Skip to content

JIT: (bug) Emulated vector arithmetic right shift evaluates the shift count before the vector operand #134195

Description

@EgorBo

When >> on a vector has to be emulated, the JIT evaluates the shift-count operand before the vector operand, so the implicit exception checks of the two operands fire in the wrong order.

Minimal Repro

using System;
using System.Runtime.CompilerServices;
using System.Runtime.Intrinsics;

public class Program
{
    [MethodImpl(MethodImplOptions.NoInlining)]
    static Vector128<sbyte> Test(Vector128<sbyte>[] a, int[] b) => a[0] >> b[0];

    [MethodImpl(MethodImplOptions.NoInlining)]
    static Vector128<int> Control(Vector128<int>[] a, int[] b) => a[0] >> b[0];

    public static void Main()
    {
        try { Test(null!, Array.Empty<int>()); } catch (Exception e) { Console.WriteLine("sbyte: " + e.GetType().Name); }
        try { Control(null!, Array.Empty<int>()); } catch (Exception e) { Console.WriteLine("int  : " + e.GetType().Name); }
    }
}

Expected

sbyte: NullReferenceException
int  : NullReferenceException

Actual

sbyte: IndexOutOfRangeException
int  : NullReferenceException

Notes

Repros on released .NET 10.0.12, and also under DOTNET_JITMinOpts=1, so it is not optimizer-dependent.
sbyte is always emulated; Vector128<long>/Vector256<long> show the same reversal once AVX-512 is unavailable (DOTNET_EnableAVX512=0). short/int use a native psra* and are correct.
Only implicit checks reorder: side effects expressed as calls are spilled to temps in source order and stay correct.
gtNewSimdBinOpNode GT_RSH (gentree.cpp) puts the fgMakeMultiUse definition of the non-constant shift count into maskOp, which becomes the first operand of the ConditionalSelect, while the vector operand stays second.

Activity

  1. added this to the 12.0.0 milestone on Sep 18, 2026
  2. added
    area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI
    on Sep 18, 2026
  3. dotnet-policy-service commented on Sep 18, 2026

    @dotnet-policy-service
    Contributor

    Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
    See info in area-owners.md if you want to be subscribed.

  4. EgorBo commented on Sep 18, 2026

    @EgorBo
    MemberAuthor

    Affected SDK versions:

    • 10.0.401
    • 11.0.100-rc.2.26467.112
  5. added a commit that references this issue on Sep 24, 2026
    2f56ca5
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions