All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH 0/2] target/i386: Fix FPU tag word for FSTP/FXCH
@ 2026-09-02 12:04 Simon Scherer
  2026-09-02 12:04 ` [PATCH 1/2] target/i386: Update FPU tag word for FSTP Simon Scherer
  2026-09-02 12:04 ` [PATCH 2/2] target/i386: Update FPU tag word for FXCH Simon Scherer
  0 siblings, 2 replies; 3+ messages in thread
From: Simon Scherer @ 2026-09-02 12:04 UTC (permalink / raw)
  To: qemu-devel; +Cc: pbonzini, richard.henderson, Simon Scherer

Following up on a similar tag word bug in FXTRACT
(https://patchew.org/QEMU/20260901085839.138094-1-scherer.simon89@gmail.com/)
two more instructions sharing the same bug of not updating
the tag word turned up:

Patch 1 fixes FSTP ST(i)
Patch 2 fixes FXCH ST(i)

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4400

Simon Scherer (2):
  target/i386: Update FPU tag word for FSTP
  target/i386: Update FPU tag word for FXCH

 target/i386/tcg/fpu_helper.c | 3 +++
 1 file changed, 3 insertions(+)

-- 
2.53.0



^ permalink raw reply	[flat|nested] 3+ messages in thread

* [PATCH 1/2] target/i386: Update FPU tag word for FSTP
  2026-09-02 12:04 [PATCH 0/2] target/i386: Fix FPU tag word for FSTP/FXCH Simon Scherer
@ 2026-09-02 12:04 ` Simon Scherer
  2026-09-02 12:04 ` [PATCH 2/2] target/i386: Update FPU tag word for FXCH Simon Scherer
  1 sibling, 0 replies; 3+ messages in thread
From: Simon Scherer @ 2026-09-02 12:04 UTC (permalink / raw)
  To: qemu-devel; +Cc: pbonzini, richard.henderson, Simon Scherer

FSTP ST(i) copies the value in ST(0) into ST(i) and then pops the
register stack. ST(i) should end up marked valid in the FPU tag word
and the old ST(0) should end up marked empty.

helper_fmov_STN_ST0() copies the value into ST(i) but never touches
its tag. So if ST(i) happened to be tagged empty beforehand, it is
still wrongly tagged empty afterwards.

Mark the destination tag to valid in helper_fmov_STN_ST0().
This also fixes FST ST(i), which shares the same helper.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4400
Signed-off-by: Simon Scherer <scherer.simon89@gmail.com>
---
 target/i386/tcg/fpu_helper.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/target/i386/tcg/fpu_helper.c b/target/i386/tcg/fpu_helper.c
index b812125efa..6ccc3c3b4e 100644
--- a/target/i386/tcg/fpu_helper.c
+++ b/target/i386/tcg/fpu_helper.c
@@ -510,6 +510,7 @@ void helper_fmov_ST0_STN(CPUX86State *env, int st_index)
 void helper_fmov_STN_ST0(CPUX86State *env, int st_index)
 {
     ST(st_index) = ST0;
+    env->fptags[(env->fpstt + st_index) & 7] = 0;
 }
 
 void helper_fxchg_ST0_STN(CPUX86State *env, int st_index)
-- 
2.53.0



^ permalink raw reply related	[flat|nested] 3+ messages in thread

* [PATCH 2/2] target/i386: Update FPU tag word for FXCH
  2026-09-02 12:04 [PATCH 0/2] target/i386: Fix FPU tag word for FSTP/FXCH Simon Scherer
  2026-09-02 12:04 ` [PATCH 1/2] target/i386: Update FPU tag word for FSTP Simon Scherer
@ 2026-09-02 12:04 ` Simon Scherer
  1 sibling, 0 replies; 3+ messages in thread
From: Simon Scherer @ 2026-09-02 12:04 UTC (permalink / raw)
  To: qemu-devel; +Cc: pbonzini, richard.henderson, Simon Scherer

FXCH ST(i) exchanges the contents of ST(0) and ST(i). Both registers
receive a new value, so both should end up marked valid in the FPU tag
word, regardless of what they were tagged before the swap.

helper_fxchg_ST0_STN() swaps the two values but never touches either
register's tag. So if either register happened to be tagged empty
beforehand, it is still wrongly tagged empty afterwards.

Mark both ST0 and ST(st_index) valid after the swap.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4400
Signed-off-by: Simon Scherer <scherer.simon89@gmail.com>
---
 target/i386/tcg/fpu_helper.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/target/i386/tcg/fpu_helper.c b/target/i386/tcg/fpu_helper.c
index 6ccc3c3b4e..9df9f2f375 100644
--- a/target/i386/tcg/fpu_helper.c
+++ b/target/i386/tcg/fpu_helper.c
@@ -520,6 +520,8 @@ void helper_fxchg_ST0_STN(CPUX86State *env, int st_index)
     tmp = ST(st_index);
     ST(st_index) = ST0;
     ST0 = tmp;
+    env->fptags[env->fpstt] = 0;
+    env->fptags[(env->fpstt + st_index) & 7] = 0;
 }
 
 /* FPU operations */
-- 
2.53.0



^ permalink raw reply related	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-09-02 12:05 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-02 12:04 [PATCH 0/2] target/i386: Fix FPU tag word for FSTP/FXCH Simon Scherer
2026-09-02 12:04 ` [PATCH 1/2] target/i386: Update FPU tag word for FSTP Simon Scherer
2026-09-02 12:04 ` [PATCH 2/2] target/i386: Update FPU tag word for FXCH Simon Scherer

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.