From nobody Sun Oct 26 07:43:47 2025 Delivered-To: importer@patchew.org Received-SPF: pass (zoho.com: domain of gnu.org designates 208.118.235.17 as permitted sender) client-ip=208.118.235.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Authentication-Results: mx.zohomail.com; spf=pass (zoho.com: domain of gnu.org designates 208.118.235.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists.gnu.org (208.118.235.17 [208.118.235.17]) by mx.zohomail.com with SMTPS id 1521537003030799.2034068506193; Tue, 20 Mar 2018 02:10:03 -0700 (PDT) Received: from localhost ([::1]:46919 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1eyDHI-0003lJ-VR for importer@patchew.org; Tue, 20 Mar 2018 05:09:57 -0400 Received: from eggs.gnu.org ([2001:4830:134:3::10]:46521) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1eyDFs-00031c-3l for qemu-devel@nongnu.org; Tue, 20 Mar 2018 05:08:32 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1eyDFn-0002Ok-KP for qemu-devel@nongnu.org; Tue, 20 Mar 2018 05:08:28 -0400 Received: from mout.kundenserver.de ([212.227.126.131]:59527) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1eyDFn-0002Nb-A5 for qemu-devel@nongnu.org; Tue, 20 Mar 2018 05:08:23 -0400 Received: from localhost.localdomain ([78.238.229.36]) by mrelayeu.kundenserver.de (mreue002 [212.227.15.167]) with ESMTPSA (Nemesis) id 0MB724-1eqXkv2elo-00A08u; Tue, 20 Mar 2018 10:08:21 +0100 From: Laurent Vivier To: qemu-devel@nongnu.org Date: Tue, 20 Mar 2018 10:08:13 +0100 Message-Id: <20180320090813.852-3-laurent@vivier.eu> X-Mailer: git-send-email 2.14.3 In-Reply-To: <20180320090813.852-1-laurent@vivier.eu> References: <20180320090813.852-1-laurent@vivier.eu> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Provags-ID: V03:K0:PNxxFdRlVSF11aPwZxXChaEyePvZojXJOYAzByD7tF2H9Rs9lUR oRPI6/lJNtZvWneHrGdsMVTEad+Z339Prf9QWKF0XFyjS/n+d9tXXQXc7hg2WlN+Zak/Q/Q cBLdjXq2vJHymhH8jsEoPfqxTlPpuo1H2eBuI5YxalxP+mvu7QSbZ/XlpkKqrHuVMxw4gm7 ITVxuQfgW897nl2slsHZw== X-UI-Out-Filterresults: notjunk:1;V01:K0:rXlRb5YCqJw=:9HjUIs2fpSKj2nTXBRSxPE 6oV3BaQbneOpv5qdb7NzBJL81XIbKXar8Yx5XKCE+YGXKJFFkxbsGa40bqwo6rAv6HR/Xc5ao zlDwhHTVDfucmF9o/gBYpwJhh00MHwKZzvrxfFy5YYiwyqVytJYbhHsEHdQGG58mYwTsPx3g5 7R/NVqrdLyuCG0HiFc+dA0lw4awsUIGts1IoHZy24wt/RgBcu+DxAtw6PlTV8ysURHfBvCQX3 /LAaiox0EgPgylQb2k3YBnKYRO00x1h+mn7KeWtwqGkelXOiU8ll/UAXHmZtcfvm2N1H+aVc9 XPvnSY4vMtIQ/P7UOSUaIXBPm7GCTGTEzqqI7KDeNBnPPl7/lI8qP2ElA1c9iBCTEdFqYZft8 tnBhvvH3SJQYbldSAR25SY5ptLVQaSPnEDCqY41KqycFlTrEc+COp6iH8WhgkU9BoJ4bZAtmr ToMuAXoYwJF0Tp5fc+2veSeX0yHQePOs+khucKlHoTnRTt6QIoiUiJ1dBozeRZ67aqazD+hhP i2/SfKvfQe8AdGDkvQ1qEDtZ4AO0xcSYZ8IQZsWk+fbWGrBh0mweBk8rscxslV1ilbjk2/QmO thxkARoxZy6/azlLa6yjzMg75O0Ai/SpPR3gAZwS/9FZD4/ZBlFhyn00ROnjN2tD+Gmb3msVf 7i6IDGtLdWkaCB82iK9tbQpZbOVITbGa2JSlYmPnEnPsEPMQAijm5hAYzC4G0NrFdiznUCOx8 vagpZO4OFu1mDgBJyZQWuzSrXfJxAnQ4PcV+BL0Z7PywzsWJkJ2WYNs/B/U= X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic] [fuzzy] X-Received-From: 212.227.126.131 Subject: [Qemu-devel] [PULL 2/2] target/m68k: add a mechanism to automatically free TCGv X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Laurent Vivier Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: "Qemu-devel" X-ZohoMail: RSF_0 Z_629925259 SPT_0 SRC_EA() and gen_extend() can return either a temporary TCGv or a memory allocated one. Mark them when they are allocated, and free them automatically at end of the instruction translation. We want to free locally allocated TCGv to avoid overflow in sequence like: 0xc00ae406: movel %fp@(-132),%fp@(-268) 0xc00ae40c: movel %fp@(-128),%fp@(-264) 0xc00ae412: movel %fp@(-20),%fp@(-212) 0xc00ae418: movel %fp@(-16),%fp@(-208) 0xc00ae41e: movel %fp@(-60),%fp@(-220) 0xc00ae424: movel %fp@(-56),%fp@(-216) 0xc00ae42a: movel %fp@(-124),%fp@(-252) 0xc00ae430: movel %fp@(-120),%fp@(-248) 0xc00ae436: movel %fp@(-12),%fp@(-260) 0xc00ae43c: movel %fp@(-8),%fp@(-256) 0xc00ae442: movel %fp@(-52),%fp@(-276) 0xc00ae448: movel %fp@(-48),%fp@(-272) ... That can fill a lot of TCGv entries in a sequence, especially since 15fa08f845 ("tcg: Dynamically allocate TCGOps") we have no limit to fill the TCGOps cache and we can fill the entire TCG variables array and overflow it. Suggested-by: Richard Henderson Signed-off-by: Laurent Vivier Reviewed-by: Richard Henderson Reviewed-by: Philippe Mathieu-Daud=C3=A9 Message-Id: <20180319113544.704-3-laurent@vivier.eu> --- target/m68k/translate.c | 56 +++++++++++++++++++++++++++++++++++++--------= ---- 1 file changed, 43 insertions(+), 13 deletions(-) diff --git a/target/m68k/translate.c b/target/m68k/translate.c index 1c2ff56305..6beaf9ed66 100644 --- a/target/m68k/translate.c +++ b/target/m68k/translate.c @@ -123,8 +123,34 @@ typedef struct DisasContext { int done_mac; int writeback_mask; TCGv writeback[8]; +#define MAX_TO_RELEASE 8 + int release_count; + TCGv release[MAX_TO_RELEASE]; } DisasContext; =20 +static void init_release_array(DisasContext *s) +{ +#ifdef CONFIG_DEBUG_TCG + memset(s->release, 0, sizeof(s->release)); +#endif + s->release_count =3D 0; +} + +static void do_release(DisasContext *s) +{ + int i; + for (i =3D 0; i < s->release_count; i++) { + tcg_temp_free(s->release[i]); + } + init_release_array(s); +} + +static TCGv mark_to_release(DisasContext *s, TCGv tmp) +{ + g_assert(s->release_count < MAX_TO_RELEASE); + return s->release[s->release_count++] =3D tmp; +} + static TCGv get_areg(DisasContext *s, unsigned regno) { if (s->writeback_mask & (1 << regno)) { @@ -347,7 +373,8 @@ static TCGv gen_ldst(DisasContext *s, int opsize, TCGv = addr, TCGv val, gen_store(s, opsize, addr, val, index); return store_dummy; } else { - return gen_load(s, opsize, addr, what =3D=3D EA_LOADS, index); + return mark_to_release(s, gen_load(s, opsize, addr, + what =3D=3D EA_LOADS, index)); } } =20 @@ -439,7 +466,7 @@ static TCGv gen_lea_indexed(CPUM68KState *env, DisasCon= text *s, TCGv base) } else { bd =3D 0; } - tmp =3D tcg_temp_new(); + tmp =3D mark_to_release(s, tcg_temp_new()); if ((ext & 0x44) =3D=3D 0) { /* pre-index */ add =3D gen_addr_index(s, ext, tmp); @@ -449,7 +476,7 @@ static TCGv gen_lea_indexed(CPUM68KState *env, DisasCon= text *s, TCGv base) if ((ext & 0x80) =3D=3D 0) { /* base not suppressed */ if (IS_NULL_QREG(base)) { - base =3D tcg_const_i32(offset + bd); + base =3D mark_to_release(s, tcg_const_i32(offset + bd)); bd =3D 0; } if (!IS_NULL_QREG(add)) { @@ -465,11 +492,11 @@ static TCGv gen_lea_indexed(CPUM68KState *env, DisasC= ontext *s, TCGv base) add =3D tmp; } } else { - add =3D tcg_const_i32(bd); + add =3D mark_to_release(s, tcg_const_i32(bd)); } if ((ext & 3) !=3D 0) { /* memory indirect */ - base =3D gen_load(s, OS_LONG, add, 0, IS_USER(s)); + base =3D mark_to_release(s, gen_load(s, OS_LONG, add, 0, IS_US= ER(s))); if ((ext & 0x44) =3D=3D 4) { add =3D gen_addr_index(s, ext, tmp); tcg_gen_add_i32(tmp, add, base); @@ -494,7 +521,7 @@ static TCGv gen_lea_indexed(CPUM68KState *env, DisasCon= text *s, TCGv base) } } else { /* brief extension word format */ - tmp =3D tcg_temp_new(); + tmp =3D mark_to_release(s, tcg_temp_new()); add =3D gen_addr_index(s, ext, tmp); if (!IS_NULL_QREG(base)) { tcg_gen_add_i32(tmp, add, base); @@ -624,7 +651,7 @@ static inline TCGv gen_extend(DisasContext *s, TCGv val= , int opsize, int sign) if (opsize =3D=3D OS_LONG) { tmp =3D val; } else { - tmp =3D tcg_temp_new(); + tmp =3D mark_to_release(s, tcg_temp_new()); gen_ext(tmp, val, opsize, sign); } =20 @@ -746,7 +773,7 @@ static TCGv gen_lea_mode(CPUM68KState *env, DisasContex= t *s, return NULL_QREG; } reg =3D get_areg(s, reg0); - tmp =3D tcg_temp_new(); + tmp =3D mark_to_release(s, tcg_temp_new()); if (reg0 =3D=3D 7 && opsize =3D=3D OS_BYTE && m68k_feature(s->env, M68K_FEATURE_M68000)) { tcg_gen_subi_i32(tmp, reg, 2); @@ -756,7 +783,7 @@ static TCGv gen_lea_mode(CPUM68KState *env, DisasContex= t *s, return tmp; case 5: /* Indirect displacement. */ reg =3D get_areg(s, reg0); - tmp =3D tcg_temp_new(); + tmp =3D mark_to_release(s, tcg_temp_new()); ext =3D read_im16(env, s); tcg_gen_addi_i32(tmp, reg, (int16_t)ext); return tmp; @@ -767,14 +794,14 @@ static TCGv gen_lea_mode(CPUM68KState *env, DisasCont= ext *s, switch (reg0) { case 0: /* Absolute short. */ offset =3D (int16_t)read_im16(env, s); - return tcg_const_i32(offset); + return mark_to_release(s, tcg_const_i32(offset)); case 1: /* Absolute long. */ offset =3D read_im32(env, s); - return tcg_const_i32(offset); + return mark_to_release(s, tcg_const_i32(offset)); case 2: /* pc displacement */ offset =3D s->pc; offset +=3D (int16_t)read_im16(env, s); - return tcg_const_i32(offset); + return mark_to_release(s, tcg_const_i32(offset)); case 3: /* pc index+displacement. */ return gen_lea_indexed(env, s, NULL_QREG); case 4: /* Immediate. */ @@ -900,7 +927,7 @@ static TCGv gen_ea_mode(CPUM68KState *env, DisasContext= *s, int mode, int reg0, default: g_assert_not_reached(); } - return tcg_const_i32(offset); + return mark_to_release(s, tcg_const_i32(offset)); default: return NULL_QREG; } @@ -6033,6 +6060,7 @@ static void disas_m68k_insn(CPUM68KState * env, Disas= Context *s) uint16_t insn =3D read_im16(env, s); opcode_table[insn](env, s, insn); do_writebacks(s); + do_release(s); } =20 /* generate intermediate code for basic block 'tb'. */ @@ -6067,6 +6095,8 @@ void gen_intermediate_code(CPUState *cs, TranslationB= lock *tb) max_insns =3D TCG_MAX_INSNS; } =20 + init_release_array(dc); + gen_tb_start(tb); do { pc_offset =3D dc->pc - pc_start; --=20 2.14.3