Skip to content

JIT: True branch not executed #124507

Description

@jakobbotsch
// Generated by Fuzzlyn v3.3 on 2026-02-15 16:12:11
// Run on X86 Windows
// Seed: 345838815179539746-vectort,vector128,vector256,x86aes,x86avx,x86avx2,x86avx512bw,x86avx512bwvl,x86avx512cd,x86avx512cdvl,x86avx512dq,x86avx512dqvl,x86avx512f,x86avx512fvl,x86bmi1,x86bmi2,x86fma,x86lzcnt,x86pclmulqdq,x86popcnt,x86sse,x86sse2,x86sse3,x86sse41,x86sse42,x86ssse3,x86x86base
// Reduced from 51.2 KiB to 0.8 KiB in 00:02:10
// Debug: Outputs 1
// Release: Outputs 0
using System.Runtime.Intrinsics;

public class C0
{
    public sbyte F2;
}

public class Program
{
    public static bool s_2 = true;
    public static C0 s_8 = new C0();
    public static sbyte s_9 = 1;
    public static Vector256<ushort> s_17;
    public static void Main()
    {
        M0();
        System.Console.WriteLine(s_8.F2);
    }

    public static void M0()
    {
        bool var5 = default(bool);
        if (!var5)
        {
            var5 = s_2;
            if (!var5)
            {
                return;
            }
        }

        if (!var5)
        {
            var5 = false;
        }

        s_17 = Vector256.Create<ushort>(1);
        if (var5)
        {
            s_8.F2 = s_9;
        }
    }
}

Bisected to/exposed by #123856, cc @EgorBo

Activity

  1. added
    area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI
    on Feb 17, 2026
  2. dotnet-policy-service commented on Feb 17, 2026

    @dotnet-policy-service
    Contributor

    Tagging subscribers to this area: @JulieLeeMSFT, @jakobbotsch
    See info in area-owners.md if you want to be subscribed.

  3. removed
    untriagedNew issue has not been triaged by the area owner
    on Feb 17, 2026
  4. added this to the 11.0.0 milestone on Feb 17, 2026
  5. self-assigned this
    on Feb 17, 2026
  6. jakobbotsch commented on Mar 2, 2026

    @jakobbotsch
    MemberAuthor

    Probably same issue:

    // Generated by Fuzzlyn v3.3 on 2026-02-28 17:41:56
    // Run on Arm Linux
    // Seed: 4947552585052090314
    // Reduced from 335.1 KiB to 0.5 KiB in 00:04:35
    // Debug: Prints 0 line(s)
    // Release: Prints 1 line(s)
    public class C0
    {
        public ushort F7;
    }
    
    public class Program
    {
        public static void Main()
        {
            C0 vr5 = new C0();
            M9(vr5);
        }
    
        public static void M9(C0 argThis)
        {
            bool var0 = !(1 != argThis.F7);
            bool var15 = var0;
            if (var0)
            {
                var0 = true;
            }
    
            if (!var15)
            {
                if (var0)
                {
                    sbyte vr7 = default(sbyte);
                    System.Console.WriteLine(vr7);
                }
            }
        }
    }

    Copilot says:

      The real issue is that `optGetEdgeAssertions` is returning assertions for an edge that no longer exists—after RBO redirected
      BB01's true target from BB03 to BB04, the function still returns the old assertions instead of recognizing the edge is gone. I
      need to add a check in `optVisitReachingAssertions` to verify that each PHI predecessor block is actually still a predecessor
      before using its assertions.
    
  7. EgorBo commented on Mar 2, 2026

    @EgorBo
    Member

    Yeah I also had a copilot run on this, not sure I agree with its analysis (or at least with whatever I had locally). It does feel like optVisitReachingAssertions is the culprit and my PR that you highlighted just uncover the bug for. But copilot seems to focus on unreachable Phi args as the issue

  8. locked and limited conversation to collaborators on Apr 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area-CodeGen-coreclrCLR JIT compiler in src/coreclr/src/jit and related components such as SuperPMI

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions