Skip to content

[release/10.0] Fix off-by-one error in TypePreinit switch instruction handling#127587

Open
github-actions[bot] wants to merge 1 commit intorelease/10.0from
backport/pr-123911-to-release/10.0
Open

[release/10.0] Fix off-by-one error in TypePreinit switch instruction handling#127587
github-actions[bot] wants to merge 1 commit intorelease/10.0from
backport/pr-123911-to-release/10.0

Conversation

@github-actions
Copy link
Copy Markdown
Contributor

Backport of #123911 to release/10.0

/cc @agocke @sbomer

Customer Impact

  • Customer reported
  • Found internally

[Select one or both of the boxes. Describe how this issue impacts customers, citing the expected and actual behaviors and scope of the issue. If customer-reported, provide the issue number.]

Regression

  • Yes
  • No

[If yes, specify when the regression was introduced. Provide the PR or commit if known.]

Testing

[How was the fix verified? How was the issue missed previously? What tests were added?]

Risk

[High/Medium/Low. Justify the indication by mentioning how risks were measured and addressed.]

IMPORTANT: If this backport is for a servicing release, please verify that:

  • For .NET 8 and .NET 9: The PR target branch is release/X.0-staging, not release/X.0.
  • For .NET 10+: The PR target branch is release/X.0 (no -staging suffix).

Package authoring no longer needed in .NET 9

IMPORTANT: Starting with .NET 9, you no longer need to edit a NuGet package's csproj to enable building and bump the version.
Keep in mind that we still need package authoring in .NET 8 and older versions.

)

The switch IL instruction interpreter used > instead of >= when checking
if the switch value exceeds the case count. Per ECMA-335, switch should
fall through to the next instruction when value >= count, but the code
only did this for value > count.

When value exactly equals count, the code tried to read a non-existent
jump table entry, corrupting the IL reader offset and causing an
IndexOutOfRangeException during NativeAOT compilation.

Added test case for the boundary condition (value == case count).
@dotnet-policy-service
Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @agocke, @dotnet/ilc-contrib
See info in area-owners.md if you want to be subscribed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants