qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
* [Qemu-devel] [BUG/PATCH] Fix i386 SSE status flag corruption
@ 2013-09-30 21:20 Richard Purdie
  2013-10-13 15:44 ` Richard Purdie
  0 siblings, 1 reply; 2+ messages in thread
From: Richard Purdie @ 2013-09-30 21:20 UTC (permalink / raw)
  To: qemu-devel

This is a combination of bug report and patch. I'm not sure if you'll want to fix it 
like this but it illustrates the problem and should be easy to fix based on this.

When we restore the mxcsr register with FXRSTOR, we need to update the various SSE
status flags in CPUX86State by calling update_sse_status(). If we don't, we end up 
using the status bits from some other context with interesting results.

I used a function prototype since it makes the fix clear, some code rearrangement
might be needed ultimately.

Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>

Index: qemu-1.5.0/target-i386/fpu_helper.c
===================================================================
--- qemu-1.5.0.orig/target-i386/fpu_helper.c	2013-09-30 18:46:39.283377648 +0000
+++ qemu-1.5.0/target-i386/fpu_helper.c	2013-09-30 18:46:56.895377232 +0000
@@ -1149,6 +1149,8 @@
     }
 }
 
+static void update_sse_status(CPUX86State *env);
+
 void helper_fxrstor(CPUX86State *env, target_ulong ptr, int data64)
 {
     int i, fpus, fptag, nb_xmm_regs;
@@ -1180,6 +1182,7 @@
     if (env->cr[4] & CR4_OSFXSR_MASK) {
         /* XXX: finish it */
         env->mxcsr = cpu_ldl_data(env, ptr + 0x18);
+        update_sse_status(env);
         /* cpu_ldl_data(env, ptr + 0x1c); */
         if (env->hflags & HF_CS64_MASK) {
             nb_xmm_regs = 16;

^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [Qemu-devel] [BUG/PATCH] Fix i386 SSE status flag corruption
  2013-09-30 21:20 [Qemu-devel] [BUG/PATCH] Fix i386 SSE status flag corruption Richard Purdie
@ 2013-10-13 15:44 ` Richard Purdie
  0 siblings, 0 replies; 2+ messages in thread
From: Richard Purdie @ 2013-10-13 15:44 UTC (permalink / raw)
  To: qemu-devel

On Mon, 2013-09-30 at 22:20 +0100, Richard Purdie wrote:
> This is a combination of bug report and patch. I'm not sure if you'll want to fix it 
> like this but it illustrates the problem and should be easy to fix based on this.
> 
> When we restore the mxcsr register with FXRSTOR, we need to update the various SSE
> status flags in CPUX86State by calling update_sse_status(). If we don't, we end up 
> using the status bits from some other context with interesting results.
> 
> I used a function prototype since it makes the fix clear, some code rearrangement
> might be needed ultimately.
> 
> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>

Ping?

This seems to be quite nasty SSE register corruption and it would be
nice to get it fixed. Happy to rework the patch if needed, am just not
sure the best way to handle moving the function if that is what is
needed.

Cheers,

Richard

> Index: qemu-1.5.0/target-i386/fpu_helper.c
> ===================================================================
> --- qemu-1.5.0.orig/target-i386/fpu_helper.c	2013-09-30 18:46:39.283377648 +0000
> +++ qemu-1.5.0/target-i386/fpu_helper.c	2013-09-30 18:46:56.895377232 +0000
> @@ -1149,6 +1149,8 @@
>      }
>  }
>  
> +static void update_sse_status(CPUX86State *env);
> +
>  void helper_fxrstor(CPUX86State *env, target_ulong ptr, int data64)
>  {
>      int i, fpus, fptag, nb_xmm_regs;
> @@ -1180,6 +1182,7 @@
>      if (env->cr[4] & CR4_OSFXSR_MASK) {
>          /* XXX: finish it */
>          env->mxcsr = cpu_ldl_data(env, ptr + 0x18);
> +        update_sse_status(env);
>          /* cpu_ldl_data(env, ptr + 0x1c); */
>          if (env->hflags & HF_CS64_MASK) {
>              nb_xmm_regs = 16;
> 
> 

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2013-10-13 15:45 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2013-09-30 21:20 [Qemu-devel] [BUG/PATCH] Fix i386 SSE status flag corruption Richard Purdie
2013-10-13 15:44 ` Richard Purdie

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).