From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mailman by lists.gnu.org with tmda-scanned (Exim 4.43) id 1JrxOJ-0002aR-9J for qemu-devel@nongnu.org; Fri, 02 May 2008 11:41:43 -0400 Received: from exim by lists.gnu.org with spam-scanned (Exim 4.43) id 1JrxOG-0002U8-2N for qemu-devel@nongnu.org; Fri, 02 May 2008 11:41:42 -0400 Received: from [199.232.76.173] (port=36854 helo=monty-python.gnu.org) by lists.gnu.org with esmtp (Exim 4.43) id 1JrxOF-0002Tz-Te for qemu-devel@nongnu.org; Fri, 02 May 2008 11:41:39 -0400 Received: from os.inf.tu-dresden.de ([141.76.48.99]) by monty-python.gnu.org with esmtps (TLS-1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.60) (envelope-from ) id 1JrxOF-0004kV-KY for qemu-devel@nongnu.org; Fri, 02 May 2008 11:41:40 -0400 Received: from erwin.inf.tu-dresden.de ([141.76.48.80] helo=os.inf.tu-dresden.de) by os.inf.tu-dresden.de with esmtps (TLSv1:AES128-SHA:128) (Exim 4.69) id 1JrxOC-0005HD-Gk for qemu-devel@nongnu.org; Fri, 02 May 2008 17:41:36 +0200 Date: Fri, 2 May 2008 17:41:34 +0200 From: Adam Lackorzynski Subject: Re: [Qemu-devel] Crash due to invalid env->current_tb Message-ID: <20080502154134.GA7060@os.inf.tu-dresden.de> References: <20080429115614.GA15524@os.inf.tu-dresden.de> <20080429184011.GK17356@os.inf.tu-dresden.de> <20080430151132.GB6712@os.inf.tu-dresden.de> <20080430152102.GC6712@os.inf.tu-dresden.de> <67C63B39-3EBE-4E1F-B46B-D2FE7AAC001F@suse.de> <20080501120241.GC13241@os.inf.tu-dresden.de> MIME-Version: 1.0 Content-Type: text/plain; charset=iso-8859-1 Content-Disposition: inline In-Reply-To: Reply-To: qemu-devel@nongnu.org List-Id: qemu-devel.nongnu.org List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: qemu-devel@nongnu.org On Thu May 01, 2008 at 18:02:46 +0300, Blue Swirl wrote: > On 5/1/08, Adam Lackorzynski wrote: > > For 64bit target T0 is 64bits so "=a" does not work and "=A" is needed. > > The strange thing is that I need to throw away the upper 32bits because > > otherwise it won't work. gen_func is defined to return just long but T0 > > is unsigned long long, this seems inconsistent. The 'and' does not > > appear in 32bit targets so it does not harm there. > > This is because in this special case, T0 is not used as target CPU > temporary, but instead to return next TB address. On i386 this is 32 > bits, so only EAX is needed. TCG does not touch EDX, so it contains > garbage. This also means that moving EDX to high word of T0 and then > throwing the high word away may be slightly wasteful. So I played a bit more with this by trying out the 'and' and the tmp variable approaches. With the tmp variables the generated code looks ok whereas with the 'and' approach it looks especially scary with gcc-4.3 (gcc-3.4 looks ok). I have two versions now, one condensed and ugly and then one with separate parts for 32 and 64 targets. I think this one should be prefered. Index: cpu-exec.c =================================================================== --- cpu-exec.c (revision 4291) +++ cpu-exec.c (working copy) @@ -690,7 +691,25 @@ fp.ip = tc_ptr; fp.gp = code_gen_buffer + 2 * (1 << 20); (*(void (*)(void)) &fp)(); +#elif defined(__i386) +#if (TARGET_LONG_BITS == 32) + asm volatile ("push %%ebp\n" + "call *%1\n" + "pop %%ebp\n" + : "=a" (T0) + : "a" (gen_func) + : "ecx", "esi", "edi", "edx", "cc"); #else + unsigned long tmp; + asm volatile ("push %%ebp\n" + "call *%1\n" + "pop %%ebp\n" + : "=a" (tmp) + : "a" (gen_func) + : "ebx", "ecx", "esi", "edi", "edx", "cc"); + T0 = tmp; +#endif +#else T0 = gen_func(); #endif env->current_tb = NULL; Index: cpu-exec.c =================================================================== --- cpu-exec.c (revision 4291) +++ cpu-exec.c (working copy) @@ -690,7 +691,31 @@ fp.ip = tc_ptr; fp.gp = code_gen_buffer + 2 * (1 << 20); (*(void (*)(void)) &fp)(); +#elif defined(__i386) +#if (TARGET_LONG_BITS == 32) +#define CLOBBER +#define OUTPUT T0 +#define OP +#define OUTPUT2 #else +#define CLOBBER ,"ebx" +#define OUTPUT *((unsigned long *)&T0) +#define OUTPUT2 , [upperT0] "=m" (*((unsigned long *)&T0 + 1)) +#define OP "movl $0, %[upperT0]\n" +#endif + asm volatile ("push %%ebp\n" + "call *%[func]\n" + "pop %%ebp\n" + OP + : "=a" (OUTPUT) OUTPUT2 + : [func] "a" (gen_func) + : "ecx", "esi", "edi", "edx", "cc" CLOBBER + ); +#undef CLOBBER +#undef OUTPUT +#undef OUTPUT2 +#undef OP +#else T0 = gen_func(); #endif env->current_tb = NULL; Adam -- Adam adam@os.inf.tu-dresden.de Lackorzynski http://os.inf.tu-dresden.de/~adam/