All of lore.kernel.org
 help / color / mirror / Atom feed
From: Brian Cain <brian.cain@oss.qualcomm.com>
To: qemu-devel@nongnu.org, richard.henderson@linaro.org,
	peter.maydell@linaro.org
Cc: brian.cain@oss.qualcomm.com,
	Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Subject: [PULL 2/9] target/hexagon: read BADVA as an alias of BADVA0/1
Date: Sat,  5 Sep 2026 13:05:43 -0700	[thread overview]
Message-ID: <20260905200550.2009799-3-brian.cain@oss.qualcomm.com> (raw)
In-Reply-To: <20260905200550.2009799-1-brian.cain@oss.qualcomm.com>

BADVA is sort of a virtual register: it reads back as either BADVA0
or BADVA1, selected by SSR[BVS].  sreg_read() instead returned the
separate copy that set_badva_regs() stores in t_sreg[HEX_SREG_BADVA].

Guest code that writes BADVA0/BADVA1 directly was reading back a stale BADVA.

Uncovered by the h2 hypervisor kernel/mem/tlbmiss test.

Reviewed-by: Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
---
 target/hexagon/op_helper.c | 7 +++++++
 1 file changed, 7 insertions(+)

diff --git a/target/hexagon/op_helper.c b/target/hexagon/op_helper.c
index 71555a7ba36..5d64c5523bb 100644
--- a/target/hexagon/op_helper.c
+++ b/target/hexagon/op_helper.c
@@ -1889,6 +1889,13 @@ static inline QEMU_ALWAYS_INLINE uint32_t sreg_read(CPUHexagonState *env,
     HexagonCPU *cpu;
 
     g_assert(bql_locked());
+    if (reg == HEX_SREG_BADVA) {
+        uint32_t ssr = env->t_sreg[HEX_SREG_SSR];
+        if (GET_SSR_FIELD(SSR_BVS, ssr)) {
+            return env->t_sreg[HEX_SREG_BADVA1];
+        }
+        return env->t_sreg[HEX_SREG_BADVA0];
+    }
     if (reg < HEX_SREG_GLB_START) {
         return env->t_sreg[reg];
     }
-- 
2.34.1


  parent reply	other threads:[~2026-09-05 20:06 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-05 20:05 [PULL 0/9] hex queue Brian Cain
2026-09-05 20:05 ` [PULL 1/9] hw/hexagon: register the V68N_1024 machine Brian Cain
2026-09-05 20:05 ` Brian Cain [this message]
2026-09-05 20:05 ` [PULL 3/9] target/hexagon: kick vCPU when re-asserting interrupts Brian Cain
2026-09-05 20:05 ` [PULL 4/9] hw/intc: name the L2VIC edge trigger check Brian Cain
2026-09-05 20:05 ` [PULL 5/9] target/hexagon: assert guest register pair alignment Brian Cain
2026-09-05 20:05 ` [PULL 6/9] hexagon: raise imprecise exception for multi-TLB matches Brian Cain
2026-09-05 20:05 ` [PULL 7/9] tests/functional/hexagon: add tests, update to v0.2.14 Brian Cain
2026-09-05 20:05 ` [PULL 8/9] tests/functional/hexagon: update arch tests " Brian Cain
2026-09-05 20:05 ` [PULL 9/9] target/hexagon: decode the DMA insts as unimp Brian Cain
2026-09-07 12:32 ` [PULL 0/9] hex queue Peter Maydell

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260905200550.2009799-3-brian.cain@oss.qualcomm.com \
    --to=brian.cain@oss.qualcomm.com \
    --cc=peter.maydell@linaro.org \
    --cc=pierrick.bouvier@oss.qualcomm.com \
    --cc=qemu-devel@nongnu.org \
    --cc=richard.henderson@linaro.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.