From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([208.118.235.92]:56573) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1TB2G3-00045f-2I for qemu-devel@nongnu.org; Mon, 10 Sep 2012 07:34:31 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1TB2Fx-00072C-2t for qemu-devel@nongnu.org; Mon, 10 Sep 2012 07:34:26 -0400 Received: from hall.aurel32.net ([88.191.126.93]:47135) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1TB2Fw-00071b-Sk for qemu-devel@nongnu.org; Mon, 10 Sep 2012 07:34:20 -0400 From: Aurelien Jarno Date: Mon, 10 Sep 2012 13:34:06 +0200 Message-Id: <1347276847-25377-1-git-send-email-aurelien@aurel32.net> Subject: [Qemu-devel] [PATCH 1/2] tcg/optimize: fix end of basic bloc detection List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: qemu-devel@nongnu.org Cc: Blue Swirl , Aurelien Jarno Commit e31b0a7c050711884ad570fe73df806520953618 fixed copy propagation on 32-bit host by restricting the copy between different types. This was the wrong fix. The real problem is that the all temps states should be reset at the end of a basic bloc. This was done by adding such operations in the switch, but brcond2 was forgotten (that's why the crash was only observed on 32-bit hosts). Fix that by looking at the TCG_OPF_BB_END instead. Cc: Blue Swirl Signed-off-by: Aurelien Jarno --- tcg/optimize.c | 23 +++++++++-------------- 1 file changed, 9 insertions(+), 14 deletions(-) diff --git a/tcg/optimize.c b/tcg/optimize.c index 9c65474..64aa35b 100644 --- a/tcg/optimize.c +++ b/tcg/optimize.c @@ -487,22 +487,17 @@ static TCGArg *tcg_constant_folding(TCGContext *s, uint16_t *tcg_opc_ptr, i--; } break; - case INDEX_op_set_label: - case INDEX_op_jmp: - case INDEX_op_br: - CASE_OP_32_64(brcond): - memset(temps, 0, nb_temps * sizeof(struct tcg_temp_info)); - for (i = 0; i < def->nb_args; i++) { - *gen_args = *args; - args++; - gen_args++; - } - break; default: /* Default case: we do know nothing about operation so no - propagation is done. We only trash output args. */ - for (i = 0; i < def->nb_oargs; i++) { - reset_temp(args[i], nb_temps, nb_globals); + propagation is done. We trash everything if the operation + is the end of a basic block, otherwise we only trash the + output args. */ + if (def->flags & TCG_OPF_BB_END) { + memset(temps, 0, nb_temps * sizeof(struct tcg_temp_info)); + } else { + for (i = 0; i < def->nb_oargs; i++) { + reset_temp(args[i], nb_temps, nb_globals); + } } for (i = 0; i < def->nb_args; i++) { gen_args[i] = args[i]; -- 1.7.10.4