Skip to content

[release/11.0] [interpreter] Resolve open virtual delegates invoked through the shuffle thunk (wasm, Apple mobile) - #134751

Open
lewing wants to merge 1 commit into
release/11.0from
backport/pr-134699-to-release/11.0
Open

lewing wants to merge 1 commit into
release/11.0from
backport/pr-134699-to-release/11.0

Conversation

@lewing

@lewing lewing commented Sep 27, 2026

Copy link
Copy Markdown
Member

Fixes Issue #134261

main PR #134699

Backport of #134699 to release/11.0.

Description

When compiled code (R2R or JIT) invokes an open virtual delegate, it calls the delegate shuffle thunk. On platforms without dynamic code (browser-wasm, iOS, tvOS, maccatalyst), that thunk is an IL stub run by the interpreter. It does calli _methodPtrAux, and for an open virtual delegate that target is CID_VirtualOpenDelegateDispatch. That stub expects the address of _methodPtrAux in a hidden argument that calli cannot express (#134733):

  • On arm64 Apple platforms it reads a garbage delegate and crashes in CID_VirtualOpenDelegateDispatchWorker.
  • On wasm it isn't a portable entry point, so the interpreter traps in PrepareInterpreterCode.

The fix makes the interpreter's INTOP_CALLI recognize CID_VirtualOpenDelegateDispatch and resolve the target from the delegate and the this argument, as INTOP_CALLDELEGATE already does. The resolution is shared through a helper, ResolveOpenVirtualDelegateTarget.

Differences from the main PR (cherry-pick conflicts):

  • src/libraries/tests.proj: not changed. release/11.0 doesn't have the browser ReadyToRun library-test lane, or the System.Linq.Expressions exclusion that main removed.
  • src/coreclr/vm/interpexec.cpp: ResolveOpenVirtualDelegateTarget uses GCX_PREEMP();, matching the existing INTOP_CALLDELEGATE code on this branch, since release/11.0 doesn't have GCX_PREEMP_REGION_BEGIN/END.

Customer Impact

On CoreCLR for iOS, tvOS and maccatalyst, and on browser-wasm with ReadyToRun, invoking an open virtual delegate from compiled code crashes the process. Examples are MethodInfo.CreateDelegate<Func<object, string>>() bound to object.ToString or to an interface method, and LINQ Expressions compiled with the interpreter. On Apple platforms a second fault during crash logging turns the crash into a hang (#134720). There is no workaround in app code other than avoiding open virtual delegates.

Regression

No. This is a bug in configurations newly supported in .NET 11 (CoreCLR on Apple mobile and browser-wasm), not a regression from a shipped release.

Testing

  • New tests in System.Runtime.Tests DelegateTests invoke open virtual delegates: class override, boxed struct, enum and interface dispatch. They crash without the fix on maccatalyst and on browser-wasm ReadyToRun. On main, System.Linq.Expressions.Tests also passes on the browser-wasm ReadyToRun lane with the fix.
  • Validated locally on this branch:
    • maccatalyst-arm64 CoreCLR Release, full System.Runtime.Tests: 78,465 run, 0 failed, including both new tests.
    • browser-wasm CoreCLR Release (Chrome), DelegateTests: 58 run, 0 failed.

Risk

Low.

  • The new INTOP_CALLI branch is only taken when the calli target is exactly CID_VirtualOpenDelegateDispatch. That only happens for open virtual delegates invoked through the IL shuffle thunk, which crashed before.
  • The helper uses the same resolution code that INTOP_CALLDELEGATE already runs.
  • No change to JIT or ReadyToRun code generation, and no change for platforms without FEATURE_CACHED_INTERFACE_DISPATCH.

Note

This PR description was generated with GitHub Copilot.

…fle thunk (wasm, Apple mobile) (#134699)

(cherry picked from commit 01a32f3)
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @JulieLeeMSFT, @BrzVlad, @janvorli
See info in area-owners.md if you want to be subscribed.

@lewing lewing added Servicing-consider Issue for next servicing release review os-ios Apple iOS os-maccatalyst MacCatalyst OS labels Sep 27, 2026
@lewing
lewing deployed to copilot-pat-pool September 27, 2026 19:26 — with GitHub Actions Active
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to 'os-maccatalyst': @vitek-karas, @kotlarmilos, @steveisok, @akoeplinger
See info in area-owners.md if you want to be subscribed.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to 'os-ios': @vitek-karas, @kotlarmilos, @steveisok, @akoeplinger
See info in area-owners.md if you want to be subscribed.

This branch was successfully deployed

1 active deployment
copilot-pat-pool — 28fbc2b0 Deployed Sep 27, 2026 by lewing via conclusion #9222
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area-CodeGen-Interpreter-coreclr os-ios Apple iOS os-maccatalyst MacCatalyst OS Servicing-consider Issue for next servicing release review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants