* [PATCH 0/2] target/i386: Fix FPU tag word for FSTP/FXCH
@ 2026-09-02 12:04 Simon Scherer
2026-09-02 12:04 ` [PATCH 1/2] target/i386: Update FPU tag word for FSTP Simon Scherer
2026-09-02 12:04 ` [PATCH 2/2] target/i386: Update FPU tag word for FXCH Simon Scherer
0 siblings, 2 replies; 3+ messages in thread
From: Simon Scherer @ 2026-09-02 12:04 UTC (permalink / raw)
To: qemu-devel; +Cc: pbonzini, richard.henderson, Simon Scherer
Following up on a similar tag word bug in FXTRACT
(https://patchew.org/QEMU/20260901085839.138094-1-scherer.simon89@gmail.com/)
two more instructions sharing the same bug of not updating
the tag word turned up:
Patch 1 fixes FSTP ST(i)
Patch 2 fixes FXCH ST(i)
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4400
Simon Scherer (2):
target/i386: Update FPU tag word for FSTP
target/i386: Update FPU tag word for FXCH
target/i386/tcg/fpu_helper.c | 3 +++
1 file changed, 3 insertions(+)
--
2.53.0
^ permalink raw reply [flat|nested] 3+ messages in thread
* [PATCH 1/2] target/i386: Update FPU tag word for FSTP
2026-09-02 12:04 [PATCH 0/2] target/i386: Fix FPU tag word for FSTP/FXCH Simon Scherer
@ 2026-09-02 12:04 ` Simon Scherer
2026-09-02 12:04 ` [PATCH 2/2] target/i386: Update FPU tag word for FXCH Simon Scherer
1 sibling, 0 replies; 3+ messages in thread
From: Simon Scherer @ 2026-09-02 12:04 UTC (permalink / raw)
To: qemu-devel; +Cc: pbonzini, richard.henderson, Simon Scherer
FSTP ST(i) copies the value in ST(0) into ST(i) and then pops the
register stack. ST(i) should end up marked valid in the FPU tag word
and the old ST(0) should end up marked empty.
helper_fmov_STN_ST0() copies the value into ST(i) but never touches
its tag. So if ST(i) happened to be tagged empty beforehand, it is
still wrongly tagged empty afterwards.
Mark the destination tag to valid in helper_fmov_STN_ST0().
This also fixes FST ST(i), which shares the same helper.
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4400
Signed-off-by: Simon Scherer <scherer.simon89@gmail.com>
---
target/i386/tcg/fpu_helper.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/target/i386/tcg/fpu_helper.c b/target/i386/tcg/fpu_helper.c
index b812125efa..6ccc3c3b4e 100644
--- a/target/i386/tcg/fpu_helper.c
+++ b/target/i386/tcg/fpu_helper.c
@@ -510,6 +510,7 @@ void helper_fmov_ST0_STN(CPUX86State *env, int st_index)
void helper_fmov_STN_ST0(CPUX86State *env, int st_index)
{
ST(st_index) = ST0;
+ env->fptags[(env->fpstt + st_index) & 7] = 0;
}
void helper_fxchg_ST0_STN(CPUX86State *env, int st_index)
--
2.53.0
^ permalink raw reply related [flat|nested] 3+ messages in thread* [PATCH 2/2] target/i386: Update FPU tag word for FXCH
2026-09-02 12:04 [PATCH 0/2] target/i386: Fix FPU tag word for FSTP/FXCH Simon Scherer
2026-09-02 12:04 ` [PATCH 1/2] target/i386: Update FPU tag word for FSTP Simon Scherer
@ 2026-09-02 12:04 ` Simon Scherer
1 sibling, 0 replies; 3+ messages in thread
From: Simon Scherer @ 2026-09-02 12:04 UTC (permalink / raw)
To: qemu-devel; +Cc: pbonzini, richard.henderson, Simon Scherer
FXCH ST(i) exchanges the contents of ST(0) and ST(i). Both registers
receive a new value, so both should end up marked valid in the FPU tag
word, regardless of what they were tagged before the swap.
helper_fxchg_ST0_STN() swaps the two values but never touches either
register's tag. So if either register happened to be tagged empty
beforehand, it is still wrongly tagged empty afterwards.
Mark both ST0 and ST(st_index) valid after the swap.
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4400
Signed-off-by: Simon Scherer <scherer.simon89@gmail.com>
---
target/i386/tcg/fpu_helper.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/target/i386/tcg/fpu_helper.c b/target/i386/tcg/fpu_helper.c
index 6ccc3c3b4e..9df9f2f375 100644
--- a/target/i386/tcg/fpu_helper.c
+++ b/target/i386/tcg/fpu_helper.c
@@ -520,6 +520,8 @@ void helper_fxchg_ST0_STN(CPUX86State *env, int st_index)
tmp = ST(st_index);
ST(st_index) = ST0;
ST0 = tmp;
+ env->fptags[env->fpstt] = 0;
+ env->fptags[(env->fpstt + st_index) & 7] = 0;
}
/* FPU operations */
--
2.53.0
^ permalink raw reply related [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-09-02 12:05 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-02 12:04 [PATCH 0/2] target/i386: Fix FPU tag word for FSTP/FXCH Simon Scherer
2026-09-02 12:04 ` [PATCH 1/2] target/i386: Update FPU tag word for FSTP Simon Scherer
2026-09-02 12:04 ` [PATCH 2/2] target/i386: Update FPU tag word for FXCH Simon Scherer
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.