qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
From: Pierrick Bouvier <pierrick.bouvier@linaro.org>
To: Julian Ganz <neither@nut.email>, qemu-devel@nongnu.org
Cc: "Alex Bennée" <alex.bennee@linaro.org>,
	"Alexandre Iooss" <erdnaxe@crans.org>,
	"Mahmoud Mandour" <ma.mandourr@gmail.com>
Subject: Re: [PATCH v4 21/23] tests: add plugin asserting correctness of discon event's to_pc
Date: Mon, 12 May 2025 17:25:24 -0700	[thread overview]
Message-ID: <53632928-0367-44cf-a93e-6ba14bb85458@linaro.org> (raw)
In-Reply-To: <e212e53b98c264366458654493e2fa2e2cdecdcc.1746968215.git.neither@nut.email>

On 5/11/25 6:14 AM, Julian Ganz wrote:
> We recently introduced plugin API for the registration of callbacks for
> discontinuity events, specifically for interrupts, exceptions and host
> call events. The callback receives various bits of information,
> including the VCPU index and PCs.
> 
> This change introduces a test plugin asserting the correctness of that
> behaviour in cases where this is possible with reasonable effort. Since
> instruction PCs are recorded at translation blocks translation time and
> a TB may be used in multiple processes running in distinct virtual
> memory, the plugin allows comparing not full addresses but a subset of
> address bits via the `compare-addr-bits` option.
> 
> Signed-off-by: Julian Ganz <neither@nut.email>
> ---
>   tests/tcg/plugins/discons.c   | 219 ++++++++++++++++++++++++++++++++++
>   tests/tcg/plugins/meson.build |   2 +-
>   2 files changed, 220 insertions(+), 1 deletion(-)
>   create mode 100644 tests/tcg/plugins/discons.c
> 

[...]

> +static void vcpu_discon(qemu_plugin_id_t id, unsigned int vcpu_index,
> +                        enum qemu_plugin_discon_type type, uint64_t from_pc,
> +                        uint64_t to_pc)
> +{
> +    struct cpu_state *state = qemu_plugin_scoreboard_find(states, vcpu_index);
> +
> +    switch (type) {
> +    case QEMU_PLUGIN_DISCON_EXCEPTION:
> +        /*
> +         * For some types of exceptions, insn_exec will be called for the
> +         * instruction that caused the exception.
> +         */
> +        if (addr_eq(state->last_pc, from_pc)) {
> +            break;
> +        }
> +        __attribute__((fallthrough));

It's a bit hard to follow the codepath with the switch and the 
fallthrough. Maybe we can simply use an empty if for that.

if (type == QEMU_PLUGIN_DISCON_EXCEPTION &&
     addr_eq(state->last_pc, from_pc))
{
   /*
    * For some types of exceptions, insn_exec will be called for the
    * instruction that caused the exception, so we don't report this
    * case.
    */
} else if (state->has_next) {
   ...
} else if (state->has_from) {
   ...
}

...
set state
...

> +    default:
> +        if (state->has_next) {
> +            /*
> +             * We may encounter discontinuity chains without any instructions
> +             * being executed in between.
> +             */
> +            report_mismatch("source", vcpu_index, type, state->last_pc,
> +                            state->next_pc, from_pc);
> +        } else if (state->has_from) {
> +            report_mismatch("source", vcpu_index, type, state->last_pc,
> +                            state->from_pc, from_pc);
> +        }
> +    }
> +
> +    state->has_from = false;
> +
> +    state->next_pc = to_pc;
> +    state->next_type = type;
> +    state->has_next = true;
> +}
> +
> +static void insn_exec(unsigned int vcpu_index, void *userdata)
> +{
> +    struct cpu_state *state = qemu_plugin_scoreboard_find(states, vcpu_index);
> +    struct insn_data* insn = (struct insn_data *) userdata;
> +
> +    state->last_pc = insn->addr;
> +    state->has_last = true;
> +
> +    if (insn->next_valid) {
> +        state->from_pc = insn->next_pc;
> +    }
> +    state->has_from = insn->next_valid;
> +
> +    if (state->has_next) {
> +        report_mismatch("target", vcpu_index, state->next_type, state->last_pc,
> +                        state->next_pc, insn->addr);
> +        state->has_next = false;
> +    }
> +
> +    if (trace_all_insns) {
> +        g_autoptr(GString) report = g_string_new(NULL);
> +        g_string_append_printf(report, "Exec insn at %"PRIx64" on VCPU %d\n",
> +                               insn->addr, vcpu_index);
> +        qemu_plugin_outs(report->str);
> +    }
> +}
> +
> +static void vcpu_tb_trans(qemu_plugin_id_t id, struct qemu_plugin_tb *tb)
> +{
> +    size_t i;
> +    size_t n_insns = qemu_plugin_tb_n_insns(tb);
> +    struct insn_data *udata = calloc(n_insns, sizeof(struct insn_data));
> +

With this, for every TB translated, we'll perform an allocation, and 
then lose track of the pointer. It's usually a pain to pass this kind of 
"dynamic" information through udata.

A more elegant solution is to perform a QEMU_PLUGIN_INLINE_STORE_U64 to 
store this information under a new cpu_state.current_insn field directly.
Callbacks are installed in the order you register them, so by storing 
information inline *before* the insn_exec callback, it will work as 
expected, as cpu_static.current_insn will be already updated.
You can find some other plugins which use this trick.

> +    for (i = 0; i < n_insns; i++) {

Feel free to declare i in the loop directly.

> +        struct qemu_plugin_insn *insn = qemu_plugin_tb_get_insn(tb, i);
> +        uint64_t pc = qemu_plugin_insn_vaddr(insn);
> +        udata[i].addr = pc;
> +        udata[i].next_pc = pc + qemu_plugin_insn_size(insn);
> +        udata[i].next_valid = true;
> +        qemu_plugin_register_vcpu_insn_exec_cb(insn, insn_exec,
> +                                               QEMU_PLUGIN_CB_NO_REGS,
> +                                               &udata[i]);
> +    }
> +
> +    udata[n_insns - 1].next_valid = false;
> +}

[...]

Otherwise, the logic of the plugin is ok for me.

Reviewed-by: Pierrick Bouvier <pierrick.bouvier@linaro.org>


  reply	other threads:[~2025-05-13  0:26 UTC|newest]

Thread overview: 40+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-05-11 13:13 [PATCH v4 00/23] tcg-plugins: add hooks for discontinuities Julian Ganz
2025-05-11 13:13 ` [PATCH v4 01/23] plugins: add types for callbacks related to certain discontinuities Julian Ganz
2025-05-12 22:35   ` Pierrick Bouvier
2025-05-11 13:13 ` [PATCH v4 02/23] plugins: add API for registering discontinuity callbacks Julian Ganz
2025-05-12 22:36   ` Pierrick Bouvier
2025-05-11 13:13 ` [PATCH v4 03/23] plugins: add hooks for new discontinuity related callbacks Julian Ganz
2025-05-12 22:37   ` Pierrick Bouvier
2025-05-11 13:13 ` [PATCH v4 04/23] contrib/plugins: add plugin showcasing new dicontinuity related API Julian Ganz
2025-05-12 22:45   ` Pierrick Bouvier
2025-05-13  7:22     ` Julian Ganz
2025-05-11 13:13 ` [PATCH v4 05/23] target/alpha: call plugin trap callbacks Julian Ganz
2025-05-11 13:13 ` [PATCH v4 06/23] target/arm: " Julian Ganz
2025-05-11 13:13 ` [PATCH v4 07/23] target/avr: " Julian Ganz
2025-05-11 13:14 ` [PATCH v4 08/23] target/hppa: " Julian Ganz
2025-05-11 13:14 ` [PATCH v4 09/23] target/i386: " Julian Ganz
2025-05-11 13:14 ` [PATCH v4 10/23] target/loongarch: " Julian Ganz
2025-05-11 13:14 ` [PATCH v4 11/23] target/m68k: " Julian Ganz
2025-05-11 13:14 ` [PATCH v4 12/23] target/microblaze: " Julian Ganz
2025-05-11 13:14 ` [PATCH v4 13/23] target/mips: " Julian Ganz
2025-05-11 13:14 ` [PATCH v4 14/23] target/openrisc: " Julian Ganz
2025-05-11 13:14 ` [PATCH v4 15/23] target/ppc: " Julian Ganz
2025-05-11 13:14 ` [PATCH v4 16/23] target/riscv: " Julian Ganz
2025-05-12 12:49   ` Daniel Henrique Barboza
2025-05-12 22:50   ` Alistair Francis
2025-05-11 13:14 ` [PATCH v4 17/23] target/rx: " Julian Ganz
2025-05-11 13:14 ` [PATCH v4 18/23] target/s390x: " Julian Ganz
2025-05-12  7:47   ` David Hildenbrand
     [not found]     ` <20250512084352.2424-1-ganz@fzi.de>
2025-05-12  8:55       ` Julian Ganz
2025-05-12  9:09       ` David Hildenbrand
2025-05-11 13:14 ` [PATCH v4 19/23] target/sparc: " Julian Ganz
2025-05-11 13:14 ` [PATCH v4 20/23] target/xtensa: " Julian Ganz
2025-05-11 20:40   ` Max Filippov
2025-05-11 13:14 ` [PATCH v4 21/23] tests: add plugin asserting correctness of discon event's to_pc Julian Ganz
2025-05-13  0:25   ` Pierrick Bouvier [this message]
2025-05-13  7:45     ` Julian Ganz
2025-05-13 19:15       ` Julian Ganz
2025-05-11 13:22 ` [PATCH v4 22/23] tests: add test for double-traps on rv64 Julian Ganz
2025-05-12 12:50   ` Daniel Henrique Barboza
2025-05-11 13:22 ` [PATCH v4 23/23] tests: add test with interrupted memory accesses " Julian Ganz
2025-05-12 12:51   ` Daniel Henrique Barboza

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=53632928-0367-44cf-a93e-6ba14bb85458@linaro.org \
    --to=pierrick.bouvier@linaro.org \
    --cc=alex.bennee@linaro.org \
    --cc=erdnaxe@crans.org \
    --cc=ma.mandourr@gmail.com \
    --cc=neither@nut.email \
    --cc=qemu-devel@nongnu.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).