From: Pierrick Bouvier <pierrick.bouvier@linaro.org>
To: Julian Ganz <neither@nut.email>, qemu-devel@nongnu.org
Cc: "Alex Bennée" <alex.bennee@linaro.org>,
"Alexandre Iooss" <erdnaxe@crans.org>,
"Mahmoud Mandour" <ma.mandourr@gmail.com>
Subject: Re: [PATCH v4 21/23] tests: add plugin asserting correctness of discon event's to_pc
Date: Mon, 12 May 2025 17:25:24 -0700 [thread overview]
Message-ID: <53632928-0367-44cf-a93e-6ba14bb85458@linaro.org> (raw)
In-Reply-To: <e212e53b98c264366458654493e2fa2e2cdecdcc.1746968215.git.neither@nut.email>
On 5/11/25 6:14 AM, Julian Ganz wrote:
> We recently introduced plugin API for the registration of callbacks for
> discontinuity events, specifically for interrupts, exceptions and host
> call events. The callback receives various bits of information,
> including the VCPU index and PCs.
>
> This change introduces a test plugin asserting the correctness of that
> behaviour in cases where this is possible with reasonable effort. Since
> instruction PCs are recorded at translation blocks translation time and
> a TB may be used in multiple processes running in distinct virtual
> memory, the plugin allows comparing not full addresses but a subset of
> address bits via the `compare-addr-bits` option.
>
> Signed-off-by: Julian Ganz <neither@nut.email>
> ---
> tests/tcg/plugins/discons.c | 219 ++++++++++++++++++++++++++++++++++
> tests/tcg/plugins/meson.build | 2 +-
> 2 files changed, 220 insertions(+), 1 deletion(-)
> create mode 100644 tests/tcg/plugins/discons.c
>
[...]
> +static void vcpu_discon(qemu_plugin_id_t id, unsigned int vcpu_index,
> + enum qemu_plugin_discon_type type, uint64_t from_pc,
> + uint64_t to_pc)
> +{
> + struct cpu_state *state = qemu_plugin_scoreboard_find(states, vcpu_index);
> +
> + switch (type) {
> + case QEMU_PLUGIN_DISCON_EXCEPTION:
> + /*
> + * For some types of exceptions, insn_exec will be called for the
> + * instruction that caused the exception.
> + */
> + if (addr_eq(state->last_pc, from_pc)) {
> + break;
> + }
> + __attribute__((fallthrough));
It's a bit hard to follow the codepath with the switch and the
fallthrough. Maybe we can simply use an empty if for that.
if (type == QEMU_PLUGIN_DISCON_EXCEPTION &&
addr_eq(state->last_pc, from_pc))
{
/*
* For some types of exceptions, insn_exec will be called for the
* instruction that caused the exception, so we don't report this
* case.
*/
} else if (state->has_next) {
...
} else if (state->has_from) {
...
}
...
set state
...
> + default:
> + if (state->has_next) {
> + /*
> + * We may encounter discontinuity chains without any instructions
> + * being executed in between.
> + */
> + report_mismatch("source", vcpu_index, type, state->last_pc,
> + state->next_pc, from_pc);
> + } else if (state->has_from) {
> + report_mismatch("source", vcpu_index, type, state->last_pc,
> + state->from_pc, from_pc);
> + }
> + }
> +
> + state->has_from = false;
> +
> + state->next_pc = to_pc;
> + state->next_type = type;
> + state->has_next = true;
> +}
> +
> +static void insn_exec(unsigned int vcpu_index, void *userdata)
> +{
> + struct cpu_state *state = qemu_plugin_scoreboard_find(states, vcpu_index);
> + struct insn_data* insn = (struct insn_data *) userdata;
> +
> + state->last_pc = insn->addr;
> + state->has_last = true;
> +
> + if (insn->next_valid) {
> + state->from_pc = insn->next_pc;
> + }
> + state->has_from = insn->next_valid;
> +
> + if (state->has_next) {
> + report_mismatch("target", vcpu_index, state->next_type, state->last_pc,
> + state->next_pc, insn->addr);
> + state->has_next = false;
> + }
> +
> + if (trace_all_insns) {
> + g_autoptr(GString) report = g_string_new(NULL);
> + g_string_append_printf(report, "Exec insn at %"PRIx64" on VCPU %d\n",
> + insn->addr, vcpu_index);
> + qemu_plugin_outs(report->str);
> + }
> +}
> +
> +static void vcpu_tb_trans(qemu_plugin_id_t id, struct qemu_plugin_tb *tb)
> +{
> + size_t i;
> + size_t n_insns = qemu_plugin_tb_n_insns(tb);
> + struct insn_data *udata = calloc(n_insns, sizeof(struct insn_data));
> +
With this, for every TB translated, we'll perform an allocation, and
then lose track of the pointer. It's usually a pain to pass this kind of
"dynamic" information through udata.
A more elegant solution is to perform a QEMU_PLUGIN_INLINE_STORE_U64 to
store this information under a new cpu_state.current_insn field directly.
Callbacks are installed in the order you register them, so by storing
information inline *before* the insn_exec callback, it will work as
expected, as cpu_static.current_insn will be already updated.
You can find some other plugins which use this trick.
> + for (i = 0; i < n_insns; i++) {
Feel free to declare i in the loop directly.
> + struct qemu_plugin_insn *insn = qemu_plugin_tb_get_insn(tb, i);
> + uint64_t pc = qemu_plugin_insn_vaddr(insn);
> + udata[i].addr = pc;
> + udata[i].next_pc = pc + qemu_plugin_insn_size(insn);
> + udata[i].next_valid = true;
> + qemu_plugin_register_vcpu_insn_exec_cb(insn, insn_exec,
> + QEMU_PLUGIN_CB_NO_REGS,
> + &udata[i]);
> + }
> +
> + udata[n_insns - 1].next_valid = false;
> +}
[...]
Otherwise, the logic of the plugin is ok for me.
Reviewed-by: Pierrick Bouvier <pierrick.bouvier@linaro.org>
next prev parent reply other threads:[~2025-05-13 0:26 UTC|newest]
Thread overview: 40+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-05-11 13:13 [PATCH v4 00/23] tcg-plugins: add hooks for discontinuities Julian Ganz
2025-05-11 13:13 ` [PATCH v4 01/23] plugins: add types for callbacks related to certain discontinuities Julian Ganz
2025-05-12 22:35 ` Pierrick Bouvier
2025-05-11 13:13 ` [PATCH v4 02/23] plugins: add API for registering discontinuity callbacks Julian Ganz
2025-05-12 22:36 ` Pierrick Bouvier
2025-05-11 13:13 ` [PATCH v4 03/23] plugins: add hooks for new discontinuity related callbacks Julian Ganz
2025-05-12 22:37 ` Pierrick Bouvier
2025-05-11 13:13 ` [PATCH v4 04/23] contrib/plugins: add plugin showcasing new dicontinuity related API Julian Ganz
2025-05-12 22:45 ` Pierrick Bouvier
2025-05-13 7:22 ` Julian Ganz
2025-05-11 13:13 ` [PATCH v4 05/23] target/alpha: call plugin trap callbacks Julian Ganz
2025-05-11 13:13 ` [PATCH v4 06/23] target/arm: " Julian Ganz
2025-05-11 13:13 ` [PATCH v4 07/23] target/avr: " Julian Ganz
2025-05-11 13:14 ` [PATCH v4 08/23] target/hppa: " Julian Ganz
2025-05-11 13:14 ` [PATCH v4 09/23] target/i386: " Julian Ganz
2025-05-11 13:14 ` [PATCH v4 10/23] target/loongarch: " Julian Ganz
2025-05-11 13:14 ` [PATCH v4 11/23] target/m68k: " Julian Ganz
2025-05-11 13:14 ` [PATCH v4 12/23] target/microblaze: " Julian Ganz
2025-05-11 13:14 ` [PATCH v4 13/23] target/mips: " Julian Ganz
2025-05-11 13:14 ` [PATCH v4 14/23] target/openrisc: " Julian Ganz
2025-05-11 13:14 ` [PATCH v4 15/23] target/ppc: " Julian Ganz
2025-05-11 13:14 ` [PATCH v4 16/23] target/riscv: " Julian Ganz
2025-05-12 12:49 ` Daniel Henrique Barboza
2025-05-12 22:50 ` Alistair Francis
2025-05-11 13:14 ` [PATCH v4 17/23] target/rx: " Julian Ganz
2025-05-11 13:14 ` [PATCH v4 18/23] target/s390x: " Julian Ganz
2025-05-12 7:47 ` David Hildenbrand
[not found] ` <20250512084352.2424-1-ganz@fzi.de>
2025-05-12 8:55 ` Julian Ganz
2025-05-12 9:09 ` David Hildenbrand
2025-05-11 13:14 ` [PATCH v4 19/23] target/sparc: " Julian Ganz
2025-05-11 13:14 ` [PATCH v4 20/23] target/xtensa: " Julian Ganz
2025-05-11 20:40 ` Max Filippov
2025-05-11 13:14 ` [PATCH v4 21/23] tests: add plugin asserting correctness of discon event's to_pc Julian Ganz
2025-05-13 0:25 ` Pierrick Bouvier [this message]
2025-05-13 7:45 ` Julian Ganz
2025-05-13 19:15 ` Julian Ganz
2025-05-11 13:22 ` [PATCH v4 22/23] tests: add test for double-traps on rv64 Julian Ganz
2025-05-12 12:50 ` Daniel Henrique Barboza
2025-05-11 13:22 ` [PATCH v4 23/23] tests: add test with interrupted memory accesses " Julian Ganz
2025-05-12 12:51 ` Daniel Henrique Barboza
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=53632928-0367-44cf-a93e-6ba14bb85458@linaro.org \
--to=pierrick.bouvier@linaro.org \
--cc=alex.bennee@linaro.org \
--cc=erdnaxe@crans.org \
--cc=ma.mandourr@gmail.com \
--cc=neither@nut.email \
--cc=qemu-devel@nongnu.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).