Skip to content

Crash in GC in the System.Globalization test #130286

Description

@MichalStrehovsky

Not clear if this is specific to the test, looks like a corruption...

0:000> k
 # Child-SP          RetAddr               Call Site
00 (Inline Function) --------`--------     System_Globalization!WKS::gc_heap::mark_array_marked+0xe [/__w/1/s/src/coreclr/gc/gcinternal.h @ 2741] 
01 (Inline Function) --------`--------     System_Globalization!WKS::gc_heap::background_mark1+0xe [/crossrootfs/x64/usr/include/x86_64-linux-gnu/bits/stdint-uintn.h @ 3233] 
02 (Inline Function) --------`--------     System_Globalization!WKS::gc_heap::background_mark+0x20 [/crossrootfs/x64/usr/include/x86_64-linux-gnu/bits/stdint-uintn.h @ 3253] 
03 00007c03`999987c0 000056a5`5f044122     System_Globalization!WKS::gc_heap::background_mark_simple1+0x420 [/__w/1/s/src/coreclr/gc/mark_phase.cpp @ 289] 
04 (Inline Function) --------`--------     System_Globalization!WKS::gc_heap::background_mark_simple+0x64 [/__w/1/s/src/coreclr/gc/background.cpp @ 477] 
05 00007c03`99998820 000056a5`5f059f4e     System_Globalization!WKS::gc_heap::background_promote+0x122 [/__w/1/s/src/coreclr/gc/mark_phase.cpp @ 565] 
06 (Inline Function) --------`--------     System_Globalization!ScanConsecutiveHandlesWithoutUserData+0x3f [/__w/1/s/src/coreclr/gc/handletablescan.cpp @ 442] 
07 00007c03`99998840 000056a5`5f05aa42     System_Globalization!BlockScanBlocksWithoutUserData+0x7e [/crossrootfs/x64/usr/include/stdint.h @ 554] 
08 (Inline Function) --------`--------     System_Globalization!ProcessScanQNode+0x39 [/__w/1/s/src/coreclr/gc/handletablescan.cpp @ 1283] 
09 (Inline Function) --------`--------     System_Globalization!ProcessScanQueue+0x76 [/crossrootfs/x64/usr/include/stdint.h @ 1253] 
0a 00007c03`99998890 000056a5`5f05b459     System_Globalization!xxxTableScanQueuedBlocksAsync+0x1f2 [/crossrootfs/x64/usr/include/stdint.h @ 1364] 
0b (Inline Function) --------`--------     System_Globalization!xxxAsyncSegmentIterator+0x1c1 [/__w/1/s/src/coreclr/gc/handletablescan.cpp @ 1596] 
0c (Inline Function) --------`--------     System_Globalization!TableScanHandles+0x2bd [/crossrootfs/x64/usr/include/stdint.h @ 1758] 
0d 00007c03`999988f0 000056a5`5f056f62     System_Globalization!xxxTableScanHandlesAsync+0x349 [/crossrootfs/x64/usr/include/stdint.h @ 1840] 
0e 00007c03`99998ad0 000056a5`5f05c21d     System_Globalization!HndScanHandlesForGC+0x172 [/__w/1/s/src/coreclr/nativeaot/Runtime/../../gc/env/gcenv.base.h @ 800] 
0f 00007c03`99998b80 000056a5`5f028c6b     System_Globalization!Ref_TraceNormalRoots+0xcd [/__w/1/s/src/coreclr/gc/objecthandle.cpp @ 1049] 
10 00007c03`99998c10 000056a5`5f0279b5     System_Globalization!WKS::gc_heap::background_mark_phase+0x3db [/__w/1/s/src/coreclr/gc/mark_phase.cpp @ 1868] 
11 00007c03`99998ce0 000056a5`5f044bbc     System_Globalization!WKS::gc_heap::gc1+0xf5 [/__w/1/s/src/coreclr/gc/collect.cpp @ 162] 
12 00007c03`99998d70 000056a5`5f015c08     System_Globalization!WKS::gc_heap::bgc_thread_function+0x9c [/__w/1/s/src/coreclr/gc/mark_phase.cpp @ 3168] 
13 (Inline Function) --------`--------     System_Globalization!GCToEEInterface::CreateThread(void (*)(void*), void*, bool, char const*)::$_0::operator() const+0x4b [/__w/1/s/src/coreclr/nativeaot/Runtime/gcenv.ee.cpp @ 642] 
14 00007c03`99998db0 00007c07`93295b7b     System_Globalization!GCToEEInterface::CreateThread(void (*)(void*), void*, bool, char const*)::$_0::__invoke+0x58 [/__w/1/s/src/coreclr/nativeaot/Runtime/gcenv.ee.cpp @ 621] 

Console log: 'System.Globalization.Tests' from job 4151bc93-6412-4a3d-81c5-148e9a0efd70 (azurelinux.3.amd64.open.rt) using docker image mcr.microsoft.com/dotnet-buildtools/prereqs:debian-13-helix-amd64@sha256:ae75186ef6fe6cc3f70ac978d41d08e35d07c511e687468cbc20d0c87f719ae5 on a00KU1R
running $HELIX_CORRELATION_PAYLOAD/scripts/8e57fb05d1bc425eb1ebf053eab968d4/execute.sh in /datadisks/disk1/work/9F90090D/w/A4C608F4/e max 900 seconds

Output:
[BEGIN EXECUTION]
+ cd /root/helix/work/workitem/e
+ mkdir -p /datadisks/disk1/dumps/
+ /root/helix/work/correlation/scripts/8e57fb05d1bc425eb1ebf053eab968d4/execute.sh
+ export __TestArchitecture=x64
+ ./RunTests.sh --runtime-path /root/helix/work/correlation
========================= Begin custom configuration settings ==============================
export XUNIT_HIDE_PASSING_OUTPUT_DIAGNOSTICS=1
========================== End custom configuration settings ===============================
----- start Tue Jul 7 01:22:18 AM UTC 2026 =============== To repro directly: =====================================================
pushd .
chmod +rwx System.Globalization.Tests ^&^& ./System.Globalization.Tests -notrait category=IgnoreForCI -notrait category=OuterLoop -notrait category=failing -xml testResults.xml 
popd
===========================================================================================================
/root/helix/work/workitem/e /root/helix/work/workitem/e
Running assembly:System.Globalization.Tests, Version=11.0.0.0, Culture=neutral, PublicKeyToken=cc7b13ffcd2ddd51
DOTNET_DbgEnableMiniDump is set and the createdump binary does not exist: ./createdump
./RunTests.sh: line 173:    18 Segmentation fault      (core dumped) ./System.Globalization.Tests -notrait category=IgnoreForCI -notrait category=OuterLoop -notrait category=failing -xml testResults.xml $RSP_FILE
/root/helix/work/workitem/e
----- end Tue Jul 7 01:22:18 AM UTC 2026 ----- exit code 139 ----------------------------------------------------------
exit code 139 means SIGSEGV Illegal memory access. Deref invalid pointer, overrunning buffer, stack overflow etc. Core dumped.

Build Information

Build: https://dev.azure.com/dnceng-public/cbb18261-c48f-4abb-8651-8cdcb5474649/_build/results?buildId=1496147
Build error leg or test failing: System.Globalization.Tests.WorkItemExecution
Pull request: #130218

Error Message

DO NOT USE JSON BELOW IF THIS IS A BUILD BREAK otherwise build analysis will allow pull requests to merge that break the build worse. For a build break, do not use this issue form. Make a regular new issue.

Fill the error message using step by step known issues guidance.

{
  "ErrorMessage": "",
  "ErrorPattern": "",
  "BuildRetry": false,
  "ExcludeConsoleLog": false
}

Report

Summary

24-Hour Hit Count 7-Day Hit Count 1-Month Count
0 0 0

Activity

  1. added this to the 11.0.0 milestone on Jul 7, 2026
  2. dotnet-policy-service commented on Jul 7, 2026

    @dotnet-policy-service
    Contributor

    Tagging subscribers to this area: @agocke, @dotnet/ilc-contrib
    See info in area-owners.md if you want to be subscribed.

  3. MichalStrehovsky commented on Jul 8, 2026

    @MichalStrehovsky
    MemberAuthor

    We have a chain of live objects that points to a dead object. We're lucky that this chain is immutable (readonly fields), so there's only one place where all of this is constructed and that's what I'm scrutinizing now.

    I'm suspicious about the following code:

    000133 mov      rsi, gword ptr [rbx+0x38]
                                ; gcrRegs +[rsi]
    000137 xorps    xmm0, xmm0
    00013A movups   xmmword ptr [rbp-0x150], xmm0
    000141 movups   xmmword ptr [rbp-0x140], xmm0
    000148 movups   xmmword ptr [rbp-0x130], xmm0
    00014F movups   xmmword ptr [rbp-0x120], xmm0
    000156 movups   xmmword ptr [rbp-0x110], xmm0
    00015D lea      rdi, [rbp-0x150]
    000164 mov      edx, r15d
    000167 call     Internal.Metadata.NativeFormat.Method:.ctor(Internal.Metadata.NativeFormat.MetadataReader,Internal.Metadata.NativeFormat.MethodHandle):this
                                ; gcrRegs -[rsi]
                                ; byrRegs -[r13]
    

    Here we initialize a struct and call its ctor. So far so good.

    But later on we seem to be copying this struct with CORINFO_HELP_MEMCPY. This expands to SpanHelpers.Memmove, so normal managed code that can take a GC anywhere. The struct has GC references. Is that legal?

    ; Assembly listing for method System.Reflection.Runtime.TypeInfos.NativeFormat.NativeFormatRuntimeNamedTypeInfo+<CoreGetDeclaredConstructors>d__58:MoveNext():bool:this (FullOpts)
    ; Emitting BLENDED_CODE for x64 on Unix
    ; FullOpts code
    ; NativeAOT compilation
    ; optimized code
    ; rbp based frame
    ; partially interruptible
    ; Final local variable assignments
    ;
    ;  V00 this         [V00,T02] ( 21, 29.50)     ref  ->  rbx         this class-hnd exact single-def <System.Reflection.Runtime.TypeInfos.NativeFormat.NativeFormatRuntimeNamedTypeInfo+<CoreGetDeclaredConstructors>d__58>
    ;  V01 loc0         [V01,T19] (  3,  2.50)     int  ->  r15        
    ;  V02 loc1         [V02,T18] (  6,  3.50)     ref  ->  r14         class-hnd exact single-def <System.Reflection.Runtime.TypeInfos.NativeFormat.NativeFormatRuntimeNamedTypeInfo>
    ;* V03 loc2         [V03    ] (  0,  0   )  struct (16) zero-ref    ld-addr-op <Internal.Metadata.NativeFormat.MethodHandleCollection>
    ;* V04 loc3         [V04    ] (  0,  0   )  struct ( 8) zero-ref    ld-addr-op <Internal.Metadata.NativeFormat.MethodHandle>
    ;  V05 loc4         [V05    ] (  3, 10   )  struct (80) [rbp-0x78]  do-not-enreg[XS] must-init addr-exposed ld-addr-op <Internal.Metadata.NativeFormat.Method>
    ;# V06 OutArgs      [V06    ] (  1,  1   )  struct ( 0) [rsp+0x00]  do-not-enreg[XS] addr-exposed "OutgoingArgSpace" <Empty>
    ;* V07 tmp1         [V07    ] (  0,  0   )  struct (24) zero-ref    do-not-enreg[S] "stack copy for value returned via return buffer" <Internal.Metadata.NativeFormat.MethodHandleCollection+Enumerator>
    ;  V08 tmp2         [V08,T23] (  2,  2   )  struct (112) [rbp-0xE8]  do-not-enreg[SF] must-init ld-addr-op "NewObj constructor temp" <System.Reflection.Runtime.MethodInfos.NativeFormat.NativeFormatMethodCommon>
    ;  V09 tmp3         [V09,T07] (  4, 12   )     ref  ->  r13         class-hnd "impAppendStmt" <System.Reflection.Runtime.BindingFlagSupport.NameFilter>
    ;* V10 tmp4         [V10    ] (  0,  0   )  struct ( 8) zero-ref    "spilled call-like call argument" <Internal.Metadata.NativeFormat.ConstantStringValueHandle>
    ;  V11 tmp5         [V11,T16] (  3,  4   )   ubyte  ->  rax         "guarded devirt return temp"
    ;  V12 tmp6         [V12,T09] (  4, 10   )     ref  ->  r12         class-hnd exact "guarded devirt arg temp" <Internal.Metadata.NativeFormat.MetadataReader>
    ;* V13 tmp7         [V13    ] (  0,  0   )     ref  ->  zero-ref    class-hnd exact "guarded devirt this exact temp" <System.Reflection.Runtime.BindingFlagSupport.NameFilterCaseInsensitive>
    ;* V14 tmp8         [V14    ] (  0,  0   )     ref  ->  zero-ref    class-hnd exact "guarded devirt this exact temp" <System.Reflection.Runtime.BindingFlagSupport.NameFilterCaseSensitive>
    ;* V15 tmp9         [V15    ] (  0,  0   )   byref  ->  zero-ref    "Inlining Arg"
    ;  V16 tmp10        [V16    ] (  8,  8   )  struct (24) [rbp-0x100]  do-not-enreg[XS] must-init addr-exposed ld-addr-op "NewObj constructor temp" <Internal.Metadata.NativeFormat.MethodHandleCollection+Enumerator>
    ;* V17 tmp11        [V17    ] (  0,  0   )     ref  ->  zero-ref    class-hnd exact single-def "Inlining Arg" <Internal.NativeFormat.NativeReader>
    ;* V18 tmp12        [V18    ] (  0,  0   )     int  ->  zero-ref    "Inlining Arg"
    ;* V19 tmp13        [V19    ] (  0,  0   )   byref  ->  zero-ref    "Inlining Arg"
    ;  V20 tmp14        [V20,T03] (  2, 16   )     ref  ->  rsi         class-hnd exact "Inlining Arg" <Internal.Metadata.NativeFormat.MetadataReader>
    ;  V21 tmp15        [V21    ] (  3, 24   )  struct (80) [rbp-0x150]  do-not-enreg[XS] must-init addr-exposed ld-addr-op "NewObj constructor temp" <Internal.Metadata.NativeFormat.Method>
    ;* V22 tmp16        [V22    ] (  0,  0   )  struct ( 8) zero-ref    ld-addr-op "Inlining Arg" <Internal.Metadata.NativeFormat.ConstantStringValueHandle>
    ;* V23 tmp17        [V23    ] (  0,  0   )  struct (24) zero-ref    ld-addr-op "Inline stloc first use temp" <Internal.Metadata.NativeFormat.ConstantStringValue>
    ;* V24 tmp18        [V24    ] (  0,  0   )     ref  ->  zero-ref    class-hnd exact "impAppendStmt" <System.String>
    ;  V25 tmp19        [V25    ] (  8, 16   )  struct (24) [rbp-0x168]  do-not-enreg[XS] must-init addr-exposed ld-addr-op "NewObj constructor temp" <Internal.Metadata.NativeFormat.ConstantStringValue>
    ;* V26 tmp20        [V26    ] (  0,  0   )  struct ( 8) zero-ref    ld-addr-op "Inlining Arg" <Internal.Metadata.NativeFormat.ConstantStringValueHandle>
    ;* V27 tmp21        [V27    ] (  0,  0   )     int  ->  zero-ref    "Inline stloc first use temp"
    ;* V28 tmp22        [V28    ] (  0,  0   )     ref  ->  zero-ref    class-hnd exact "Inlining Arg" <Internal.NativeFormat.NativeReader>
    ;* V29 tmp23        [V29    ] (  0,  0   )  struct ( 8) zero-ref    ld-addr-op "Inlining Arg" <Internal.Metadata.NativeFormat.ConstantStringValueHandle>
    ;  V30 tmp24        [V30,T17] (  2,  4   )     ref  ->  rdx         class-hnd exact "Inlining Arg" <System.String>
    ;* V31 tmp25        [V31    ] (  0,  0   )  struct ( 8) zero-ref    ld-addr-op "Inlining Arg" <Internal.Metadata.NativeFormat.ConstantStringValueHandle>
    ;* V32 tmp26        [V32    ] (  0,  0   )     ref  ->  zero-ref    class-hnd exact "impAppendStmt" <Internal.NativeFormat.NativeReader>
    ;* V33 tmp27        [V33    ] (  0,  0   )  struct ( 8) zero-ref    "Inlining Arg" <Internal.Metadata.NativeFormat.MethodHandle>
    ;  V34 tmp28        [V34,T21] (  2,  2   )     ref  ->  r13         class-hnd single-def "Inlining Arg" <System.Reflection.Runtime.TypeInfos.RuntimeTypeInfo>
    ;* V35 tmp29        [V35    ] (  0,  0   )     ref  ->  zero-ref    class-hnd exact single-def "Inlining Arg" <Internal.Metadata.NativeFormat.MetadataReader>
    ;  V36 tmp30        [V36    ] (  2,  2   )  struct (80) [rbp-0x1B8]  do-not-enreg[XS] must-init addr-exposed ld-addr-op "NewObj constructor temp" <Internal.Metadata.NativeFormat.Method>
    ;  V37 tmp31        [V37,T14] (  5,  5   )  struct (112) [rbp-0x228]  do-not-enreg[SF] must-init "Inlining Arg" <System.Reflection.Runtime.MethodInfos.NativeFormat.NativeFormatMethodCommon>
    ;  V38 tmp32        [V38,T15] (  4,  4   )     ref  ->  [rbp-0x238]  class-hnd exact spill-single-def "NewObj constructor temp" <System.Reflection.Runtime.MethodInfos.RuntimePlainConstructorInfo`1[System.Reflection.Runtime.MethodInfos.NativeFormat.NativeFormatMethodCommon]>
    ;* V39 tmp33        [V39    ] (  0,  0   )   ubyte  ->  zero-ref    "Inline return value spill temp"
    ;  V40 tmp34        [V40,T00] (  7, 56   )   byref  ->  r15         "Inlining Arg"
    ;  V41 tmp35        [V41,T04] (  2, 16   )     ref  ->  rdi         class-hnd exact "Inlining Arg" <Internal.NativeFormat.NativeReader>
    ;  V42 tmp36        [V42,T01] (  4, 32   )     int  ->  rsi         "Inlining Arg"
    ;  V43 tmp37        [V43    ] (  2,  8   )     int  ->  [rbp-0x230]  do-not-enreg[X] addr-exposed ld-addr-op "Inline ldloca(s) first use temp"
    ;  V44 tmp38        [V44,T05] (  2, 16   )   byref  ->  r13         "Inlining Arg"
    ;* V45 tmp39        [V45    ] (  0,  0   )  struct ( 8) zero-ref    ld-addr-op "NewObj constructor temp" <Internal.Metadata.NativeFormat.MethodHandle>
    ;  V46 tmp40        [V46,T06] (  2, 16   )     int  ->  rdi         "Inlining Arg"
    ;  V47 tmp41        [V47,T24] (  3,  1.50)     ref  ->  rdi         single-def "field V03._reader (fldOffset=0x0)" P-INDEP
    ;  V48 tmp42        [V48,T25] (  2,  1   )     int  ->  rsi         "field V03._offset (fldOffset=0x8)" P-INDEP
    ;  V49 tmp43        [V49,T10] (  4,  9   )     int  ->  r15         "field V04._value (fldOffset=0x0)" P-INDEP
    ;  V50 tmp44        [V50,T12] (  5,  6   )     int  ->  rsi         "field V10._value (fldOffset=0x0)" P-INDEP
    ;  V51 tmp45        [V51    ] (  2,  1   )     ref  ->  [rbp-0x100]  do-not-enreg[X] addr-exposed "field V16._reader (fldOffset=0x0)" P-DEP
    ;  V52 tmp46        [V52    ] (  2,  1   )     int  ->  [rbp-0xF8]  do-not-enreg[X] addr-exposed "field V16._offset (fldOffset=0x8)" P-DEP
    ;  V53 tmp47        [V53    ] (  2,  1   )     int  ->  [rbp-0xF4]  do-not-enreg[X] addr-exposed "field V16._remaining (fldOffset=0xc)" P-DEP
    ;  V54 tmp48        [V54    ] (  2,  1   )     int  ->  [rbp-0xF0]  do-not-enreg[X] addr-exposed "field V16._current (fldOffset=0x10)" P-DEP
    ;* V55 tmp49        [V55    ] (  0,  0   )     int  ->  zero-ref    "field V22._value (fldOffset=0x0)" P-INDEP
    ;* V56 tmp50        [V56    ] (  0,  0   )     ref  ->  zero-ref    "field V23._reader (fldOffset=0x0)" P-INDEP
    ;  V57 tmp51        [V57,T22] (  2,  2   )     ref  ->  rdi         "field V23._value (fldOffset=0x8)" P-INDEP
    ;* V58 tmp52        [V58    ] (  0,  0   )     int  ->  zero-ref    "field V23._handle (fldOffset=0x10)" P-INDEP
    ;  V59 tmp53        [V59    ] (  3,  4   )     ref  ->  [rbp-0x168]  do-not-enreg[X] addr-exposed "field V25._reader (fldOffset=0x0)" P-DEP
    ;  V60 tmp54        [V60    ] (  4,  5   )     ref  ->  [rbp-0x160]  do-not-enreg[X] addr-exposed "field V25._value (fldOffset=0x8)" P-DEP
    ;  V61 tmp55        [V61    ] (  3,  4   )     int  ->  [rbp-0x158]  do-not-enreg[X] addr-exposed "field V25._handle (fldOffset=0x10)" P-DEP
    ;* V62 tmp56        [V62    ] (  0,  0   )     int  ->  zero-ref    "field V26._value (fldOffset=0x0)" P-INDEP
    ;* V63 tmp57        [V63    ] (  0,  0   )     int  ->  zero-ref    "field V29._value (fldOffset=0x0)" P-INDEP
    ;* V64 tmp58        [V64    ] (  0,  0   )     int  ->  zero-ref    "field V31._value (fldOffset=0x0)" P-INDEP
    ;* V65 tmp59        [V65    ] (  0,  0   )     int  ->  zero-ref    "field V33._value (fldOffset=0x0)" P-INDEP
    ;  V66 tmp60        [V66,T11] (  2,  8   )     int  ->  rdi         "field V45._value (fldOffset=0x0)" P-INDEP
    ;* V67 tmp61        [V67    ] (  0,  0   )     ref  ->  zero-ref    single-def "V08.[000..008)"
    ;* V68 tmp62        [V68    ] (  0,  0   )     ref  ->  zero-ref    single-def "V08.[008..016)"
    ;  V69 tmp63        [V69,T20] (  4,  2   )     ref  ->  r12         single-def "V08.[016..024)"
    ;* V70 tmp64        [V70    ] (  0,  0   )     int  ->  zero-ref    "V08.[024..028)"
    ;* V71 tmp65        [V71    ] (  0,  0   )     ref  ->  zero-ref    single-def "V37.[000..008)"
    ;* V72 tmp66        [V72    ] (  0,  0   )     ref  ->  zero-ref    single-def "V37.[008..016)"
    ;* V73 tmp67        [V73    ] (  0,  0   )     ref  ->  zero-ref    single-def "V37.[016..024)"
    ;* V74 tmp68        [V74    ] (  0,  0   )     int  ->  zero-ref    "V37.[024..028)"
    ;  V75 cse0         [V75,T08] (  3, 12   )     int  ->  rdx         "CSE #04: moderate"
    ;  V76 cse1         [V76,T13] (  3,  6   )     ref  ->  r13         "CSE #01: moderate"
    ;
    ; Lcl frame size = 536
    
    G_M4777_IG01:        ; bbWeight=1, gcrefRegs=0000 {}, byrefRegs=0000 {}, byref, prolog, nogc
    000000 push     rbp
    000001 push     r15
    000003 push     r14
    000005 push     r13
    000007 push     r12
    000009 push     rbx
    00000A sub      rsp, 536
    000011 lea      rbp, [rsp+0x240]
    000019 xor      eax, eax
    00001B mov      qword ptr [rbp-0x228], rax
    000022 xorps    xmm8, xmm8
    000026 movaps   xmmword ptr [rbp-0x220], xmm8
    00002E mov      rax, -480
    						;; size=56 bbWeight=1 PerfScore 9.58
    G_M4777_IG18:        ; bbWeight=1, prolog, nogc, extend
    000038 movaps   xmmword ptr [rbp+rax-0x30], xmm8
    00003E movaps   xmmword ptr [rbp+rax-0x20], xmm8
    000044 movaps   xmmword ptr [rbp+rax-0x10], xmm8
    00004A add      rax, 48
    00004E jne      SHORT G_M4777_IG18
    000050 mov      qword ptr [rbp-0x30], rax
    000054 mov      rbx, rdi
                                ; gcrRegs +[rbx]
    						;; size=31 bbWeight=1 PerfScore 5.50
    G_M4777_IG02:        ; bbWeight=1, gcrefRegs=0008 {rbx}, byrefRegs=0000 {}, byref, isz
    000057 mov      r15d, dword ptr [rbx+0x40]
    00005B mov      r14, gword ptr [rbx+0x10]
                                ; gcrRegs +[r14]
    00005F test     r15d, r15d
    000062 jne      SHORT G_M4777_IG04
    						;; size=13 bbWeight=1 PerfScore 5.25
    G_M4777_IG03:        ; bbWeight=0.50, gcrefRegs=4008 {rbx r14}, byrefRegs=0000 {}, byref, isz
    000064 mov      dword ptr [rbx+0x40], -1
    00006B mov      rsi, gword ptr [r14+0x28]
                                ; gcrRegs +[rsi]
    00006F lea      rdi, bword ptr [rbx+0x38]
                                ; byrRegs +[rdi]
    000073 call     CORINFO_HELP_ASSIGN_REF
                                ; gcrRegs -[rsi]
                                ; byrRegs -[rdi]
    000078 mov      rdi, gword ptr [r14+0x78]
                                ; gcrRegs +[rdi]
    00007C mov      esi, dword ptr [r14+0x80]
    000083 mov      gword ptr [rbp-0x100], rdi
    00008A lea      rdx, [rbp-0xF4]
    000091 cmp      dword ptr [rdi], edi
    000093 call     Internal.NativeFormat.NativeReader:DecodeUnsigned(uint,byref):uint:this
                                ; gcrRegs -[rdi]
    000098 mov      dword ptr [rbp-0xF8], eax
    00009E xor      edi, edi
    0000A0 mov      dword ptr [rbp-0xF0], edi
    0000A6 lea      rdi, bword ptr [rbx+0x48]
                                ; byrRegs +[rdi]
    0000AA mov      rsi, gword ptr [rbp-0x100]
                                ; gcrRegs +[rsi]
    0000B1 call     CORINFO_HELP_ASSIGN_REF
                                ; gcrRegs -[rsi]
                                ; byrRegs -[rdi]
    0000B6 mov      edx, dword ptr [rbp-0xF8]
    0000BC mov      dword ptr [rbx+0x50], edx
    0000BF mov      edx, dword ptr [rbp-0xF4]
    0000C5 mov      dword ptr [rbx+0x54], edx
    0000C8 mov      edx, dword ptr [rbp-0xF0]
    0000CE mov      dword ptr [rbx+0x58], edx
    0000D1 jmp      SHORT G_M4777_IG05
    						;; size=111 bbWeight=0.50 PerfScore 12.88
    G_M4777_IG04:        ; bbWeight=0.50, gcrefRegs=4008 {rbx r14}, byrefRegs=0000 {}, byref
    0000D3 cmp      r15d, 1
    0000D7 jne      G_M4777_IG16
    0000DD mov      dword ptr [rbx+0x40], -1
    						;; size=17 bbWeight=0.50 PerfScore 1.12
    G_M4777_IG05:        ; bbWeight=4, gcrefRegs=4008 {rbx r14}, byrefRegs=0000 {}, byref
    0000E4 lea      r15, bword ptr [rbx+0x48]
                                ; byrRegs +[r15]
    0000E8 mov      edx, dword ptr [r15+0x0C]
    0000EC test     edx, edx
    0000EE je       G_M4777_IG15
    0000F4 dec      edx
    0000F6 mov      dword ptr [r15+0x0C], edx
    0000FA mov      rdi, gword ptr [r15]
                                ; gcrRegs +[rdi]
    0000FD mov      esi, dword ptr [r15+0x08]
    000101 lea      r13, bword ptr [r15+0x10]
                                ; byrRegs +[r13]
    000105 lea      rdx, [rbp-0x230]
    00010C cmp      dword ptr [rdi], edi
    00010E call     Internal.NativeFormat.NativeReader:DecodeUnsigned(uint,byref):uint:this
                                ; gcrRegs -[rdi]
    000113 mov      esi, eax
    000115 mov      edi, dword ptr [rbp-0x230]
    00011B and      edi, 0x1FFFFFF
    000121 or       edi, 0x50000000
    000127 mov      dword ptr [r13], edi
    00012B mov      dword ptr [r15+0x08], esi
    00012F mov      r15d, dword ptr [rbx+0x58]
                                ; byrRegs -[r15]
    000133 mov      rsi, gword ptr [rbx+0x38]
                                ; gcrRegs +[rsi]
    000137 xorps    xmm0, xmm0
    00013A movups   xmmword ptr [rbp-0x150], xmm0
    000141 movups   xmmword ptr [rbp-0x140], xmm0
    000148 movups   xmmword ptr [rbp-0x130], xmm0
    00014F movups   xmmword ptr [rbp-0x120], xmm0
    000156 movups   xmmword ptr [rbp-0x110], xmm0
    00015D lea      rdi, [rbp-0x150]
    000164 mov      edx, r15d
    000167 call     Internal.Metadata.NativeFormat.Method:.ctor(Internal.Metadata.NativeFormat.MetadataReader,Internal.Metadata.NativeFormat.MethodHandle):this
                                ; gcrRegs -[rsi]
                                ; byrRegs -[r13]
    00016C lea      rdi, bword ptr [rbp-0x78]
                                ; byrRegs +[rdi]
    000170 lea      rsi, [rbp-0x150]
    000177 mov      edx, 80
    00017C call     CORINFO_HELP_MEMCPY
                                ; byrRegs -[rdi]
    000181 mov      rsi, gword ptr [rbx+0x38]
                                ; gcrRegs +[rsi]
    000185 lea      rdi, [rbp-0x78]
    000189 call     System.Reflection.Runtime.General.NativeFormatMetadataReaderExtensions:IsConstructor(byref,Internal.Metadata.NativeFormat.MetadataReader):bool
                                ; gcrRegs -[rsi]
    00018E test     eax, eax
    000190 je       G_M4777_IG05
    						;; size=178 bbWeight=4 PerfScore 139.33
    G_M4777_IG06:        ; bbWeight=2, gcrefRegs=4008 {rbx r14}, byrefRegs=0000 {}, byref, isz
    000196 mov      r13, gword ptr [rbx+0x18]
                                ; gcrRegs +[r13]
    00019A test     r13, r13
    00019D je       G_M4777_IG13
    0001A3 mov      esi, dword ptr [rbp-0x64]
    0001A6 mov      r12, gword ptr [rbx+0x38]
                                ; gcrRegs +[r12]
    0001AA lea      rdi, [(reloc 0x478a68)]      ; System.Reflection.Runtime.BindingFlagSupport.NameFilterCaseInsensitive
    0001B1 cmp      qword ptr [r13], rdi
    0001B5 je       SHORT G_M4777_IG08
    						;; size=33 bbWeight=2 PerfScore 19.50
    G_M4777_IG07:        ; bbWeight=1, gcrefRegs=7008 {rbx r12 r13 r14}, byrefRegs=0000 {}, byref, isz
    0001B7 mov      rdx, gword ptr [r13+0x08]
                                ; gcrRegs +[rdx]
    0001BB mov      rdi, gword ptr [r12+0x10]
                                ; gcrRegs +[rdi]
    0001C0 and      esi, 0x1FFFFFF
    0001C6 cmp      dword ptr [rdi], edi
    0001C8 call     Internal.NativeFormat.NativeReader:StringEquals(uint,System.String):bool:this
                                ; gcrRegs -[rdx rdi r12-r13]
    0001CD jmp      SHORT G_M4777_IG12
    						;; size=24 bbWeight=1 PerfScore 9.25
    G_M4777_IG08:        ; bbWeight=1, gcrefRegs=7008 {rbx r12 r13 r14}, byrefRegs=0000 {}, byref
                                ; gcrRegs +[r12-r13]
    0001CF xorps    xmm0, xmm0
    0001D2 movups   xmmword ptr [rbp-0x168], xmm0
    0001D9 movups   xmmword ptr [rbp-0x160], xmm0
    0001E0 xor      rdi, rdi
                                ; gcrRegs +[rdi]
    0001E2 mov      gword ptr [rbp-0x168], rdi
    						;; size=26 bbWeight=1 PerfScore 3.58
    G_M4777_IG09:        ; bbWeight=1, gcrefRegs=7008 {rbx r12 r13 r14}, byrefRegs=0000 {}, byref
                                ; gcrRegs -[rdi]
    0001E9 mov      dword ptr [rbp-0x158], edi
    						;; size=6 bbWeight=1 PerfScore 1.00
    G_M4777_IG10:        ; bbWeight=1, gcrefRegs=7008 {rbx r12 r13 r14}, byrefRegs=0000 {}, byref, isz
    0001EF mov      gword ptr [rbp-0x160], rdi
    0001F6 test     esi, 0x1FFFFFF
    0001FC je       SHORT G_M4777_IG11
    0001FE mov      gword ptr [rbp-0x168], r12
    000205 mov      dword ptr [rbp-0x158], esi
    00020B mov      rdi, gword ptr [r12+0x10]
                                ; gcrRegs +[rdi]
    000210 and      esi, 0x1FFFFFF
    000216 lea      rdx, [rbp-0x160]
    00021D cmp      dword ptr [rdi], edi
    00021F call     Internal.NativeFormat.NativeReader:DecodeString(uint,byref):uint:this
                                ; gcrRegs -[rdi r12]
    						;; size=53 bbWeight=1 PerfScore 10.00
    G_M4777_IG11:        ; bbWeight=1, gcrefRegs=6008 {rbx r13 r14}, byrefRegs=0000 {}, byref
    000224 mov      rdi, gword ptr [rbp-0x160]
                                ; gcrRegs +[rdi]
    00022B mov      rsi, gword ptr [r13+0x08]
                                ; gcrRegs +[rsi]
    00022F mov      edx, 5
    000234 cmp      dword ptr [rdi], edi
    000236 call     System.String:Equals(System.String,int):bool:this
                                ; gcrRegs -[rsi rdi r13]
    						;; size=23 bbWeight=1 PerfScore 6.25
    G_M4777_IG12:        ; bbWeight=2, gcrefRegs=4008 {rbx r14}, byrefRegs=0000 {}, byref
    00023B test     eax, eax
    00023D je       G_M4777_IG05
    						;; size=8 bbWeight=2 PerfScore 2.50
    G_M4777_IG13:        ; bbWeight=0.50, gcrefRegs=4008 {rbx r14}, byrefRegs=0000 {}, byref
    000243 mov      r13, gword ptr [rbx+0x28]
                                ; gcrRegs +[r13]
    000247 mov      r12, gword ptr [r14+0x28]
                                ; gcrRegs +[r12]
    00024B cmp      byte  ptr [r12], r12b
    00024F lea      rdi, [rbp-0x1B8]
    000256 mov      rsi, r12
                                ; gcrRegs +[rsi]
    000259 mov      edx, r15d
    00025C call     Internal.Metadata.NativeFormat.Method:.ctor(Internal.Metadata.NativeFormat.MetadataReader,Internal.Metadata.NativeFormat.MethodHandle):this
                                ; gcrRegs -[rsi]
    000261 lea      rdi, bword ptr [rbp-0xC8]
                                ; byrRegs +[rdi]
    000268 lea      rsi, [rbp-0x1B8]
    00026F mov      edx, 80
    000274 call     CORINFO_HELP_MEMCPY
                                ; byrRegs -[rdi]
    000279 lea      rdi, bword ptr [rbp-0x228]
                                ; byrRegs +[rdi]
    000280 lea      rsi, [rbp-0xE8]
    000287 mov      edx, 112
    00028C call     CORINFO_HELP_MEMCPY
                                ; byrRegs -[rdi]
    000291 lea      rdi, [(reloc 0x46f370)]      ; System.Reflection.Runtime.MethodInfos.RuntimePlainConstructorInfo`1[System.Reflection.Runtime.MethodInfos.NativeFormat.NativeFormatMethodCommon]
    000298 call     CORINFO_HELP_NEWSFAST
                                ; gcrRegs +[rax]
    00029D mov      gword ptr [rbp-0x238], rax
                                ; GC ptr vars +{V38}
    0002A4 mov      gword ptr [rbp-0x228], r14
    0002AB mov      gword ptr [rbp-0x220], r13
    0002B2 mov      gword ptr [rbp-0x218], r12
    0002B9 lea      rdi, bword ptr [rax+0x18]
                                ; byrRegs +[rdi]
    0002BD lea      rsi, [rbp-0x228]
    0002C4 mov      edx, 112
    0002C9 call     CORINFO_HELP_BULK_WRITEBARRIER
                                ; gcrRegs -[rax r12-r14]
                                ; byrRegs -[rdi]
    0002CE mov      r14, gword ptr [rbp-0x238]
                                ; gcrRegs +[r14]
    0002D5 mov      dword ptr [r14+0x30], r15d
    0002D9 lea      rdi, bword ptr [rbx+0x08]
                                ; byrRegs +[rdi]
    0002DD mov      rsi, r14
                                ; gcrRegs +[rsi]
                                ; GC ptr vars -{V38}
    0002E0 call     CORINFO_HELP_ASSIGN_REF
                                ; gcrRegs -[rsi r14]
                                ; byrRegs -[rdi]
    0002E5 mov      dword ptr [rbx+0x40], 1
    0002EC mov      eax, 1
    						;; size=174 bbWeight=0.50 PerfScore 12.62
    G_M4777_IG14:        ; bbWeight=0.50, epilog, nogc, extend
    0002F1 add      rsp, 536
    0002F8 pop      rbx
    0002F9 pop      r12
    0002FB pop      r13
    0002FD pop      r14
    0002FF pop      r15
    000301 pop      rbp
    000302 ret      
    						;; size=18 bbWeight=0.50 PerfScore 2.12
    G_M4777_IG15:        ; bbWeight=0.50, gcVars=0000000000000000 {}, gcrefRegs=0008 {rbx}, byrefRegs=0000 {}, gcvars, byref
    000303 xor      eax, eax
    000305 mov      qword ptr [rbx+0x48], rax
    000309 mov      qword ptr [rbx+0x50], rax
    00030D mov      qword ptr [rbx+0x58], rax
    						;; size=14 bbWeight=0.50 PerfScore 1.62
    G_M4777_IG16:        ; bbWeight=0.50, gcrefRegs=0000 {}, byrefRegs=0000 {}, byref
                                ; gcrRegs -[rbx]
    000311 xor      eax, eax
    						;; size=2 bbWeight=0.50 PerfScore 0.12
    G_M4777_IG17:        ; bbWeight=0.50, epilog, nogc, extend
    000313 add      rsp, 536
    00031A pop      rbx
    00031B pop      r12
    00031D pop      r13
    00031F pop      r14
    000321 pop      r15
    000323 pop      rbp
    000324 ret      
    						;; size=18 bbWeight=0.50 PerfScore 2.12
    
    ; Total bytes of code 805, prolog size 84, PerfScore 244.38, instruction count 178, allocated bytes for code 805 (MethodHash=808ded56) for method System.Reflection.Runtime.TypeInfos.NativeFormat.NativeFormatRuntimeNamedTypeInfo+<CoreGetDeclaredConstructors>d__58:MoveNext():bool:this (FullOpts)
    ; ============================================================
    
    Set code length to 805.
    Set stack base register to rbp.
    Set Outgoing stack arg area size to 0.
    Stack slot id for offset -120 (-0x78) (frame) (untracked) = 0.
    Stack slot id for offset -88 (-0x58) (frame) (untracked) = 1.
    Stack slot id for offset -72 (-0x48) (frame) (untracked) = 2.
    Stack slot id for offset -56 (-0x38) (frame) (untracked) = 3.
    Stack slot id for offset -232 (-0xe8) (frame) (untracked) = 4.
    Stack slot id for offset -224 (-0xe0) (frame) (untracked) = 5.
    Stack slot id for offset -216 (-0xd8) (frame) (untracked) = 6.
    Stack slot id for offset -200 (-0xc8) (frame) (untracked) = 7.
    Stack slot id for offset -168 (-0xa8) (frame) (untracked) = 8.
    Stack slot id for offset -152 (-0x98) (frame) (untracked) = 9.
    Stack slot id for offset -136 (-0x88) (frame) (untracked) = 10.
    Stack slot id for offset -256 (-0x100) (frame) (untracked) = 11.
    Stack slot id for offset -336 (-0x150) (frame) (untracked) = 12.
    Stack slot id for offset -304 (-0x130) (frame) (untracked) = 13.
    Stack slot id for offset -288 (-0x120) (frame) (untracked) = 14.
    Stack slot id for offset -272 (-0x110) (frame) (untracked) = 15.
    Stack slot id for offset -360 (-0x168) (frame) (untracked) = 16.
    Stack slot id for offset -352 (-0x160) (frame) (untracked) = 17.
    Stack slot id for offset -440 (-0x1b8) (frame) (untracked) = 18.
    Stack slot id for offset -408 (-0x198) (frame) (untracked) = 19.
    Stack slot id for offset -392 (-0x188) (frame) (untracked) = 20.
    Stack slot id for offset -376 (-0x178) (frame) (untracked) = 21.
    Stack slot id for offset -552 (-0x228) (frame) (untracked) = 22.
    Stack slot id for offset -544 (-0x220) (frame) (untracked) = 23.
    Stack slot id for offset -536 (-0x218) (frame) (untracked) = 24.
    Stack slot id for offset -520 (-0x208) (frame) (untracked) = 25.
    Stack slot id for offset -488 (-0x1e8) (frame) (untracked) = 26.
    Stack slot id for offset -472 (-0x1d8) (frame) (untracked) = 27.
    Stack slot id for offset -456 (-0x1c8) (frame) (untracked) = 28.
    Stack slot id for offset -568 (-0x238) (frame) = 29.
    Register slot id for reg rbx = 30.
    Register slot id for reg r14 = 31.
    Register slot id for reg r13 (byref) = 32.
    Register slot id for reg r15 (byref) = 33.
    Register slot id for reg r13 = 34.
    Register slot id for reg r12 = 35.
    Register slot id for reg rax = 36.
    Set state of slot 29 at instr offset 0x2a4 to Live.
    Set state of slot 29 at instr offset 0x2e0 to Dead.
    Set state of slot 30 at instr offset 0x93 to Live.
    Set state of slot 31 at instr offset 0x93 to Live.
    Set state of slot 30 at instr offset 0x98 to Dead.
    Set state of slot 31 at instr offset 0x98 to Dead.
    Set state of slot 30 at instr offset 0x10e to Live.
    Set state of slot 32 at instr offset 0x10e to Live.
    Set state of slot 31 at instr offset 0x10e to Live.
    Set state of slot 33 at instr offset 0x10e to Live.
    Set state of slot 30 at instr offset 0x113 to Dead.
    Set state of slot 32 at instr offset 0x113 to Dead.
    Set state of slot 31 at instr offset 0x113 to Dead.
    Set state of slot 33 at instr offset 0x113 to Dead.
    Set state of slot 30 at instr offset 0x167 to Live.
    Set state of slot 31 at instr offset 0x167 to Live.
    Set state of slot 30 at instr offset 0x16c to Dead.
    Set state of slot 31 at instr offset 0x16c to Dead.
    Set state of slot 30 at instr offset 0x17c to Live.
    Set state of slot 31 at instr offset 0x17c to Live.
    Set state of slot 30 at instr offset 0x181 to Dead.
    Set state of slot 31 at instr offset 0x181 to Dead.
    Set state of slot 30 at instr offset 0x189 to Live.
    Set state of slot 31 at instr offset 0x189 to Live.
    Set state of slot 30 at instr offset 0x18e to Dead.
    Set state of slot 31 at instr offset 0x18e to Dead.
    Set state of slot 30 at instr offset 0x1c8 to Live.
    Set state of slot 31 at instr offset 0x1c8 to Live.
    Set state of slot 30 at instr offset 0x1cd to Dead.
    Set state of slot 31 at instr offset 0x1cd to Dead.
    Set state of slot 30 at instr offset 0x21f to Live.
    Set state of slot 34 at instr offset 0x21f to Live.
    Set state of slot 31 at instr offset 0x21f to Live.
    Set state of slot 30 at instr offset 0x224 to Dead.
    Set state of slot 34 at instr offset 0x224 to Dead.
    Set state of slot 31 at instr offset 0x224 to Dead.
    Set state of slot 30 at instr offset 0x236 to Live.
    Set state of slot 31 at instr offset 0x236 to Live.
    Set state of slot 30 at instr offset 0x23b to Dead.
    Set state of slot 31 at instr offset 0x23b to Dead.
    Set state of slot 30 at instr offset 0x25c to Live.
    Set state of slot 35 at instr offset 0x25c to Live.
    Set state of slot 34 at instr offset 0x25c to Live.
    Set state of slot 31 at instr offset 0x25c to Live.
    Set state of slot 30 at instr offset 0x261 to Dead.
    Set state of slot 35 at instr offset 0x261 to Dead.
    Set state of slot 34 at instr offset 0x261 to Dead.
    Set state of slot 31 at instr offset 0x261 to Dead.
    Set state of slot 30 at instr offset 0x274 to Live.
    Set state of slot 35 at instr offset 0x274 to Live.
    Set state of slot 34 at instr offset 0x274 to Live.
    Set state of slot 31 at instr offset 0x274 to Live.
    Set state of slot 30 at instr offset 0x279 to Dead.
    Set state of slot 35 at instr offset 0x279 to Dead.
    Set state of slot 34 at instr offset 0x279 to Dead.
    Set state of slot 31 at instr offset 0x279 to Dead.
    Set state of slot 30 at instr offset 0x28c to Live.
    Set state of slot 35 at instr offset 0x28c to Live.
    Set state of slot 34 at instr offset 0x28c to Live.
    Set state of slot 31 at instr offset 0x28c to Live.
    Set state of slot 30 at instr offset 0x291 to Dead.
    Set state of slot 35 at instr offset 0x291 to Dead.
    Set state of slot 34 at instr offset 0x291 to Dead.
    Set state of slot 31 at instr offset 0x291 to Dead.
    Set state of slot 36 at instr offset 0x298 to Live.
    Set state of slot 30 at instr offset 0x298 to Live.
    Set state of slot 35 at instr offset 0x298 to Live.
    Set state of slot 34 at instr offset 0x298 to Live.
    Set state of slot 31 at instr offset 0x298 to Live.
    Set state of slot 36 at instr offset 0x29d to Dead.
    Set state of slot 30 at instr offset 0x29d to Dead.
    Set state of slot 35 at instr offset 0x29d to Dead.
    Set state of slot 34 at instr offset 0x29d to Dead.
    Set state of slot 31 at instr offset 0x29d to Dead.
    Set state of slot 30 at instr offset 0x2c9 to Live.
    Set state of slot 30 at instr offset 0x2ce to Dead.
    Defining 13 call sites:
        Offset 0x93, size 5.
        Offset 0x10e, size 5.
        Offset 0x167, size 5.
        Offset 0x17c, size 5.
        Offset 0x189, size 5.
        Offset 0x1c8, size 5.
        Offset 0x21f, size 5.
        Offset 0x236, size 5.
        Offset 0x25c, size 5.
        Offset 0x274, size 5.
        Offset 0x28c, size 5.
        Offset 0x298, size 5.
        Offset 0x2c9, size 5.
    
    
  4. dotnet-policy-service commented on Jul 8, 2026

    @dotnet-policy-service
    Contributor

    Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
    See info in area-owners.md if you want to be subscribed.

  5. MichalStrehovsky commented on Jul 8, 2026

    @MichalStrehovsky
    MemberAuthor

    Also cc @EgorBo - is it expected we'd be using CORINFO_HELP_MEMCPY (SpanHelpers.Memmove that just copies bytes) to copy structs that have GC references?

  6. added a commit that references this issue on Jul 8, 2026
    2df526f
  7. self-assigned this
    on Jul 8, 2026
  8. EgorBo commented on Jul 8, 2026

    @EgorBo
    Member

    Also cc @EgorBo - is it expected we'd be using CORINFO_HELP_MEMCPY (SpanHelpers.Memmove that just copies bytes) to copy structs that have GC references?

    Thanks for investigating, it does look like a fallout from my PR

  9. added a commit that references this issue on Jul 8, 2026
    c6e5137
  10. added a commit that references this issue on Jul 15, 2026
    d3e1fde
  11. locked and limited conversation to collaborators on Aug 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Known Build ErrorUse this to report build issues in the .NET Helix tabarea-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMIblocking-clean-ciBlocking PR or rolling runs of 'runtime' or 'runtime-extra-platforms'

Type

No type

Projects

  • Status
    No status

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions