Repository navigation
[mono][aot] Fix stack overflow normalizing self-referencing struct wrappers - #135029
Merged
pavelsavara merged 1 commit intoOct 7, 2026
Merged
pavelsavara merged 1 commit into
pavelsavara merged 1 commit into
Conversation
…appers
get_wrapper_shared_vtype() normalizes every instance field of a struct and
get_wrapper_shared_type_full() normalizes every type argument of a generic
struct, calling back into get_wrapper_shared_vtype() for struct arguments.
A struct with a field of a generic struct instantiated over itself, e.g.
struct S { Box<S> F; }, made the two functions recurse without bound and
crashed mono-aot-cross with a native stack overflow while building gsharedvt
wrapper signatures.
Track the structs whose layout is being normalized in a stack-allocated
chain. On re-entry, or past a depth limit for shapes that grow on every
level, return NULL so the original type is kept, which is the existing
"do not share" outcome.
Fixes dotnet#132071
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
|
Azure Pipelines: Successfully started running 3 pipeline(s). 13 pipeline(s) were filtered out due to trigger conditions. There may be pipelines that require an authorized user to comment /azp run to run. |
1 task done
BrzVlad
approved these changes
Oct 2, 2026
Member
Author
|
/azp run runtime-wasm |
|
Azure Pipelines: Successfully started running 1 pipeline(s). |
Member
Author
|
/ba-g unrelated CI failures |
Member
Author
|
/backport to release/11.0 |
Contributor
|
Started backporting to |
Open
2 of 4 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
mono-aot-crosscrashed with a native stack overflow (0xC00000FD/ exit code-1073741571) on any assembly with a struct that has a field of a generic struct instantiated over the struct itself:Root cause
When building gsharedvt wrapper signatures,
get_wrapper_shared_vtype()normalizes each instance field of a struct.get_wrapper_shared_type_full()normalizes each type argument of a generic struct and calls back intoget_wrapper_shared_vtype()for struct arguments. ForSelf-> fieldBox<Self>-> type argumentSelf-> ..., nothing stops the recursion.Generic constraints are not involved, even though the shape in the issue has them; the cycle through the field type argument is enough.
Fix
Pass a stack-allocated chain of the structs whose layout is currently being normalized through both functions. If a struct is reached again while already in the chain,
get_wrapper_shared_vtype()returnsNULLand the original type is kept. That is the existing "do not share this valuetype" outcome. A depth limit of 16 also bounds shapes that create a new type on every level, such asstruct S<T> { Box<S<S<T>>> F; }.Testing
Tested with a Debug
mono-aot-crossbuilt from this branch (-os browser -subset mono+libs -c Debug), comparing against the shipped 10.0.11 compiler:aot-instances.dll(dedup, 31 assemblies)ValueTypeTests.StructWithSelfReferencingGenericFieldPassedToGenericMethodTestwith the self-referencing and mutual shapes. The browser AOT leg compilesSystem.Runtime.Tests, so before this fix the test assembly itself would crash the AOT compiler.System.Tests.ValueTypeTestson browser Mono with V8 (interpreter): 23/23 passed.System.Runtime.Tests; that is left to the CI browser AOT leg.Resolves #132071
Note
This PR description was drafted with GitHub Copilot.