Skip to content

[ci-scan] Test failure: GC object corruption assert (Object::ValidateInner) in runtime-coreclr jit-cfg #129835

Description

@github-actions

Build Information

Build: https://dev.azure.com/dnceng-public/public/_build/results?buildId=1474087
Build error leg or test failing: coreclr Pri1 Runtime Tests Run windows x64 checked-Loader.2.3

Error Details

Under CFG (Control Flow Guard) mode in runtime-coreclr jit-cfg (definition 155), the Loader and Regressions work items crash with a GC object validation assertion. The Object::ValidateInner function detects a corrupted OBJECTREF during GC enumeration of live slots, indicating a GC hole where a register or stack slot that GcInfo reports as containing an object reference actually holds corrupted data.

Affected tests include classloader/explicitlayout/objrefandnonobjrefoverlap/case13 and Regressions/coreclr/25057/byref/byref.dll.

Assert failure(PID 3748 [0x00000ea4], Thread: 4196 [0x1064]): !CREATE_CHECK_STRING(!"Detected use of a corrupted OBJECTREF. Possible GC hole.")

CORECLR! `Object::ValidateInner'::`1'::catch$7 + 0x139 (0x00007ff8`5b838cc9)
CORECLR! CallSettingFrame_LookupContinuationIndex + 0x20 (0x00007ff8`5b762c70)
CORECLR! _FrameHandler4::CxxCallCatchBlock + 0x1DE (0x00007ff8`5b76127e)
NTDLL! RtlCaptureContext + 0x3C3 (0x00007ff8`846ca523)
CORECLR! Object::ValidateInner + 0x119 (0x00007ff8`5b252b69)
CORECLR! Object::Validate + 0xB0 (0x00007ff8`5b252a10)
CORECLR! TGcInfoDecoder<AMD64GcInfoEncoding>::ReportRegisterToGC + 0x1A6 (0x00007ff8`5b701976)
CORECLR! TGcInfoDecoder<AMD64GcInfoEncoding>::EnumerateLiveSlots + 0x1726 (0x00007ff8`5b6fd816)
CORECLR! EECodeManager::EnumGcRefs + 0x2E7 (0x00007ff8`5b0fd397)

Affected pipelines:

  • runtime-coreclr jit-cfg (def 155): windows x64 checked, windows arm64 checked

First build it occurred: Build 1452746 (June 7, 2026). Prior build 1442662 (June 1) succeeded. 6 consecutive failures in window.

Related issues: #129545, #129546 (same GC validation asserts in Loader tests under gcstress)

Error Message

{
  "ErrorMessage": ["Detected use of a corrupted OBJECTREF. Possible GC hole.", "Object::ValidateInner"],
  "ErrorPattern": "",
  "BuildRetry": false,
  "ExcludeConsoleLog": false
}

Note

🔒 Integrity filter blocked 13 items

The following items were blocked because they don't meet the GitHub integrity level.

  • #84911 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
  • #95367 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
  • #108070 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
  • #114229 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
  • #112196 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
  • #129682 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
  • #128330 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
  • #126819 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
  • #115319 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
  • #91975 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
  • #114222 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
  • #116358 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
  • #86273 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".

To allow these resources, lower min-integrity in your GitHub frontmatter:

tools:
  github:
    min-integrity: approved  # merged | approved | unapproved | none

Generated by CI Outer-Loop Failure Scanner · ● 102M · ◷

Report

Build Repository Test Pull Request
1494962 dotnet/runtime Regressions.0.1.WorkItemExecution
1494753 dotnet/runtime Loader.2.3.WorkItemExecution
1494448 dotnet/runtime Regressions.0.1.WorkItemExecution
1494677 dotnet/runtime Regressions.0.1.WorkItemExecution
1494697 dotnet/runtime Regressions.0.1.WorkItemExecution
1494353 dotnet/runtime Regressions.0.1.WorkItemExecution
1494288 dotnet/runtime Loader.2.3.WorkItemExecution
1494227 dotnet/runtime Regressions.0.1.WorkItemExecution
1494234 dotnet/runtime Regressions.0.1.WorkItemExecution
1494098 dotnet/runtime Regressions.0.1.WorkItemExecution
1485325 dotnet/runtime Regressions.0.1.WorkItemExecution
1485063 dotnet/runtime Loader.2.3.WorkItemExecution
1484926 dotnet/runtime Regressions.0.1.WorkItemExecution
1484928 dotnet/runtime Regressions.0.1.WorkItemExecution
1484796 dotnet/runtime Regressions.0.1.WorkItemExecution
1484677 dotnet/runtime Regressions.0.1.WorkItemExecution
1484575 dotnet/runtime Loader.2.3.WorkItemExecution
1484484 dotnet/runtime Regressions.0.1.WorkItemExecution
1484494 dotnet/runtime Regressions.0.1.WorkItemExecution
1484288 dotnet/runtime Regressions.0.1.WorkItemExecution
1482287 dotnet/runtime ComInterfaceGenerator.Unit.Tests.WorkItemExecution #129877
1481259 dotnet/runtime Regressions.0.1.WorkItemExecution #129540
1481304 dotnet/runtime Regressions.0.1.WorkItemExecution #129791

Summary

24-Hour Hit Count 7-Day Hit Count 1-Month Count
0 5 23

Activity

  1. added and removed
    blocking-clean-ciBlocking PR or rolling runs of 'runtime' or 'runtime-extra-platforms'
    on Jun 26, 2026
  2. added this to the 11.0.0 milestone on Jun 26, 2026
  3. removed
    untriagedNew issue has not been triaged by the area owner
    on Jun 26, 2026
  4. github-actions commented on Jul 6, 2026

    @github-actions
    ContributorAuthor

    Workflow artifact: ci-fix
    Artifact kind: handoff
    Linked KBE: #129835

    Root-cause analysis (read-only hand-off)

    Under Control-Flow-Guard mode (runtime-coreclr jit-cfg, AzDO definition 155) the Loader and Regressions work items abort during GC stack enumeration:

    Assert failure: !"Detected use of a corrupted OBJECTREF. Possible GC hole."
      Object::ValidateInner
      TGcInfoDecoder<AMD64GcInfoEncoding>::ReportRegisterToGC
      TGcInfoDecoder<AMD64GcInfoEncoding>::EnumerateLiveSlots
      EECodeManager::EnumGcRefs
    

    A register/stack slot that GcInfo reports as containing a live object reference actually holds non-object data, so the GC dereferences a corrupted OBJECTREF. That is a JIT/GcInfo codegen defect (the GC-liveness reporting emitted by the JIT under CFG is inaccurate), not a test-side problem. Affected tests are classloader/explicitlayout/objrefandnonobjrefoverlap/case13 and Regressions/coreclr/25057/byref/byref.dll.

    Per this workflow's rules JIT/GC codegen fixes are out of bounds for an automated PR (no safe product diff, and a test-side workaround would only mask the GC hole), so this is a hand-off rather than a fix.

    Evidence

    Suggested reviewers / area contacts

    • area-CodeGen-coreclr: @JulieLeeMSFT, @dotnet/jit-contrib

    Note

    This root-cause hand-off was generated by an AI/Copilot agent (ci-failure-fix). No code change was produced because the failure is a JIT/GC codegen defect that must not be worked around in test code. Please verify before acting.

    Note

    🔒 Integrity filter blocked 6 items

    The following items were blocked because they don't meet the GitHub integrity level.

    To allow these resources, lower min-integrity in your GitHub frontmatter:

    tools:
      github:
        min-integrity: approved  # merged | approved | unapproved | none

    Generated by CI Outer-Loop Failure Fixer · ● 9.2M · ◷

  5. added
    area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI
    on Jul 7, 2026
  6. JulieLeeMSFT commented on Jul 7, 2026

    @JulieLeeMSFT
    Member

    possible duplicate #129959.

  7. dotnet-policy-service commented on Jul 7, 2026

    @dotnet-policy-service
    Contributor

    Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
    See info in area-owners.md if you want to be subscribed.

  8. EgorBo commented on Jul 15, 2026

    @EgorBo
    Member

    This is the same VM exception-dispatch / GC-stackwalk bug diagnosed in #129546 (not a JIT codegen defect): a GC ref held in a callee-saved register live across a call is mis-recovered during a GC stackwalk while a TypeLoadException thrown from the prestub dispatches. CFG mode just widens the window. Root cause + minimal repro: #129546 (comment)

    Duplicates / same root cause:

  9. EgorBo commented on Jul 15, 2026

    @EgorBo
    Member

    cc @jkotas @janvorli can someone from the VM team take look at it?

    Looks like various AI tools keep filing issues for the same issue (4 active issues now)

  10. removed their assignment
    on Jul 15, 2026
  11. added and removed
    area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI
    on Jul 15, 2026
  12. dotnet-policy-service commented on Jul 15, 2026

    @dotnet-policy-service
    Contributor

    Tagging subscribers to this area: @agocke
    See info in area-owners.md if you want to be subscribed.

  13. jkotas commented on Jul 15, 2026

    @jkotas
    Member

    Duplicate of #129682 . Fixed about a week ago.

  14. locked and limited conversation to collaborators on Aug 15, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    • Status
      No status

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions