Runtime: How the NullReferenceException is thrown by coreclr?

Created on 20 May 2017  路  2Comments  路  Source: dotnet/runtime

Hello, I'm trying to understand how NullReferenceException is thrown.

First I looked at the generated assembly code,
most time it use instruction like cmp [reg], reg to make the hardware throw an exception when instance is null.

Then it catch the SIGSEGV signal by sigsegv_handler on linux, and then passdown like

sigsegv_handler (pal\src\exception\signal.cpp)
  common_signal_handler (pal\src\exception\signal.cpp)
    SEHProcessException (pal\src\exception\seh.cpp)
      HandleHardwareException (vm\exceptionhandling.cpp)
        DispatchManagedException (vm\exceptionhandling.cpp)
          UnwindManagedExceptionPass1 (vm\exceptionhandling.cpp)
            UnwindManagedExceptionPass2 (vm\exceptionhandling.cpp)
              ProcessCLRException (vm\exceptionhandling.cpp)
                ExceptionTracker::CallCatchHandler (vm\exceptionhandling.cpp)
                  FinishSecondPass (vm\exceptionhandling.cpp)
                ExceptionTracker::ResumeExecution (vm\exceptionhandling.cpp)
                  RtlRestoreContext (pal\src\arch\i386\context2.S)

This is what I know so far.

But I don't know:

(1) RtlRestoreContext will reset the PC, where is the PC at?

It goes to some place contains these instructions, I can't figure out where these code from

momvabsq $0x7fff7cf5b7d1. %rcx
movzbl (%rcx), %ecx
test %ecx, %ecx
je 0x7fff7cf04969
leaq -0x20(%ecx), %rcx

(2) How EXCEPTION_ACCESS_VIOLATION(STATUS_ACCESS_VIOLATION) become NullReferenceException?

I think in the code some where will convert STATUS_ACCESS_VIOLATION to NullReferenceException,
but I can't found it after I search all code under src directory.

I also inspected CLRException::GetThrowableFromException, but looks like it's not I want.

(3) How is the hardware exception caught on windows?

On windows the same instruction is generated for checking null, (eg cmp, or mov),
Is there an equivalent function of handle_signal(SIGSEGV on windows?
After some search on bing I only found descriptions about __try and __catch.

I also read the document about exception,
but it doesn't contain the information I want.

And lldb support of debugging exceptions is poor, it always stuck after RtlRestoreContext so I can't dig depper.

Please answer my questions above when you have some time, Thank you!

area-ExceptionHandling-coreclr question

Most helpful comment

@303248153 here are answers to your questions:

  1. The PC is set to the place where the code execution continues after the catch handler is done.
  2. The conversion happens in MapWin32FaultToCOMPlusException in excep.cpp
  3. On Windows, the vectored exception handler CLRVectoredExceptionHandlerShim is called by the OS to process hardware exceptions.

All 2 comments

@303248153 here are answers to your questions:

  1. The PC is set to the place where the code execution continues after the catch handler is done.
  2. The conversion happens in MapWin32FaultToCOMPlusException in excep.cpp
  3. On Windows, the vectored exception handler CLRVectoredExceptionHandlerShim is called by the OS to process hardware exceptions.

Ok, thanks for your accurate answer!

Was this page helpful?
0 / 5 - 0 ratings

Related issues

nalywa picture nalywa  路  3Comments

yahorsi picture yahorsi  路  3Comments

jzabroski picture jzabroski  路  3Comments

GitAntoinee picture GitAntoinee  路  3Comments

jchannon picture jchannon  路  3Comments