qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
From: Christoph Egger <Christoph.Egger@amd.com>
To: "qemu-devel@nongnu.org" <qemu-devel@nongnu.org>
Subject: [Qemu-devel] [PATCH] target-i386: fix cmpxchg
Date: Fri, 17 Jun 2011 11:38:57 +0200	[thread overview]
Message-ID: <4DFB20B1.8070409@amd.com> (raw)

Correct emulation of i386 cmpxchg instruction in the case where the
comparison outcome is unequal and the memory write causes a page
fault.

From: Andreas Gustafsson <gson@netbsd.org>
Signed-off-by: Christoph Egger <Christoph.Egger@amd.com>

diff --git a/target-i386/translate.c b/target-i386/translate.c
index 10bd72a..69a878f 100644
--- a/target-i386/translate.c
+++ b/target-i386/translate.c
@@ -4857,20 +4857,23 @@ static target_ulong disas_insn(DisasContext *s, 
target_ulong pc_start)
              tcg_gen_sub_tl(t2, cpu_regs[R_EAX], t0);
              gen_extu(ot, t2);
              tcg_gen_brcondi_tl(TCG_COND_EQ, t2, 0, label1);
+            label2 = gen_new_label();
              if (mod == 3) {
-                label2 = gen_new_label();
                  gen_op_mov_reg_v(ot, R_EAX, t0);
                  tcg_gen_br(label2);
                  gen_set_label(label1);
                  gen_op_mov_reg_v(ot, rm, t1);
-                gen_set_label(label2);
              } else {
-                tcg_gen_mov_tl(t1, t0);
+                /* perform no-op store cycle like physical cpu; must be
+                 * before changing accumulator to ensure idempotency if
+                 * the store faults and the instruction is restarted */
+                gen_op_st_v(ot + s->mem_index, t0, a0);
                  gen_op_mov_reg_v(ot, R_EAX, t0);
+                tcg_gen_br(label2);
                  gen_set_label(label1);
-                /* always store */
                  gen_op_st_v(ot + s->mem_index, t1, a0);
              }
+            gen_set_label(label2);
              tcg_gen_mov_tl(cpu_cc_src, t0);
              tcg_gen_mov_tl(cpu_cc_dst, t2);
              s->cc_op = CC_OP_SUBB + ot;



-- 
---to satisfy European Law for business letters:
Advanced Micro Devices GmbH
Einsteinring 24, 85689 Dornach b. Muenchen
Geschaeftsfuehrer: Alberto Bozzo, Andrew Bowd
Sitz: Dornach, Gemeinde Aschheim, Landkreis Muenchen
Registergericht Muenchen, HRB Nr. 43632

             reply	other threads:[~2011-06-17 13:57 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2011-06-17  9:38 Christoph Egger [this message]
2011-06-17 14:40 ` [Qemu-devel] [PATCH] target-i386: fix cmpxchg malc

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4DFB20B1.8070409@amd.com \
    --to=christoph.egger@amd.com \
    --cc=qemu-devel@nongnu.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).