Skip to content

JIT: guard overflow in loop cloning offset limits - #133834

Open
AndyAyersMS wants to merge 1 commit into
dotnet:mainfrom
AndyAyersMS:fix-133823-loop-cloning-overflow
Open

JIT: guard overflow in loop cloning offset limits#133834
AndyAyersMS wants to merge 1 commit into
dotnet:mainfrom
AndyAyersMS:fix-133823-loop-cloning-overflow

Conversation

@AndyAyersMS

Copy link
Copy Markdown
Member

Positive array length offsets can wrap negative and let the fast clone run
without bounds checks. Guard offsets that can overflow and add regression
coverage for decreasing loops.

Fixes #133823

Note

This pull request description was generated with GitHub Copilot.

Positive array length offsets can wrap negative and let the fast clone run
without bounds checks. Guard offsets that can overflow and add regression
coverage for decreasing loops.

Fixes dotnet#133823

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 336fb408-8580-4f7b-b3e6-087280a6294a
Copilot AI lite review requested due to automatic review settings September 13, 2026 23:38
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 5 pipeline(s).
11 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@github-actions github-actions Bot added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label Sep 13, 2026
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
See info in area-owners.md if you want to be subscribed.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

No unresolved review issues were identified.

Pull request overview

Guards JIT loop cloning against signed overflow in positive array-length offsets and adds regression coverage.

Changes:

  • Adds overflow detection for positive offset limits.
  • Tests decreasing loops using >, >=, and !=.
File summaries
File Description
src/tests/JIT/opt/Cloning/OffsetLimit.cs Adds positive-offset overflow regression tests.
src/coreclr/jit/loopcloning.cpp Adds an overflow-aware fast-clone guard.
Review details
  • Files reviewed: 2/2 changed files
  • Comments generated: 0
  • Review effort level: Lite

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI

Projects

None yet

Development

Successfully merging this pull request may close these issues.

JIT (bug): Loop cloning drops bounds checks when an arr.Length + K loop limit overflows to a negative value

2 participants