From: Richard Henderson <richard.henderson@linaro.org>
To: qemu-devel@nongnu.org
Cc: stefanha@gmail.com
Subject: [PULL v2 08/13] target/openrisc: Use cpu_unwind_state_data for mfspr
Date: Tue, 1 Nov 2022 09:00:19 +1100 [thread overview]
Message-ID: <20221031220020.414768-5-richard.henderson@linaro.org> (raw)
In-Reply-To: <20221031220020.414768-1-richard.henderson@linaro.org>
Since we do not plan to exit, use cpu_unwind_state_data
and extract exactly the data requested.
This is a bug fix, in that we no longer clobber dflag.
Consider:
l.j L2 // branch
l.mfspr r1, ppc // delay
L1: boom
L2: l.lwa r3, (r4)
Here, dflag would be set by cpu_restore_state (because that is the current
state of the cpu), but but not cleared by tb_stop on exiting the TB
(because DisasContext has recorded the current value as zero).
The next TB begins at L2 with dflag incorrectly set. If the load has a
tlb miss, then the exception will be delivered as per a delay slot:
with DSX set in the status register and PC decremented (delay slots
restart by re-executing the branch). This will cause the return from
interrupt to go to L1, and boom!
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
---
target/openrisc/sys_helper.c | 11 +++++++++--
1 file changed, 9 insertions(+), 2 deletions(-)
diff --git a/target/openrisc/sys_helper.c b/target/openrisc/sys_helper.c
index a3508e421d..dde2fa1623 100644
--- a/target/openrisc/sys_helper.c
+++ b/target/openrisc/sys_helper.c
@@ -199,6 +199,7 @@ target_ulong HELPER(mfspr)(CPUOpenRISCState *env, target_ulong rd,
target_ulong spr)
{
#ifndef CONFIG_USER_ONLY
+ uint64_t data[TARGET_INSN_START_WORDS];
MachineState *ms = MACHINE(qdev_get_machine());
OpenRISCCPU *cpu = env_archcpu(env);
CPUState *cs = env_cpu(env);
@@ -232,14 +233,20 @@ target_ulong HELPER(mfspr)(CPUOpenRISCState *env, target_ulong rd,
return env->evbar;
case TO_SPR(0, 16): /* NPC (equals PC) */
- cpu_restore_state(cs, GETPC(), false);
+ if (cpu_unwind_state_data(cs, GETPC(), data)) {
+ return data[0];
+ }
return env->pc;
case TO_SPR(0, 17): /* SR */
return cpu_get_sr(env);
case TO_SPR(0, 18): /* PPC */
- cpu_restore_state(cs, GETPC(), false);
+ if (cpu_unwind_state_data(cs, GETPC(), data)) {
+ if (data[1] & 2) {
+ return data[0] - 4;
+ }
+ }
return env->ppc;
case TO_SPR(0, 32): /* EPCR */
--
2.34.1
next prev parent reply other threads:[~2022-10-31 22:02 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2022-10-31 21:57 [PULL v2 00/13] tcg-next patch queue Richard Henderson
2022-10-31 21:57 ` [PULL v2 01/13] tcg/sparc: Remove support for sparc32plus Richard Henderson
2022-10-31 21:57 ` [PULL v2 02/13] tcg/sparc64: Rename from tcg/sparc Richard Henderson
2022-10-31 21:57 ` [PULL v2 03/13] tcg/sparc64: Remove sparc32plus constraints Richard Henderson
2022-10-31 22:00 ` [PULL v2 04/13] tcg/tci: fix logic error when registering helpers via FFI Richard Henderson
2022-10-31 22:00 ` [PULL v2 05/13] accel/tcg: Introduce cpu_unwind_state_data Richard Henderson
2022-10-31 22:00 ` [PULL v2 06/13] target/i386: Use cpu_unwind_state_data for tpr access Richard Henderson
2022-10-31 22:00 ` [PULL v2 07/13] target/openrisc: Always exit after mtspr npc Richard Henderson
2022-10-31 22:00 ` Richard Henderson [this message]
2022-10-31 22:00 ` [PULL v2 09/13] accel/tcg: Remove will_exit argument from cpu_restore_state Richard Henderson
2022-10-31 22:01 ` [PULL v2 10/13] accel/tcg: Remove reset_icount argument from cpu_restore_state_from_tb Richard Henderson
2022-10-31 22:01 ` [PULL v2 11/13] target/i386: Expand eflags updates inline Richard Henderson
2022-10-31 22:01 ` [PULL v2 12/13] accel/tcg: Complete cpu initialization before registration Richard Henderson
2022-10-31 22:01 ` [PULL v2 13/13] tests/tcg/multiarch: Add munmap-pthread.c Richard Henderson
2022-11-01 15:03 ` [PULL v2 00/13] tcg-next patch queue Stefan Hajnoczi
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20221031220020.414768-5-richard.henderson@linaro.org \
--to=richard.henderson@linaro.org \
--cc=qemu-devel@nongnu.org \
--cc=stefanha@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).