Skip to content

JIT: (bug) a negative constant dimension passed to Array.GetLength asserts in the importer #133556

Description

@EgorBo

Repro

using System;
using System.Runtime.CompilerServices;

class Program
{
    static int[,] s_md = new int[3, 4];

    [MethodImpl(MethodImplOptions.NoInlining | MethodImplOptions.AggressiveOptimization)]
    static string Test()
    {
        try { return s_md.GetLength(-1).ToString(); }
        catch (Exception e) { return e.GetType().Name; }
    }

    static void Main() => Console.WriteLine(Test());
}

Expected

IndexOutOfRangeException

Actual

Assert failure(PID 110488 [0x0001af98], Thread: 82424 [0x141f8]): Assertion failed '(unsigned int)dimValue == dimValue' in 'Program:Test():System.String' during 'Importation' (IL size 37; hash 0xe4e107d8; FullOpts)

    File: C:\prj\runtime-main3\src\coreclr\jit\importercalls.cpp:5381

The process aborts with exit code 0xC0000602.

Platform

Windows x64, local Checked build of dotnet/runtime main (ef97eb5). Not target-specific.
Requires a Checked/Debug JIT; a Release JIT throws IndexOutOfRangeException correctly.

Activity

added this to the 12.0.0 milestone on Sep 10, 2026
added
area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI
on Sep 10, 2026

dotnet-policy-service commented on Sep 10, 2026

@dotnet-policy-service
Contributor

Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
See info in area-owners.md if you want to be subscribed.

added a commit that references this issue on Sep 22, 2026
5edb3a2
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions