qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
From: Ilya Leoshkevich <iii@linux.ibm.com>
To: "Philippe Mathieu-Daudé" <philmd@linaro.org>,
	"Richard Henderson" <richard.henderson@linaro.org>,
	"David Hildenbrand" <david@redhat.com>,
	"Thomas Huth" <thuth@redhat.com>
Cc: qemu-s390x@nongnu.org, qemu-devel@nongnu.org
Subject: Re: [PATCH v2 1/2] target/s390x: Fix R[NOX]SBG with T=1
Date: Thu, 16 Mar 2023 18:15:06 +0100	[thread overview]
Message-ID: <a2e12eb0c498958524888cfc539e8f30174b2faf.camel@linux.ibm.com> (raw)
In-Reply-To: <9b5c4389-a9e3-00e1-11fa-b1a0c10cd312@linaro.org>

On Thu, 2023-03-16 at 09:41 +0100, Philippe Mathieu-Daudé wrote:
> On 16/3/23 00:56, Ilya Leoshkevich wrote:
> > RXSBG usage in the "filetests" test from the wasmtime testsuite
> > makes
> > tcg_reg_alloc_op() attempt to temp_load() a TEMP_VAL_DEAD
> > temporary,
> > causing an assertion failure:
> > 
> >      0x01000a70:  ec14 b040 3057  rxsbg    %r1, %r4, 0xb0, 0x40,
> > 0x30
> > 
> >      OP after optimization and liveness analysis:
> >       ---- 0000000001000a70 0000000000000004 0000000000000006
> >       rotl_i64 tmp2,r4,$0x30                   dead: 1 2 
> > pref=0xffff
> >       and_i64 tmp2,tmp2,$0x800000000000ffff    dead: 1  pref=0xffff
> >      [xor_i64 tmp3,tmp3,tmp2                   dead: 1 2 
> > pref=0xffff]
> >       and_i64 cc_dst,tmp3,$0x800000000000ffff  sync: 0  dead: 0 1
> > 2  pref=0xffff
> >       mov_i64 psw_addr,$0x1000a76              sync: 0  dead: 0 1 
> > pref=0xffff
> >       mov_i32 cc_op,$0x6                       sync: 0  dead: 0 1 
> > pref=0xffff
> >       call lookup_tb_ptr,$0x6,$1,tmp8,env      dead: 1  pref=none
> >       goto_ptr tmp8                            dead: 0
> >       set_label $L0
> >       exit_tb $0x7fffe809d183
> > 
> >      ../tcg/tcg.c:3865: tcg fatal error
> > 
> > The reason is that tmp3 does not have an initial value, which
> > confuses
> > the register allocator. This also affects the correctness of the
> > results.
> > 
> > Fix by assigning R1 to it.
> > 
> > Fixes: d6c6372e186e ("target-s390: Implement R[NOX]SBG")
> 
> Exposed by 3ac6f91bca..dd161de75f?

Bisect points to:

commit e2e641fa3d5e730f128562d6901dcc729c9bf8a0
Author: Richard Henderson <richard.henderson@linaro.org>
Date:   Sun Jan 29 14:09:00 2023 -1000

    tcg: Change default temp lifetime to TEMP_TB

I will mention this.

> 3ac6f91bca target/s390x: Drop tcg_temp_free from translate.c
> dd161de75f target/s390x: Remove g_out, g_out2, g_in1, g_in2
> 
> > Reviewed-by: David Hildenbrand <david@redhat.com>
> > Signed-off-by: Ilya Leoshkevich <iii@linux.ibm.com>
> > ---
> >   target/s390x/tcg/translate.c | 3 +++
> >   1 file changed, 3 insertions(+)
> > 
> > diff --git a/target/s390x/tcg/translate.c
> > b/target/s390x/tcg/translate.c
> > index 14c3896d529..6dd2f41ad08 100644
> > --- a/target/s390x/tcg/translate.c
> > +++ b/target/s390x/tcg/translate.c
> > @@ -3696,10 +3696,13 @@ static DisasJumpType op_rosbg(DisasContext
> > *s, DisasOps *o)
> >       int i4 = get_field(s, i4);
> >       int i5 = get_field(s, i5);
> >       uint64_t mask;
> > +    TCGv_i64 tmp;
> >   
> >       /* If this is a test-only form, arrange to discard the
> > result.  */
> >       if (i3 & 0x80) {
> 
>            tcg_debug_assert(o->out != NULL); ?

Ok, I will add this.

> 
> > +        tmp = o->out;
> >           o->out = tcg_temp_new_i64();
> > +        tcg_gen_mov_i64(o->out, tmp);
> 
> Something bugs me with this pattern but I can't say why yet :(

Please let me know once you come up with something.
I will do s/tmp/orig_out/ send a v3 in the meantime.

> >       }
> >   
> >       i3 &= 63;



  reply	other threads:[~2023-03-16 17:16 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2023-03-15 23:56 [PATCH v2 0/2] target/s390x: Fix R[NOX]SBG with T=1 Ilya Leoshkevich
2023-03-15 23:56 ` [PATCH v2 1/2] " Ilya Leoshkevich
2023-03-16  8:41   ` Philippe Mathieu-Daudé
2023-03-16 17:15     ` Ilya Leoshkevich [this message]
2023-03-15 23:56 ` [PATCH v2 2/2] tests/tcg/s390x: Add rxsbg.c Ilya Leoshkevich

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=a2e12eb0c498958524888cfc539e8f30174b2faf.camel@linux.ibm.com \
    --to=iii@linux.ibm.com \
    --cc=david@redhat.com \
    --cc=philmd@linaro.org \
    --cc=qemu-devel@nongnu.org \
    --cc=qemu-s390x@nongnu.org \
    --cc=richard.henderson@linaro.org \
    --cc=thuth@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).