Resolve small type tags when looking up referenced objects - #961
Merged
Merged
Conversation
Julia 1.10+ refers to some types by a small tag instead of their address: an offset into `jl_small_typeof`, below `jl_max_tags << 4`. Codegen emits such a tag as the type operand of `julia.gc_alloc_obj`, e.g., since 1.12 when allocating a `Core.svec` inline, where `check_allocation!` passed it to `referenced_object`. That treated every `inttoptr` constant as an object address and dereferenced the tag, crashing the compiler. Look small tags up in `jl_small_typeof` instead, as `jl_to_typeof` does, and treat unused table entries and non-constant operands as unknown. Larger constants are still object addresses, as embedded by 1.10's codegen or by baking relocations. Such allocations of a `SimpleVector` are now reported as allocations of an object with references.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## tb/reject-reference-allocations #961 +/- ##
===================================================================
+ Coverage 86.39% 86.56% +0.17%
===================================================================
Files 29 29
Lines 5805 5813 +8
===================================================================
+ Hits 5015 5032 +17
+ Misses 790 781 -9 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
maleadt
merged commit Sep 28, 2026
634b0b2
into
tb/reject-reference-allocations
32 of 33 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes the crash reported on #949; meant to be folded into that PR.
Since Julia 1.10, codegen refers to some types by a small tag rather than their address: an offset into
jl_small_typeof, belowjl_max_tags << 4. On 1.12+,Core.svecis allocated inline with such a tag as the type operand:check_allocation!passes that operand toreferenced_object, which treated everyinttoptrconstant as an object address, so compiling a kernel like this segfaulted:referenced_objectnow looks up constants belowjl_max_tags << 4injl_small_typeof, asjl_to_typeofdoes. Unused table entries and non-constantinttoptroperands are treated as unknown. Larger constants are still treated as object addresses, as before: 1.10's codegen and:bakerelocations embed them. The svec allocation above is now reported asunsupported allocation of an object with references (Core.SimpleVector).Tests: the Metal
unsupported allocationstestset has a kernel that allocates an svec, checked on 1.12+ because older versions calljl_f_svecinstead. It also callsreferenced_objectdirectly, on every version, for a small tag, an unused tag and a type address. Without the fix, the test worker segfaults. I ran the Metal tests on 1.10 through 1.13, the SPIR-V tests on the same versions, and the full suite on 1.10 and 1.12. PTX and GCN tests were skipped because those back-ends aren't available on macOS. With Metal.jl 1.11.1, the reproducer above no longer crashes, and launching the kernel with@metalraises theInvalidIRError.