From: Max Chou <max.chou@sifive.com>
To: qemu-devel@nongnu.org, qemu-riscv@nongnu.org
Cc: Palmer Dabbelt <palmer@dabbelt.com>,
Alistair Francis <Alistair.Francis@wdc.com>,
Daniel Henrique Barboza <daniel.barboza@oss.qualcomm.com>,
Richard Henderson <richard.henderson@linaro.org>,
Max Chou <max.chou@sifive.com>
Subject: [PATCH 0/2] tcg/riscv64: Fix AUIPC pair range validation
Date: Fri, 4 Sep 2026 01:04:03 +0800 [thread overview]
Message-ID: <20260903170405.3632015-1-max.chou@sifive.com> (raw)
This patchset tries to fix the AUIPC-pair range checking issue in
current TCG riscv64 backend.
The issue will be triggered in the following example.
---
Assumptions
- AUIPC at 0x00007fff77fa1258
- target call at 0x00007ffff7fa12d6
The direct pc-relative displacement from the AUIPC at 0x00007fff77fa1258
is 0x000000008000007e, so it is already outside the signed 32-bit range.
tcg_out_call_int therefore takes its far-call path: it separates the JALR
immediate (0x2d6) and asks tcg_out_movi to materialize this page-aligned
base:
target call = 0x00007ffff7fa12d6
JALR lo = 0x2d6
base = 0x00007ffff7fa1000
base - AUIPC = 0x000000007ffffda8
The final value, 0x7ffffda8, is less than INT32_MAX. The current range
therefore accepts it, but that is not sufficient: the signed low 12-bit
immediate must be removed before the value can be encoded in AUIPC.
The current reloc_call performs that split as follows:
int32_t lo = sextreg(offset, 0, 12);
int32_t hi = offset - lo;
For the captured placement, the values required by the split are:
offset = 0x000000007ffffda8
lo = 0xfffffffffffffda8
hi = 0x0000000080000000
The lo is representable by the ADDI immediate. But the hi is not
representable by int32_t: narrowing it produces the bit pattern
0x80000000, which is -0x80000000 as a signed 32-bit value.
Thus the int32_t split can accept a wrapped upper value instead of
proving that the positive upper contribution required by AUIPC is
representable.
AUIPC has a 20-bit immediate which it shifts left by 12 and sign-extends.
Consequently, an encoded immediate of 0x80000 means -0x80000000, not the
required +0x80000000. The resulting generated code will be:
0x00007fff77fa1258: auipc t6,-524288
0x00007fff77fa125c: addi t6,t6,-600
0x00007fff77fa1260: jalr ra,t6,726
It computes the base as 0x00007ffef7fa1000 and transfers to
0x00007ffef7fa12d6, exactly 4 GiB below the requested callback which is
0x00007ffff7fa12d6.
---
This patchset addresses the issue of AUIPC split checking and applies
the corrected split. It ensures that the split is checked before
emitting AUIPC/ADDI and AUIPC/JALR pairs in tcg_out_[movi|call_int].
rnax
Max Chou (2):
tcg/riscv64: Validate AUIPC relocation range
tcg/riscv64: Fall back when AUIPC pairs are out of range
tcg/riscv64/tcg-target.c.inc | 68 ++++++++++++++++++++++++++----------
1 file changed, 49 insertions(+), 19 deletions(-)
--
2.43.7
next reply other threads:[~2026-09-03 17:04 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-03 17:04 Max Chou [this message]
2026-09-03 17:04 ` [PATCH 1/2] tcg/riscv64: Validate AUIPC relocation range Max Chou
2026-09-03 17:31 ` Philippe Mathieu-Daudé
2026-09-04 7:56 ` Max Chou
2026-09-03 17:04 ` [PATCH 2/2] tcg/riscv64: Fall back when AUIPC pairs are out of range Max Chou
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260903170405.3632015-1-max.chou@sifive.com \
--to=max.chou@sifive.com \
--cc=Alistair.Francis@wdc.com \
--cc=daniel.barboza@oss.qualcomm.com \
--cc=palmer@dabbelt.com \
--cc=qemu-devel@nongnu.org \
--cc=qemu-riscv@nongnu.org \
--cc=richard.henderson@linaro.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.