From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mailman by lists.gnu.org with tmda-scanned (Exim 4.43) id 1KFq8e-0004Qz-Vl for qemu-devel@nongnu.org; Mon, 07 Jul 2008 08:48:16 -0400 Received: from exim by lists.gnu.org with spam-scanned (Exim 4.43) id 1KFq8d-0004Q9-67 for qemu-devel@nongnu.org; Mon, 07 Jul 2008 08:48:16 -0400 Received: from [199.232.76.173] (port=39030 helo=monty-python.gnu.org) by lists.gnu.org with esmtp (Exim 4.43) id 1KFq8d-0004Q5-0x for qemu-devel@nongnu.org; Mon, 07 Jul 2008 08:48:15 -0400 Received: from gecko.sbs.de ([194.138.37.40]:19656) by monty-python.gnu.org with esmtps (TLS-1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.60) (envelope-from ) id 1KFq8b-0002sg-Qr for qemu-devel@nongnu.org; Mon, 07 Jul 2008 08:48:14 -0400 Received: from mail1.sbs.de (localhost [127.0.0.1]) by gecko.sbs.de (8.12.11.20060308/8.12.11) with ESMTP id m67Cm9oE022895 for ; Mon, 7 Jul 2008 14:48:09 +0200 Received: from [139.25.109.167] (mchn012c.ww002.siemens.net [139.25.109.167] (may be forged)) by mail1.sbs.de (8.12.11.20060308/8.12.11) with ESMTP id m67Cm9Da011733 for ; Mon, 7 Jul 2008 14:48:09 +0200 Message-ID: <48721086.2010506@siemens.com> Date: Mon, 07 Jul 2008 14:48:06 +0200 From: Jan Kiszka MIME-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-15 Content-Transfer-Encoding: 7bit Subject: [Qemu-devel] [PATCH] x86-64: Fix 64-bit lgs/lfs/lss Reply-To: qemu-devel@nongnu.org List-Id: qemu-devel.nongnu.org List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: qemu-devel@nongnu.org Reading the code while porting my segment limit and type checks to latest SVN made me stumble over this bug in the translator: 64-bit lgs/lfs/lss was incorrectly reading only 32-bit offsets. Signed-off-by: Jan Kiszka --- target-i386/translate.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) Index: b/target-i386/translate.c =================================================================== --- a/target-i386/translate.c +++ b/target-i386/translate.c @@ -4864,7 +4864,7 @@ static target_ulong disas_insn(DisasCont case 0x1b5: /* lgs Gv */ op = R_GS; do_lxx: - ot = dflag ? OT_LONG : OT_WORD; + ot = dflag + OT_WORD; modrm = ldub_code(s->pc++); reg = ((modrm >> 3) & 7) | rex_r; mod = (modrm >> 6) & 3; @@ -4872,7 +4872,7 @@ static target_ulong disas_insn(DisasCont goto illegal_op; gen_lea_modrm(s, modrm, ®_addr, &offset_addr); gen_op_ld_T1_A0(ot + s->mem_index); - gen_add_A0_im(s, 1 << (ot - OT_WORD + 1)); + gen_add_A0_im(s, 1 << ot); /* load the segment first to handle exceptions properly */ gen_op_ldu_T0_A0(OT_WORD + s->mem_index); gen_movl_seg_T0(s, op, pc_start - s->cs_base);