiseEquatable<T>() branch.
For this particular case, in normal circumstances (no stress modes) the unreachable code is folded away early enough that the JIT does not see the reinterpretation, so no issue happens.

Testing

Verified that the failing test case now generates correct code and GC reporting, even when the stress variables are set.

Risk

Low. Targeted fix with no diffs in any of our own code (under non stress circumstances) that disables physical promotion when the case is detected.

Physical promotion was working under the assumption that reinterpreting
GC pointers is undefined behavior, and would happily promote GC pointers
as integers if it saw such accesses. However, physical promotion is
function wide while the UB accesses can be happening in a restricted
(dynamically unreachable) scope. This exact situation happens in
MemoryExtensions.Contains. The issue was uncovered under jit stress
where we did not fold away the guard early enough, meaning that
promotion then saw a `TYP_LONG` access of a `struct { object, int }` and
proceeded to promote it as such.
Fix#90602
@ghostghost added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label Aug 17, 2023
@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
See info in area-owners.md if you want to be subscribed.

Issue Details

Backport of #90694 to release/8.0

/cc @jakobbotsch

Customer Impact

Testing

Risk

IMPORTANT: If this backport is for a servicing release, please verify that:

  • The PR target branch is release/X.0-staging, not release/X.0.

  • If the change touches code that ships in a NuGet package, you have added the necessary package authoring and gotten it explicitly reviewed.

Author:github-actions[bot]
Assignees:-
Labels:

area-CodeGen-coreclr

Milestone:-

@jeffschwMSFTjeffschwMSFT left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

approved. please get a code review, you are good to merge

@carlossanlop

Copy link
Copy Markdown
Contributor

FYI this is going into RC2 (release/8.0). If that's your intention, @jakobbotsch , then I can merge right away, since it has been signed-off and approved by @jeffschwMSFT .

If you intended to send it to RC1, please retarget the PR to release/8.0-rc1 and send an email to Tactics requesting approval.

@jakobbotsch

Copy link
Copy Markdown
Member

FYI this is going into RC2 (release/8.0). If that's your intention, @jakobbotsch , then I can merge right away, since it has been signed-off and approved by @jeffschwMSFT .

I think RC2 only is just fine.

@carlossanlopcarlossanlop added Servicing-consider Issue for next servicing release review Servicing-approved Approved for servicing release and removed Servicing-consider Issue for next servicing release review labels Aug 17, 2023
@carlossanlop
carlossanlop merged commit 3ab4246 into release/8.0Aug 17, 2023
@carlossanlop
carlossanlop deleted the backport/pr-90694-to-release/8.0 branch August 17, 2023 17:27
@ghostghost locked as resolved and limited conversation to collaborators Sep 16, 2023
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMIServicing-approvedApproved for servicing release

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@carlossanlop@jakobbotsch@EgorBo@jeffschwMSFT
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' [release/8.0] JIT: Disallow mismatched GC-ness for physical promotions by github-actions[bot] · Pull Request #90739 · dotnet/runtime · GitHub
Skip to content

[release/8.0] JIT: Disallow mismatched GC-ness for physical promotions - #90739

Merged
carlossanlop merged 2 commits into
release/8.0from
backport/pr-90694-to-release/8.0
Aug 17, 2023
Merged

[release/8.0] JIT: Disallow mismatched GC-ness for physical promotions#90739
carlossanlop merged 2 commits into
release/8.0from
backport/pr-90694-to-release/8.0

Conversation

@github-actions

@github-actionsgithub-actionsBot commented Aug 17, 2023

Copy link
Copy Markdown
Contributor

Backport of #90694 to release/8.0

/cc @jakobbotsch

Customer Impact

Code that involves illegal reinterpretations of GC pointers in unreachable code paths can cause the JIT to generate code with incorrect GC reporting, even in the reachable paths.
For example, MemoryMarshal.Contains is a case. When value is a GC pointer, RuntimeHelpers.IsBitwiseEquatable<T>() will return false, but under some stress scenarios the JIT will still see the later Unsafe.As<T, long>(ref value). This can cause it to mistakenly reinterpret value as a long without any GC reporting, even outside the RuntimeHelpers.IsBitwiseEquatable<T>() branch.
For this particular case, in normal circumstances (no stress modes) the unreachable code is folded away early enough that the JIT does not see the reinterpretation, so no issue happens.

Testing

Verified that the failing test case now generates correct code and GC reporting, even when the stress variables are set.

Risk

Low. Targeted fix with no diffs in any of our own code (under non stress circumstances) that disables physical promotion when the case is detected.

Physical promotion was working under the assumption that reinterpreting
GC pointers is undefined behavior, and would happily promote GC pointers
as integers if it saw such accesses. However, physical promotion is
function wide while the UB accesses can be happening in a restricted
(dynamically unreachable) scope. This exact situation happens in
MemoryExtensions.Contains. The issue was uncovered under jit stress
where we did not fold away the guard early enough, meaning that
promotion then saw a `TYP_LONG` access of a `struct { object, int }` and
proceeded to promote it as such.
Fix#90602
@ghostghost added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label Aug 17, 2023
@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
See info in area-owners.md if you want to be subscribed.

Issue Details

Backport of #90694 to release/8.0

/cc @jakobbotsch

Customer Impact

Testing

Risk

IMPORTANT: If this backport is for a servicing release, please verify that:

  • The PR target branch is release/X.0-staging, not release/X.0.

  • If the change touches code that ships in a NuGet package, you have added the necessary package authoring and gotten it explicitly reviewed.

Author:github-actions[bot]
Assignees:-
Labels:

area-CodeGen-coreclr

Milestone:-

@jeffschwMSFTjeffschwMSFT left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

approved. please get a code review, you are good to merge

@carlossanlop

Copy link
Copy Markdown
Contributor

FYI this is going into RC2 (release/8.0). If that's your intention, @jakobbotsch , then I can merge right away, since it has been signed-off and approved by @jeffschwMSFT .

If you intended to send it to RC1, please retarget the PR to release/8.0-rc1 and send an email to Tactics requesting approval.

@jakobbotsch

Copy link
Copy Markdown
Member

FYI this is going into RC2 (release/8.0). If that's your intention, @jakobbotsch , then I can merge right away, since it has been signed-off and approved by @jeffschwMSFT .

I think RC2 only is just fine.

@carlossanlopcarlossanlop added Servicing-consider Issue for next servicing release review Servicing-approved Approved for servicing release and removed Servicing-consider Issue for next servicing release review labels Aug 17, 2023
@carlossanlop
carlossanlop merged commit 3ab4246 into release/8.0Aug 17, 2023
@carlossanlop
carlossanlop deleted the backport/pr-90694-to-release/8.0 branch August 17, 2023 17:27
@ghostghost locked as resolved and limited conversation to collaborators Sep 16, 2023
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMIServicing-approvedApproved for servicing release

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@carlossanlop@jakobbotsch@EgorBo@jeffschwMSFT
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' [release/8.0] JIT: Disallow mismatched GC-ness for physical promotions by github-actions[bot] · Pull Request #90739 · dotnet/runtime · GitHub
Skip to content

[release/8.0] JIT: Disallow mismatched GC-ness for physical promotions - #90739

Merged
carlossanlop merged 2 commits into
release/8.0from
backport/pr-90694-to-release/8.0
Aug 17, 2023
Merged

[release/8.0] JIT: Disallow mismatched GC-ness for physical promotions#90739
carlossanlop merged 2 commits into
release/8.0from
backport/pr-90694-to-release/8.0

Conversation

@github-actions

@github-actionsgithub-actionsBot commented Aug 17, 2023

Copy link
Copy Markdown
Contributor

Backport of #90694 to release/8.0

/cc @jakobbotsch

Customer Impact

Code that involves illegal reinterpretations of GC pointers in unreachable code paths can cause the JIT to generate code with incorrect GC reporting, even in the reachable paths.
For example, MemoryMarshal.Contains is a case. When value is a GC pointer, RuntimeHelpers.IsBitwiseEquatable<T>() will return false, but under some stress scenarios the JIT will still see the later Unsafe.As<T, long>(ref value). This can cause it to mistakenly reinterpret value as a long without any GC reporting, even outside the RuntimeHelpers.IsBitwiseEquatable<T>() branch.
For this particular case, in normal circumstances (no stress modes) the unreachable code is folded away early enough that the JIT does not see the reinterpretation, so no issue happens.

Testing

Verified that the failing test case now generates correct code and GC reporting, even when the stress variables are set.

Risk

Low. Targeted fix with no diffs in any of our own code (under non stress circumstances) that disables physical promotion when the case is detected.

Physical promotion was working under the assumption that reinterpreting
GC pointers is undefined behavior, and would happily promote GC pointers
as integers if it saw such accesses. However, physical promotion is
function wide while the UB accesses can be happening in a restricted
(dynamically unreachable) scope. This exact situation happens in
MemoryExtensions.Contains. The issue was uncovered under jit stress
where we did not fold away the guard early enough, meaning that
promotion then saw a `TYP_LONG` access of a `struct { object, int }` and
proceeded to promote it as such.
Fix#90602
@ghostghost added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label Aug 17, 2023
@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
See info in area-owners.md if you want to be subscribed.

Issue Details

Backport of #90694 to release/8.0

/cc @jakobbotsch

Customer Impact

Testing

Risk

IMPORTANT: If this backport is for a servicing release, please verify that:

  • The PR target branch is release/X.0-staging, not release/X.0.

  • If the change touches code that ships in a NuGet package, you have added the necessary package authoring and gotten it explicitly reviewed.

Author:github-actions[bot]
Assignees:-
Labels:

area-CodeGen-coreclr

Milestone:-

@jeffschwMSFTjeffschwMSFT left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

approved. please get a code review, you are good to merge

@carlossanlop

Copy link
Copy Markdown
Contributor

FYI this is going into RC2 (release/8.0). If that's your intention, @jakobbotsch , then I can merge right away, since it has been signed-off and approved by @jeffschwMSFT .

If you intended to send it to RC1, please retarget the PR to release/8.0-rc1 and send an email to Tactics requesting approval.

@jakobbotsch

Copy link
Copy Markdown
Member

FYI this is going into RC2 (release/8.0). If that's your intention, @jakobbotsch , then I can merge right away, since it has been signed-off and approved by @jeffschwMSFT .

I think RC2 only is just fine.

@carlossanlopcarlossanlop added Servicing-consider Issue for next servicing release review Servicing-approved Approved for servicing release and removed Servicing-consider Issue for next servicing release review labels Aug 17, 2023
@carlossanlop
carlossanlop merged commit 3ab4246 into release/8.0Aug 17, 2023
@carlossanlop
carlossanlop deleted the backport/pr-90694-to-release/8.0 branch August 17, 2023 17:27
@ghostghost locked as resolved and limited conversation to collaborators Sep 16, 2023
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMIServicing-approvedApproved for servicing release

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@carlossanlop@jakobbotsch@EgorBo@jeffschwMSFT
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); [release/8.0] JIT: Disallow mismatched GC-ness for physical promotions by github-actions[bot] · Pull Request #90739 · dotnet/runtime · GitHub
Skip to content

[release/8.0] JIT: Disallow mismatched GC-ness for physical promotions - #90739

Merged
carlossanlop merged 2 commits into
release/8.0from
backport/pr-90694-to-release/8.0
Aug 17, 2023
Merged

[release/8.0] JIT: Disallow mismatched GC-ness for physical promotions#90739
carlossanlop merged 2 commits into
release/8.0from
backport/pr-90694-to-release/8.0

Conversation

@github-actions

@github-actionsgithub-actionsBot commented Aug 17, 2023

Copy link
Copy Markdown
Contributor

Backport of #90694 to release/8.0

/cc @jakobbotsch

Customer Impact

Code that involves illegal reinterpretations of GC pointers in unreachable code paths can cause the JIT to generate code with incorrect GC reporting, even in the reachable paths.
For example, MemoryMarshal.Contains is a case. When value is a GC pointer, RuntimeHelpers.IsBitwiseEquatable<T>() will return false, but under some stress scenarios the JIT will still see the later Unsafe.As<T, long>(ref value). This can cause it to mistakenly reinterpret value as a long without any GC reporting, even outside the RuntimeHelpers.IsBitwiseEquatable<T>() branch.
For this particular case, in normal circumstances (no stress modes) the unreachable code is folded away early enough that the JIT does not see the reinterpretation, so no issue happens.

Testing

Verified that the failing test case now generates correct code and GC reporting, even when the stress variables are set.

Risk

Low. Targeted fix with no diffs in any of our own code (under non stress circumstances) that disables physical promotion when the case is detected.

Physical promotion was working under the assumption that reinterpreting
GC pointers is undefined behavior, and would happily promote GC pointers
as integers if it saw such accesses. However, physical promotion is
function wide while the UB accesses can be happening in a restricted
(dynamically unreachable) scope. This exact situation happens in
MemoryExtensions.Contains. The issue was uncovered under jit stress
where we did not fold away the guard early enough, meaning that
promotion then saw a `TYP_LONG` access of a `struct { object, int }` and
proceeded to promote it as such.
Fix#90602
@ghostghost added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label Aug 17, 2023
@ghost

Copy link
Copy Markdown

Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
See info in area-owners.md if you want to be subscribed.

Issue Details

Backport of #90694 to release/8.0

/cc @jakobbotsch

Customer Impact

Testing

Risk

IMPORTANT: If this backport is for a servicing release, please verify that:

  • The PR target branch is release/X.0-staging, not release/X.0.

  • If the change touches code that ships in a NuGet package, you have added the necessary package authoring and gotten it explicitly reviewed.

Author:github-actions[bot]
Assignees:-
Labels:

area-CodeGen-coreclr

Milestone:-

@jeffschwMSFTjeffschwMSFT left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

approved. please get a code review, you are good to merge

@carlossanlop

Copy link
Copy Markdown
Contributor

FYI this is going into RC2 (release/8.0). If that's your intention, @jakobbotsch , then I can merge right away, since it has been signed-off and approved by @jeffschwMSFT .

If you intended to send it to RC1, please retarget the PR to release/8.0-rc1 and send an email to Tactics requesting approval.

@jakobbotsch

Copy link
Copy Markdown
Member

FYI this is going into RC2 (release/8.0). If that's your intention, @jakobbotsch , then I can merge right away, since it has been signed-off and approved by @jeffschwMSFT .

I think RC2 only is just fine.

@carlossanlopcarlossanlop added Servicing-consider Issue for next servicing release review Servicing-approved Approved for servicing release and removed Servicing-consider Issue for next servicing release review labels Aug 17, 2023
@carlossanlop
carlossanlop merged commit 3ab4246 into release/8.0Aug 17, 2023
@carlossanlop
carlossanlop deleted the backport/pr-90694-to-release/8.0 branch August 17, 2023 17:27
@ghostghost locked as resolved and limited conversation to collaborators Sep 16, 2023
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMIServicing-approvedApproved for servicing release

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@carlossanlop@jakobbotsch@EgorBo@jeffschwMSFT