From: Ilya Leoshkevich <iii@linux.ibm.com>
To: "Philippe Mathieu-Daudé" <philmd@linaro.org>,
"Richard Henderson" <richard.henderson@linaro.org>,
"David Hildenbrand" <david@redhat.com>,
"Thomas Huth" <thuth@redhat.com>
Cc: qemu-s390x@nongnu.org, qemu-devel@nongnu.org
Subject: Re: [PATCH v2 1/2] target/s390x: Fix R[NOX]SBG with T=1
Date: Thu, 16 Mar 2023 18:15:06 +0100 [thread overview]
Message-ID: <a2e12eb0c498958524888cfc539e8f30174b2faf.camel@linux.ibm.com> (raw)
In-Reply-To: <9b5c4389-a9e3-00e1-11fa-b1a0c10cd312@linaro.org>
On Thu, 2023-03-16 at 09:41 +0100, Philippe Mathieu-Daudé wrote:
> On 16/3/23 00:56, Ilya Leoshkevich wrote:
> > RXSBG usage in the "filetests" test from the wasmtime testsuite
> > makes
> > tcg_reg_alloc_op() attempt to temp_load() a TEMP_VAL_DEAD
> > temporary,
> > causing an assertion failure:
> >
> > 0x01000a70: ec14 b040 3057 rxsbg %r1, %r4, 0xb0, 0x40,
> > 0x30
> >
> > OP after optimization and liveness analysis:
> > ---- 0000000001000a70 0000000000000004 0000000000000006
> > rotl_i64 tmp2,r4,$0x30 dead: 1 2
> > pref=0xffff
> > and_i64 tmp2,tmp2,$0x800000000000ffff dead: 1 pref=0xffff
> > [xor_i64 tmp3,tmp3,tmp2 dead: 1 2
> > pref=0xffff]
> > and_i64 cc_dst,tmp3,$0x800000000000ffff sync: 0 dead: 0 1
> > 2 pref=0xffff
> > mov_i64 psw_addr,$0x1000a76 sync: 0 dead: 0 1
> > pref=0xffff
> > mov_i32 cc_op,$0x6 sync: 0 dead: 0 1
> > pref=0xffff
> > call lookup_tb_ptr,$0x6,$1,tmp8,env dead: 1 pref=none
> > goto_ptr tmp8 dead: 0
> > set_label $L0
> > exit_tb $0x7fffe809d183
> >
> > ../tcg/tcg.c:3865: tcg fatal error
> >
> > The reason is that tmp3 does not have an initial value, which
> > confuses
> > the register allocator. This also affects the correctness of the
> > results.
> >
> > Fix by assigning R1 to it.
> >
> > Fixes: d6c6372e186e ("target-s390: Implement R[NOX]SBG")
>
> Exposed by 3ac6f91bca..dd161de75f?
Bisect points to:
commit e2e641fa3d5e730f128562d6901dcc729c9bf8a0
Author: Richard Henderson <richard.henderson@linaro.org>
Date: Sun Jan 29 14:09:00 2023 -1000
tcg: Change default temp lifetime to TEMP_TB
I will mention this.
> 3ac6f91bca target/s390x: Drop tcg_temp_free from translate.c
> dd161de75f target/s390x: Remove g_out, g_out2, g_in1, g_in2
>
> > Reviewed-by: David Hildenbrand <david@redhat.com>
> > Signed-off-by: Ilya Leoshkevich <iii@linux.ibm.com>
> > ---
> > target/s390x/tcg/translate.c | 3 +++
> > 1 file changed, 3 insertions(+)
> >
> > diff --git a/target/s390x/tcg/translate.c
> > b/target/s390x/tcg/translate.c
> > index 14c3896d529..6dd2f41ad08 100644
> > --- a/target/s390x/tcg/translate.c
> > +++ b/target/s390x/tcg/translate.c
> > @@ -3696,10 +3696,13 @@ static DisasJumpType op_rosbg(DisasContext
> > *s, DisasOps *o)
> > int i4 = get_field(s, i4);
> > int i5 = get_field(s, i5);
> > uint64_t mask;
> > + TCGv_i64 tmp;
> >
> > /* If this is a test-only form, arrange to discard the
> > result. */
> > if (i3 & 0x80) {
>
> tcg_debug_assert(o->out != NULL); ?
Ok, I will add this.
>
> > + tmp = o->out;
> > o->out = tcg_temp_new_i64();
> > + tcg_gen_mov_i64(o->out, tmp);
>
> Something bugs me with this pattern but I can't say why yet :(
Please let me know once you come up with something.
I will do s/tmp/orig_out/ send a v3 in the meantime.
> > }
> >
> > i3 &= 63;
next prev parent reply other threads:[~2023-03-16 17:16 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2023-03-15 23:56 [PATCH v2 0/2] target/s390x: Fix R[NOX]SBG with T=1 Ilya Leoshkevich
2023-03-15 23:56 ` [PATCH v2 1/2] " Ilya Leoshkevich
2023-03-16 8:41 ` Philippe Mathieu-Daudé
2023-03-16 17:15 ` Ilya Leoshkevich [this message]
2023-03-15 23:56 ` [PATCH v2 2/2] tests/tcg/s390x: Add rxsbg.c Ilya Leoshkevich
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=a2e12eb0c498958524888cfc539e8f30174b2faf.camel@linux.ibm.com \
--to=iii@linux.ibm.com \
--cc=david@redhat.com \
--cc=philmd@linaro.org \
--cc=qemu-devel@nongnu.org \
--cc=qemu-s390x@nongnu.org \
--cc=richard.henderson@linaro.org \
--cc=thuth@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).