Skip to content

[release/11.0] Fix SIMD primitive zero initialization - #133168

Merged
tannergooding merged 1 commit into
release/11.0from
backport/pr-133100-to-release/11.0
Sep 4, 2026
Merged

[release/11.0] Fix SIMD primitive zero initialization#133168
tannergooding merged 1 commit into
release/11.0from
backport/pr-133100-to-release/11.0

Conversation

@github-actions

@github-actions github-actions Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

Backport of #133100 to release/11.0

/cc @tannergooding

Customer Impact

  • Customer reported
  • Found internally

Reported in #133085. Zero-initializing a struct through a byref that the JIT can see is the address of a Vector128<T>/Vector256<T> local (Unsafe.As<Vector256<ulong>, S>(ref v) = default;) produces a SIMD store whose source is an integer zero constant. With optimizations that lowers to vmovq ymm0, rax (C4 E1 FD 6E C0), which has no valid VEX.256 encoding, so the process dies with ExecutionEngineException: Illegal instruction; at Tier0 the same method fails to compile and throws InvalidProgramException. Expected behavior is a SIMD zero (vxorps) in both modes.

The pattern shows up in code that reinterprets vector locals as multi-limb structs, and there is no compile-time diagnostic — it fails at runtime on any AVX-capable x64 machine.

Regression

  • Yes
  • No

Not a regression in 10.0 or 11.0 — .NET 9 fails the same way. The bad tree dates to the assignment rationalization work in #85585 (53b4cd0912d), where the legacy GT_ASG path updated gtOp2 but the rationalized store path never updated Data().

Testing

New regression test src/tests/JIT/Regression/JitBlue/Runtime_133085, covering Vector128<ulong> and Vector256<ulong> in both FullOpts (AggressiveOptimization) and Tier0. It reproduces the illegal encoding / InvalidProgramException without the fix and passes with it.

Missed previously because TryPrimitiveInit looked correct in isolation — it built the SIMD zero node and assigned it to m_src — and no existing test zero-initialized a SIMD local through a reinterpreted struct view, so nothing exercised the path where the store's data operand still had to be replaced.

Risk

Low. Two lines in TryPrimitiveInit, reached only when a block zero-init of a SIMD-typed local is converted into a primitive store. It makes the store's data node match the store's type, which is what the transform already intended; every other case was already consistent.

Note

This pull request description was generated with GitHub Copilot.

`TryPrimitiveInit` created a SIMD zero node when converting a zero block
initialization into a primitive local store, but the rationalized store
retained its original integer-zero data node. This produced a SIMD store
with an integer source, leading to invalid codegen and Tier0 compilation
failures.

The missing source replacement was introduced by the assignment
rationalization changes in #85585 (`53b4cd0912d`), where the legacy
`GT_ASG` path updated `gtOp2` but the rationalized store path did not
update `Data()`.

Before the fix, the `Vector256` case encoded `C4 E1 FD 6E C0` (`vmovq`
with `VEX.L=1`). The corrected tree emits a SIMD zero (`vxorps`) in both
FullOpts and Tier0. Regression coverage includes `Vector128` and
`Vector256` in both modes.

Fixes #133085

> [!NOTE]
> This pull request description was generated with GitHub Copilot.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@github-actions github-actions Bot added the area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI label Sep 3, 2026
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
See info in area-owners.md if you want to be subscribed.

@JulieLeeMSFT

Copy link
Copy Markdown
Member

@EgorBo, please review this servicing PR.

@JulieLeeMSFT JulieLeeMSFT added this to the 11.0.0 milestone Sep 3, 2026
@JulieLeeMSFT JulieLeeMSFT added the Servicing-consider Issue for next servicing release review label Sep 3, 2026
@JulieLeeMSFT JulieLeeMSFT added Servicing-approved Approved for servicing release and removed Servicing-consider Issue for next servicing release review labels Sep 3, 2026
@tannergooding

Copy link
Copy Markdown
Member

/ba-g helix monitor timeout

@tannergooding
tannergooding merged commit 59ddfdc into release/11.0 Sep 4, 2026
127 of 133 checks passed
@tannergooding
tannergooding deleted the backport/pr-133100-to-release/11.0 branch September 4, 2026 01:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-CodeGen-coreclr CLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI Servicing-approved Approved for servicing release

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants