Skip to content

JIT: preserve value evaluation when expanding reference array stores - #135458

Open
EgorBo wants to merge 3 commits into
dotnet:mainfrom
EgorBo:egorbo/fix-jit-133860
Open

EgorBo wants to merge 3 commits into
dotnet:mainfrom
EgorBo:egorbo/fix-jit-133860

Conversation

@EgorBo

@EgorBo EgorBo commented Oct 8, 2026 •

Copy link
Copy Markdown
Member

When morph replaces an array-store helper with a direct store, evaluate effectful operands in array/index/value order before introducing the array null and bounds checks. Enforce this at the conversion itself: importer spills can be undone by forward substitution while the operation is still a helper call.

Include ordering-only effects such as volatile reads, both in the conversion and in the existing inline array-store importer spill.

Fixes #133860

Almost no diffs

PR description draft:
<!-- -->
When morph replaces an array-store helper with a direct store, evaluate effectful operands in array/index/value order before introducing the array null and bounds checks. Enforce this at the conversion itself: importer spills can be undone by forward substitution while the operation is still a helper call.

Include ordering-only effects such as volatile reads, both in the conversion and in the existing inline array-store importer spill. Add a single-file regression covering value-expression exceptions and index-before-value exception ordering.

Fixes dotnet#133860

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: ae8155d6-f240-4542-a1da-c721ba933c91
@github-actions github-actions Bot added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label Oct 8, 2026
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 5 pipeline(s).
11 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
See info in area-owners.md if you want to be subscribed.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The equivalent multidimensional-array store path remains unfixed, and ordering-only behavior lacks regression coverage.

2 open findings
What changed in this PR

Fixes JIT evaluation ordering when expanding reference-array stores.

Changes:

  • Preserves array/index/value evaluation order during morphing.
  • Includes ordering-only effects such as volatile reads.
  • Adds exception-order regression coverage.
File Description
src/​coreclr/​jit/​morph.cpp Sequences operands before array checks.
src/​coreclr/​jit/​importer.cpp Recognizes observable ordering effects.
src/​tests/​JIT/​Regression_ro_2/​Runtime_133860.cs Tests exception precedence.

🧠 Review effort: Balanced

Comment thread src/coreclr/jit/importer.cpp
Comment thread src/tests/JIT/Regression_ro_2/Runtime_133860.cs
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: d844e008-f7ad-4958-ad42-de4c706fcb00
@EgorBo

EgorBo commented Oct 9, 2026

Copy link
Copy Markdown
Member Author

PTAL @dotnet/jit-contrib

@EgorBo
EgorBo requested a review from a team October 9, 2026 14:49

@JulieLeeMSFT JulieLeeMSFT left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. The new flag GTF_OBS_EFFECT (observable effect) appears to combine both exception-contributing effects (GTF_EXCEPT) and ordering-only effect (GTF_ORDER_SIDEEFF), closing a gap where ordering-only effects weren't being spilled.

Old (helper call):                 New (direct store, optimized):
 push array                         eval array ----+
 push index                         eval index ----|--> temps (preserve order)
 push value (may throw/order-dep)   eval value ----+
 call ARRADDR_ST (does checks       nullcheck/boundscheck (introduced here)
   array,index,value in order)      store

Finalize the new spill stores without reapplying assertions to operands already morphed by fgMorphArgs.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e8778de6-8ade-4f24-91f4-9060e1eb4744

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI

Projects

None yet

Development

Successfully merging this pull request may close these issues.

JIT: (bug) Wrong exception order for stelem.ref: the array range check runs before the value expression

3 participants