From nobody Sun Jul 26 13:26:00 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=gmail.com ARC-Seal: i=1; a=rsa-sha256; t=1781482183; cv=none; d=zohomail.com; s=zohoarc; b=DtrLhDemdv9GD/ukzjkcaKnM7XCHQHt24JOPZiT2Jbz1DNhB/SOVbj2pMTMdGf+9vLHQD+ik8/+0nlbsW4BpWAorq3+UEXdNIbdPt1a2av6Uiqz7d2JZkQMIlMPHqePRObaooYWfLvDXl2TGkPJ/6w3jK/uoMErtNPuR2g6U7n4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781482183; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=0itSddNhXHUQmdf83KRdnrOB89AyIQq3+Tsy42l9m4E=; b=Smw8bdUJBXanwsQn9mhuVQL8JtBR5Re2PQsvn0ivc8AOO+JBu8qLCAvnJhTeOYaI8mXAOyrFhlSlDZuDVnRioYj8WXSU853G6VDTTH9tONJGn83/uQxZlgZ9QY0Lh0BPhQOCM/bPmp0DyhjgfzRKsfABtdY4z1AQ6cQQqQmXY/I= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781482183020228.34492976645504; Sun, 14 Jun 2026 17:09:43 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wYusg-0001Fr-KE; Sun, 14 Jun 2026 20:08:46 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wYusf-0001Fb-Kz for qemu-devel@nongnu.org; Sun, 14 Jun 2026 20:08:45 -0400 Received: from mail-yw1-x1134.google.com ([2607:f8b0:4864:20::1134]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wYusd-0001xU-LQ for qemu-devel@nongnu.org; Sun, 14 Jun 2026 20:08:45 -0400 Received: by mail-yw1-x1134.google.com with SMTP id 00721157ae682-7e16f05fd79so26590207b3.1 for ; Sun, 14 Jun 2026 17:08:42 -0700 (PDT) Received: from skippy.tail1682c8.ts.net (99-61-67-1.lightspeed.austtx.sbcglobal.net. [99.61.67.1]) by smtp.gmail.com with ESMTPSA id 00721157ae682-7f76e2b578asm38654607b3.3.2026.06.14.17.08.41 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 14 Jun 2026 17:08:41 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1781482122; x=1782086922; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=0itSddNhXHUQmdf83KRdnrOB89AyIQq3+Tsy42l9m4E=; b=otyAaiUYnLTem2U1KOpRPDxiJC9DGLcywCXjMLHllI9rCb9a6tA9hxU2a3OuSTVl1c m0fyStH/hkN/yNwIxsNuvIK7WVErEok9tmu275T/XTD40oCLsTpa7Cc+iBuHXHTWx8RI rqXDl14Q9L7dVcdccGA0jJAb+Eg6f8/32R/9rLkDQV5HlAsZUH0gl49z2IVe5VbitwRz Bqx8yYJV9e7rtC8on3W671OQUdX3FFH4/Er3MsQyYOhojU9M1ZL6d4UcV5onBwZjJ9/6 nFxudt4dzIRv4b5SVc+V9iR2QXofonUD8Q3aNUZxjaHSFjrbiH7kFgyCIKyRyKDUMXab MRIw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1781482122; x=1782086922; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=0itSddNhXHUQmdf83KRdnrOB89AyIQq3+Tsy42l9m4E=; b=X2dRQehPoFH1BAlPRYBRTdnHpIk9Q2jzUxi1Eq5v/p+mKDl7/VrtirWP1seQtbIubN PhdvTQnGlGZ5JJTeLpxHwB+upAOBUSTr/18Fqk3EQmfBzWcWodkczLnqsQkNLULD+cCi zdrZV0OH5l5scmsKrXBLhRkuEuORBRAdc8unyc+1CynmFy/oONs25UYTOp/HzE1DNjom mZ1rKNFD9cuLzhXADTCQX/5t/m2JkeHHcKC0gKvFwPDlQO9SAWgh/W/DMRK2uZoMJjXn M47hbQ+ndqlrS4uas5+jVpqOnp7oHB0dalMQNRFrUCLXeOD5BbUo0j9SyrPuJArZDKqm qC5Q== X-Forwarded-Encrypted: i=1; AFNElJ+2SxKSKc5O8Y6+46pmNwGz8JwKt1g4cF0VBCYsg3NE2A4jmrPeZH03mxI/udvQgayskiTWti8Z5zRH@nongnu.org X-Gm-Message-State: AOJu0YyVHLuu5RSZTQAnjiaX3IE3E4RjxqmiWZkPKCF7rucTEyE7wg22 /Ytm/ghdohK1+MnFkD34eFSHCXPT0GBnpXa/YRNuMXICX0yOP6mdBJVk X-Gm-Gg: Acq92OGjb3P+hgL+NiQV6UnR1Nvcv5sXOaw5YGw+EANjAskE9B3jgZE8seBW7czn1UG MytRpWqOnAEcrjnBn75sDHh9QYuQKU3WaFSGk0xrxoXSVR5P+p7d/DKtCSO8RDs9hjv3Xi6pPhk sJKwXxCfgWjzkCCk5ADHWWyVknNOGUInXHNsmH0b+ODnW9PNwMKpNTQLBhSnqsEuhzPuq1vwITz FkGSv+7Fy4M4vpKPLUxpuOlC7XnRqVeRoL7JqY9j18mzSDbaGqiK6RIYshXv6VkRNHdxFh4ctee 4963CLav0KeNyKCWn6SLByEK/o14va5ueqkVGkh7mZY3/jsBc1Hj/TS8nV4DS3sHUHPEjj+3hou e+wiAxGZB08BZ9/0Z61Og3JAnVky5Xxwnw2t9s/xf4LEhnr9gmkCs6CkuYFTUxjsbM8n9slsP8K i3jQIJTMuSPRWt4qHWbDvc6lcIL4OFspAKcnN0s83vySI+4WVPCs8hrZJc55iIcgkkqfYTrn+MH MrNbDLI8sMv+xiOHBZQpfEK X-Received: by 2002:a05:690c:4a11:b0:7bd:5af9:f0a2 with SMTP id 00721157ae682-7f7b5f52026mr122891037b3.14.1781482121917; Sun, 14 Jun 2026 17:08:41 -0700 (PDT) From: Kyle Fox To: Peter Maydell Cc: qemu-arm@nongnu.org, qemu-devel@nongnu.org, Kyle Fox Subject: [PATCH v2] target/arm: honour CCR.BFHFNMIGN for probed data BusFaults Date: Sun, 14 Jun 2026 19:08:35 -0500 Message-Id: <20260615000835.996870-1-kylefoxaustin.github@gmail.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260605035012.2876664-1-kylefoxaustin.github@gmail.com> References: <20260605035012.2876664-1-kylefoxaustin.github@gmail.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2607:f8b0:4864:20::1134; envelope-from=kylefoxaustin.github@gmail.com; helo=mail-yw1-x1134.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @gmail.com) X-ZM-MESSAGEID: 1781482184996158500 Content-Type: text/plain; charset="utf-8" M-profile CCR.BFHFNMIGN lets software executing at a negative execution priority (in HardFault/NMI, or with FAULTMASK set) suppress precise data BusFaults caused by load/store instructions: the access completes returning UNKNOWN data, the fault status is recorded in BFSR/BFAR, but no BusFault exception is taken. Software uses this to probe for the presence of a device. QEMU stored CCR.BFHFNMIGN but never consumed it: arm_cpu_do_transaction_ failed() always raised the external abort, which arm_v7m_cpu_do_interrupt() pended as a BusFault and then escalated to a HardFault it could not take at priority -1, aborting the VM with "Lockup: can't escalate 3 to HardFault". Honour the bit in arm_cpu_do_transaction_failed(): when the access is a data access from M-profile code at negative priority with BFHFNMIGN set, record PRECISERR/BFARVALID and BFAR and return without raising, so the faulting instruction completes instead of re-faulting forever. Instruction fetches are unaffected, since BFHFNMIGN applies only to data accesses. The SG instruction's stack-word load is also an AccType_NORMAL data access that must honour BFHFNMIGN, but QEMU performs it manually in v7m_read_sg_stack_word() (outside the TCG TLB, so it never reaches arm_cpu_do_transaction_failed()). Apply the same suppression there: on a BusFault, record the status and, when BFHFNMIGN is set at negative priority, return the UNKNOWN data instead of pending ARMV7M_EXCP_BUS. The remaining manual EXCP_BUS sites (vector-table loads, stacking, unstacking) are AccType_VECTABLE/STACK/UNSTACK and are not required to honour the bit, so they are left unchanged. This surfaced running the real NXP i.MX 95 System Manager firmware on the emulated Cortex-M33: its SystemMemoryProbe() (set BFHFNMIGN + FAULTMASK, do the access, test CFSR.BFARVALID) locked up the VM. With this change the SM's debug-monitor memory-probe commands run and recover correctly. Signed-off-by: Kyle Fox --- v2: - Also honour BFHFNMIGN for the SG instruction's stack-word load in v7m_read_sg_stack_word() (an AccType_NORMAL access performed manually, outside the TCG TLB), per review. The vector-table/stacking/unstacking EXCP_BUS sites are left unchanged (AccType_VECTABLE/STACK/UNSTACK). target/arm/tcg/m_helper.c | 12 ++++++++++++ target/arm/tcg/tlb_helper.c | 24 ++++++++++++++++++++++++ 2 files changed, 36 insertions(+) diff --git a/target/arm/tcg/m_helper.c b/target/arm/tcg/m_helper.c index f2059ed8b03..ba101ecb953 100644 --- a/target/arm/tcg/m_helper.c +++ b/target/arm/tcg/m_helper.c @@ -2086,6 +2086,18 @@ static bool v7m_read_sg_stack_word(ARMCPU *cpu, ARMM= MUIdx mmu_idx, env->v7m.cfsr[M_REG_NS] |=3D (R_V7M_CFSR_PRECISERR_MASK | R_V7M_CFSR_BFARVALID_MASK); env->v7m.bfar =3D addr; + /* + * The SG instruction's stack-word load is an AccType_NORMAL data + * access, so CCR.BFHFNMIGN applies: at negative execution priority + * with BFHFNMIGN set, the BusFault is suppressed -- the access + * completes returning UNKNOWN data (status recorded above), with = no + * BusFault exception pended. + */ + if ((env->v7m.ccr[M_REG_NS] & R_V7M_CCR_BFHFNMIGN_MASK) && + armv7m_nvic_neg_prio_requested(env->nvic, env->v7m.secure)) { + *spdata =3D value; + return true; + } armv7m_nvic_set_pending(env->nvic, ARMV7M_EXCP_BUS, false); return false; } diff --git a/target/arm/tcg/tlb_helper.c b/target/arm/tcg/tlb_helper.c index bbe1e70bc43..452688010f5 100644 --- a/target/arm/tcg/tlb_helper.c +++ b/target/arm/tcg/tlb_helper.c @@ -10,6 +10,7 @@ #include "helper.h" #include "internals.h" #include "cpu-features.h" +#include "hw/intc/armv7m_nvic.h" =20 /* * Returns true if the stage 1 translation regime is using LPAE format page @@ -318,8 +319,31 @@ void arm_cpu_do_transaction_failed(CPUState *cs, hwadd= r physaddr, MemTxResult response, uintptr_t retaddr) { ARMCPU *cpu =3D ARM_CPU(cs); + CPUARMState *env =3D &cpu->env; ARMMMUFaultInfo fi =3D {}; =20 + /* + * For M-profile, CCR.BFHFNMIGN lets software executing at a negative + * priority (in HardFault/NMI, or with FAULTMASK set) suppress precise + * data BusFaults from load/store instructions: the access completes + * returning UNKNOWN data (the store is dropped), the fault status is + * recorded in BFSR/BFAR, but no BusFault exception is taken. This is + * the mechanism software uses to probe for the presence of a device + * (e.g. the NXP System Manager's SystemMemoryProbe). Honour it by + * recording the status and returning without raising, so the faulting + * instruction completes rather than re-faulting forever. BFHFNMIGN + * applies only to data accesses, so instruction fetches are unaffecte= d. + */ + if (arm_feature(env, ARM_FEATURE_M) && + access_type !=3D MMU_INST_FETCH && + (env->v7m.ccr[M_REG_NS] & R_V7M_CCR_BFHFNMIGN_MASK) && + armv7m_nvic_neg_prio_requested(env->nvic, env->v7m.secure)) { + env->v7m.cfsr[M_REG_NS] |=3D + (R_V7M_CFSR_PRECISERR_MASK | R_V7M_CFSR_BFARVALID_MASK); + env->v7m.bfar =3D addr; + return; + } + /* now we have a real cpu fault */ cpu_restore_state(cs, retaddr); =20 --=20 2.34.1