From nobody Sat Jul 25 13:41:30 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linaro.org ARC-Seal: i=1; a=rsa-sha256; t=1784330641; cv=none; d=zohomail.com; s=zohoarc; b=DOy7c37sNxpZAH2B2EZ1fSxD6o/7/aalnF2Ak/OsHOMB7fMh3kotK47akYUKZ3lPQZCiLVTyfs8u5lSIq4NLCBAU5EN/JhoWHgpdwhstfsnNgYIUxRv0oTooPTk5HttFK+aeBxPybBOk0UInQ80Dty0pJFnZ04AZZiBAPVHpq1g= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784330641; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=0XTzqP1IaisVAsyNJ2xKnLKxlyIiY6j16WEFEoC9ZrU=; b=iwFJShPFnvmlsghv31iLSxkI2U+YRM/HsK4QQqZ0yQ0YcqfGZVvbQzqSkMpp8+gD9tDNZ9/iJDjdSMZHUW4QF1TavS3hldegsAL/W984JiBu08V1sjZI0GHXmMFL+oh47G3XjwgL/HcqWrChhHMR6gi43ZAc7TKGHHEOmhTbIAM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784330641671219.81227308542316; Fri, 17 Jul 2026 16:24:01 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wkrtj-0001SA-Hl; Fri, 17 Jul 2026 19:23:17 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkrth-0001Qb-Hg for qemu-devel@nongnu.org; Fri, 17 Jul 2026 19:23:13 -0400 Received: from mail-pj1-x1031.google.com ([2607:f8b0:4864:20::1031]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wkrtf-0006wz-5H for qemu-devel@nongnu.org; Fri, 17 Jul 2026 19:23:13 -0400 Received: by mail-pj1-x1031.google.com with SMTP id 98e67ed59e1d1-38df94d4dd8so3595868a91.2 for ; Fri, 17 Jul 2026 16:23:10 -0700 (PDT) Received: from stoup.. ([32.140.233.50]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13ce2a18a47sm8186261c88.8.2026.07.17.16.23.08 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 17 Jul 2026 16:23:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1784330590; x=1784935390; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=0XTzqP1IaisVAsyNJ2xKnLKxlyIiY6j16WEFEoC9ZrU=; b=oa9ZbTDEAN+yiZv9Szfjf43LT1OWCBve71lURXs30so0gMO+9qWnPvo4inAHapKuWY WPJ3Pw9AeSc9+stsIb2BUesSm2aFn5q0Ba3KAiO+Mhb6kh7AOibTIRFqsXMcVe0/C6n+ sSgAq5woShbidEFVBDr5BW1b1OXbH5niIxADfmK3MjG28bRVq3J6MCxsIIBZPqFc1Zk/ HQXjXk9adu7X9MhGOAbBWLtINkqc5WyTs8vCiWKxEjalauabGJFrPUcblyxKLvNCp/jr 8cmb5vYNuVN6XQ4a5HQdvQQ9YjPLzVotBY94cxu3iFSX6llG0XcyxJIjoM3u2RA2FGq9 6WWQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784330590; x=1784935390; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=0XTzqP1IaisVAsyNJ2xKnLKxlyIiY6j16WEFEoC9ZrU=; b=gLXoIJ1RMZlpx8zzn2NBgNAtlNAMGMQuTuAvAcqHhmRvqlsy01aGt95zVoFzP35zEc y4sm0/41BBUzVouoEtIGtGuWNz0pkdYNWT24XKNl5xL0y5bQaYQ5pYsFPtXJDhLZydOO WWD8b2Ed24321m6HD1rhKcYsAT4R8L/ua/VEJDUp2Ez3bxgcwkYMRl2fGE3W9tE6OUlF gG7IJf1kAqNn1vMmX2e8DdXhnseB5iC2vX871iylq/4ERJD0H50qlxLz8sup0+3M9Xgt whzxzl3C1wCVMBLBMBJk3a33EU2QB2bGNodXGooDPEdGm0yFge1qeueL691RGtjxpTJY 5O/w== X-Gm-Message-State: AOJu0YxEjD5TGbWPvexuXnMfON+sKHYY4jtPqn7aILKg83rlFtsNYnU4 5gPYJ7X3RdWABH6FG1tAerJ39G1LNV9rX5ooPmsavoabQUnAdHHuxzmkVMxz57wxdj6GkI/DI+2 YqZb6 X-Gm-Gg: AfdE7cn7uEvtIZ6XUwK+blgd9eleV2rsymdjjn658PqyNAXoY4KfYiINGFZl0RsMAHk 5uVZLF3V20ZL4dPZMOK0VXR8JOBUYzRb/tc7KIReVpLQv5BvxJwmEn9v8jK/sKrMIv/0cYkWPtQ 4pdwLhau3muufR10rLTRI2cnrFUDoT5Xq0IyPKZhwFdYzQwbELLu1r9LdRu+kf+L8h9BqKDq79Z 7cIlMTYnvStZ1sX/+aP23jNxLp3m2fOeJRxNBwYUVgXw2xSKNuvr3ufQENrjYTYWTalbCJJp2Xx q0HcpUqT0PyU6Uf21I9bzbKN4m5lVGvZnwpLsPf2MI+iO9D1y0P/XOhYFFOPHY/WcBCJBMYod2P qVG+bqUo7XY/cnFbWggqJGvv+IVf52fhJ6zmNEHYgWpZw8EFwTWUicfin5f5wwn5TmkJLuI7doe LI8oRAwEg= X-Received: by 2002:a17:90b:2e46:b0:38e:2a4:cffc with SMTP id 98e67ed59e1d1-38e4b507f42mr4855302a91.25.1784330589626; Fri, 17 Jul 2026 16:23:09 -0700 (PDT) From: Richard Henderson To: qemu-devel@nongnu.org Cc: qemu-arm@nongnu.org Subject: [PATCH 01/17] include/user/guest-host: Include exec/abi_ptr.h Date: Fri, 17 Jul 2026 16:22:48 -0700 Message-ID: <20260717232306.378988-2-richard.henderson@linaro.org> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260717232306.378988-1-richard.henderson@linaro.org> References: <20260717232306.378988-1-richard.henderson@linaro.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2607:f8b0:4864:20::1031; envelope-from=richard.henderson@linaro.org; helo=mail-pj1-x1031.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linaro.org) X-ZM-MESSAGEID: 1784330644618158500 Content-Type: text/plain; charset="utf-8" The COMPILING_PER_TARGET block uses the abi_ptr type without including the proper header. Signed-off-by: Richard Henderson Reviewed-by: Philippe Mathieu-Daud=C3=A9 --- include/user/guest-host.h | 1 + 1 file changed, 1 insertion(+) diff --git a/include/user/guest-host.h b/include/user/guest-host.h index 506efc097e..f136f81f5d 100644 --- a/include/user/guest-host.h +++ b/include/user/guest-host.h @@ -80,6 +80,7 @@ static inline bool guest_range_valid_untagged_vaddr(vaddr= start, vaddr len) }) =20 #ifdef COMPILING_PER_TARGET +#include "exec/abi_ptr.h" =20 /* * These functions take the guest virtual address as an abi_ptr. This --=20 2.43.0 From nobody Sat Jul 25 13:41:30 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linaro.org ARC-Seal: i=1; a=rsa-sha256; t=1784330794; cv=none; d=zohomail.com; s=zohoarc; b=Z22/xVBQ6Dn4OHDvQ/KeqpXHXFP9w52IiUXBBN1kr4gixk22R/SM1J3o2qR7ULJ37MXPF9GJckZp2aBp1k0xvPnU0ov60QaA38RQjLnDYw1c4pZbq7N4oKbruWOpEL0NA7vUh6sxDjQB4GDcIMRTlf2KQcA82U+40QMCL1PWc1A= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784330794; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=DLlDGxtFFW3g2iYlBDYJu83t+bys0fFHlAOwYxW5TVQ=; b=Cdw0xdEvw96qpTHTzJYyFzrWCyTkIuCbPwI4POXskCXP/DtMiIgwuo+iQkX/J9mzlX+G0UNNTIMfI7am54VKrUTjROkanrauzvCN9aCJ/CBfu2S1vswJwoy1Fr3TusVVHT4EfQkt4faUOXTr8hbPLHfVK4M3eI1Y7KEwrL9zh+w= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784330794793659.5236725321314; Fri, 17 Jul 2026 16:26:34 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wkrtp-0001UF-6x; Fri, 17 Jul 2026 19:23:21 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkrtj-0001Ru-8T for qemu-devel@nongnu.org; Fri, 17 Jul 2026 19:23:15 -0400 Received: from mail-pj1-x1035.google.com ([2607:f8b0:4864:20::1035]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wkrth-0006xS-Cn for qemu-devel@nongnu.org; Fri, 17 Jul 2026 19:23:14 -0400 Received: by mail-pj1-x1035.google.com with SMTP id 98e67ed59e1d1-384930ca5e2so8057085a91.3 for ; Fri, 17 Jul 2026 16:23:13 -0700 (PDT) Received: from stoup.. ([32.140.233.50]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13ce2a18a47sm8186261c88.8.2026.07.17.16.23.10 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 17 Jul 2026 16:23:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1784330592; x=1784935392; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=DLlDGxtFFW3g2iYlBDYJu83t+bys0fFHlAOwYxW5TVQ=; b=xD/8HEMX6QCkkdbQ7teHj7vv/S//pXo0xcSAYvvTOXD5fQTGn6y8x/Jl6AMnGrEwNb HxavYc5xE3eojJ8qWDllxp5R2aNdQV5vs92vPyfihtUcUzNgh19ViyZejHcRStLMducO RRIREbr00kftYGPsgLvoH3riQYk5v1FohZe0umVA0Ofc3VdDN8jqeWSElP2Kltb7KxgX AVh0gqN3h9seGmeVwdP1ySfVjZMl8weo3tzQkVhDjHvvudFGzU009ERRk3RrjKMh995t jz1FQLpr5LWHKeGh4MfvmSW2VU37uoByc1DOUboCmbO2jHsQgLtCNZNP5+ZTLi8y1MJh GU+Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784330592; x=1784935392; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=DLlDGxtFFW3g2iYlBDYJu83t+bys0fFHlAOwYxW5TVQ=; b=r4+qxHlDMohTTP/sfgUPCgfBGh5PZq1fpwWSzRF9JL6MxgJlfClC5mnYy+WawCC1fE /QoSJZlABHyFap+OgvPcmOHTNoSSYek6nStyZQqGnjWPPjyxMp+hD89hhG2a9QSQc193 oAkpI5x7+Ymd8EvbE9nE5An8AeL+GYOzJOnlBn/SLLOHGTAlvNGBvSfkVs7+I4SkgAT0 waUA5U7VHkO0iLmFPJ4N9AYx2C+N1K5aPnVbALAFH28gTWNTSqAP/aGYnxKoU/x9t1DM 5ReAeLCoWeb2eyr9gBgQwo7KXIXRmQq+H7lWU4Lkf5u57matLDZXtFHjAfsc666vPa4S K/QA== X-Gm-Message-State: AOJu0YzL/bwd31oIsTgNg1dLcgs1jDycb962EmCBGgwBcg6vwTehqbs7 zho0uA7CyfB5m/0ryGwN4AUqrlTGqiHMoc7RO+5DpIf1YIxwiK3+BdY44Ebbg0KjNpCld5YGXjQ rI9+K X-Gm-Gg: AfdE7clUPLA0hv5bkCXYtC9SHzCGJcSl3JKHOzMM6RoMkESlzqfr8HnrTMlRJavjM2i ojenz5Zz9gvtiJ4o80juHYhtDYbT8U/B8mvNQNSifG3rzHoflmSnpSsVsWOi2VviI7lRDg1Rf75 fh5cQViHke3oVNPVL9m6VKN2SzcZ6zBFMVvHqusLziQeuHAtvILCrPAy5qj3r5FGr0g+tk7eB3n yueZrewYXudS9nGFCZlKZzS4/65ahkbaSfiXpOd549GeM7Fqdr0GwxWLl/Q9jRpSEeqorr3u31j lO1HZ377kqns0o7QxJ6PorOfrf/rxubeRCUxg67k8mWTIanCTz6y5mnfbgJ/YdUUEyYVZ+WjSgB DINKFzhCWGzP61/kteKATk7xDCJxcOT4rVsRkkXDf0LUvqcnEb9BglP7HRQ7ZqAouQuEyCA2LqA /UOVseaQ0= X-Received: by 2002:a17:90b:1a90:b0:38d:c834:24cf with SMTP id 98e67ed59e1d1-38e4b53433bmr4965963a91.23.1784330591800; Fri, 17 Jul 2026 16:23:11 -0700 (PDT) From: Richard Henderson To: qemu-devel@nongnu.org Cc: qemu-arm@nongnu.org Subject: [PATCH 02/17] target/arm: Fix testing of raw mtx value Date: Fri, 17 Jul 2026 16:22:50 -0700 Message-ID: <20260717232306.378988-4-richard.henderson@linaro.org> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260717232306.378988-1-richard.henderson@linaro.org> References: <20260717232306.378988-1-richard.henderson@linaro.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2607:f8b0:4864:20::1035; envelope-from=richard.henderson@linaro.org; helo=mail-pj1-x1035.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linaro.org) X-ZM-MESSAGEID: 1784330796498158500 Content-Type: text/plain; charset="utf-8" MTX is always a pair of bits, one for each half of the address space. Testing it like a boolean is incorrect. Introduce raw_mte_check, a mirror of the similar mte_check function that applies when MTX is passed in MTEDESC. Fixes: 8912ceced815 ("target/arm: load on canonical tag loads ext bits") Signed-off-by: Richard Henderson --- target/arm/tcg/mte_helper.c | 25 +++++++++++++++++-------- 1 file changed, 17 insertions(+), 8 deletions(-) diff --git a/target/arm/tcg/mte_helper.c b/target/arm/tcg/mte_helper.c index dca4ef5a94..ad4ad5b4cc 100644 --- a/target/arm/tcg/mte_helper.c +++ b/target/arm/tcg/mte_helper.c @@ -317,6 +317,12 @@ int load_tag1(uint64_t ptr, uint8_t *mem) return extract32(*mem, ofs, 4); } =20 +/* Like mtx_check, but simple mtx bit pair instead of MTEDESC. */ +static bool raw_mtx_check(unsigned mtx, unsigned bit55) +{ + return (mtx >> bit55) & 1; +} + uint64_t HELPER(ldg)(CPUARMState *env, uint64_t ptr, uint64_t xt, uint32_t= mtx) { int mmu_idx =3D arm_env_mmu_index(env); @@ -330,9 +336,11 @@ uint64_t HELPER(ldg)(CPUARMState *env, uint64_t ptr, u= int64_t xt, uint32_t mtx) /* Load if page supports tags. */ if (mem) { rtag =3D load_tag1(ptr, mem); - } else if (mtx) { - uint64_t bit55 =3D extract64(ptr, 55, 1); - rtag =3D 0xF * bit55; + } else { + bool bit55 =3D extract64(ptr, 55, 1); + if (raw_mtx_check(mtx, bit55)) { + rtag =3D 0xF * bit55; + } } =20 return address_with_allocation_tag(xt, rtag); @@ -387,7 +395,7 @@ static inline void do_stg(CPUARMState *env, uint64_t pt= r, uint64_t xt, /* Store if page supports tags. */ if (mem) { store1(ptr, mem, allocation_tag_from_addr(xt)); - } else if (mtx) { + } else if (raw_mtx_check(mtx, extract64(ptr, 55, 1))) { canonical_tag_write_fail(env, ptr, ra); } } @@ -420,6 +428,7 @@ static inline void do_st2g(CPUARMState *env, uint64_t p= tr, uint64_t xt, uint8_t *mem1, *mem2; =20 check_tag_aligned(env, ptr, ra); + mtx =3D raw_mtx_check(mtx, extract64(ptr, 55, 1)); =20 /* * Trap if accessing an invalid page(s). @@ -504,8 +513,8 @@ uint64_t HELPER(ldgm)(CPUARMState *env, uint64_t ptr, u= int32_t mtx) /* The tag is squashed to zero if the page does not support tags. */ if (!tag_mem) { /* Load canonical value if mtx is set (untagged memory region) */ - if (mtx) { - bool bit55 =3D extract64(ptr, 55, 1); + bool bit55 =3D extract64(ptr, 55, 1); + if (raw_mtx_check(mtx, bit55)) { ret =3D extract64(-bit55, 0, 1 << gm_bs); shift =3D extract64(ptr, LOG2_TAG_GRANULE, 4) * 4; return ret << shift; @@ -573,7 +582,7 @@ void HELPER(stgm)(CPUARMState *env, uint64_t ptr, uint6= 4_t val, uint32_t mtx) */ if (!tag_mem) { /* Storing tags to canonically tagged region: fault. */ - if (mtx) { + if (raw_mtx_check(mtx, extract64(ptr, 55, 1))) { canonical_tag_write_fail(env, ptr, ra); } return; @@ -630,7 +639,7 @@ void HELPER(stzgm_tags)(CPUARMState *env, uint64_t ptr,= uint64_t val, if (mem) { int tag_pair =3D (val & 0xf) * 0x11; memset(mem, tag_pair, tag_bytes); - } else if (mtx) { + } else if (raw_mtx_check(mtx, extract64(ptr, 55, 1))) { canonical_tag_write_fail(env, ptr, ra); } } --=20 2.43.0 From nobody Sat Jul 25 13:41:30 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linaro.org ARC-Seal: i=1; a=rsa-sha256; t=1784330829; cv=none; d=zohomail.com; s=zohoarc; b=D1TNXbiHWDmg5/R+hQAwQTihqIz52vnCLGG5LjLcO/AyfsSssqtQKbY3x702/pLl2wu8Wj2PVSn+UzazcTi0mzh5+0c/ijv7aMT4E4V/oQKnFhH5wvHFr5fIIIm7EKDxtwjUb94Kcj791Q3VxadSSDZiLkg3US6c1icZ9xZyqdE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784330829; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=/3aFVhh4R0lFQSwDx2BhLx8jPqJaBt2/8J/G1SbTklc=; b=RzoE2/RVM6zItEiqGv4753YR0AcHu36qBhrhANzpQKaLMjV4rj59yU4ZX3TO4/hhvg415AjA/O5FPduy5N7Pebqxnzu3UafZ8TN5ad6H4IsXzvUGOwL9H5H4uKSCNfSqHaPDzSyOAr5m+TGgn1XT5SPPla4hVhXAq7t7PzcK03A= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784330829794844.0312967707968; Fri, 17 Jul 2026 16:27:09 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wkrtr-0001Vq-30; Fri, 17 Jul 2026 19:23:23 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkrtk-0001SI-Fp for qemu-devel@nongnu.org; Fri, 17 Jul 2026 19:23:17 -0400 Received: from mail-pj1-x102d.google.com ([2607:f8b0:4864:20::102d]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wkrti-0006xp-Hk for qemu-devel@nongnu.org; Fri, 17 Jul 2026 19:23:16 -0400 Received: by mail-pj1-x102d.google.com with SMTP id 98e67ed59e1d1-381c51fde6bso8331347a91.2 for ; Fri, 17 Jul 2026 16:23:14 -0700 (PDT) Received: from stoup.. ([32.140.233.50]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13ce2a18a47sm8186261c88.8.2026.07.17.16.23.12 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 17 Jul 2026 16:23:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1784330593; x=1784935393; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=/3aFVhh4R0lFQSwDx2BhLx8jPqJaBt2/8J/G1SbTklc=; b=j97965/CssragNDEUxROdPlZhyrQxNdGcJOxcQ6+qd+ADb+ovE5FxOQP+5PeJXADqk zRxNlWsky0tnoO6BJlHtpUb3sbLgNhDfSncOMNOZtcKYW5yiu6L1ibwnWYQQLmq7CYov BuddXvmXXiS/whq6WJYNlYVOAWNbpKrpps1i3lAW4Eqchs3JLg7HQ4qHtZ2JfRm4XAbP JZD5uwMru8+nrr/9ArqiRhKTGAWB6nPAaeW2KqOCthjH/+PuITdN6OAkiBa2Zgc8gbQF j52Bm3FgR78BxashExAiMa+r3eEKey34NbKJgJlM9KdTpkXYU6lqCs/hAm2tqPTLSqyV JrZA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784330593; x=1784935393; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=/3aFVhh4R0lFQSwDx2BhLx8jPqJaBt2/8J/G1SbTklc=; b=IVoqCoKqjflC6BWINk/b9LxoCHxdmgPhgLDPlUSiUGa/Yp7LYA5k7tk4Z0y3I5K5MP Zh77luqiMgg9mgEJP3ChM6sJ50OXRiyUBSeLdSjvQH2ag/WQTZi5waI57GUWMr9ToHUX CuXSV85/vo3nXHTrUnNbKRkx8YnW7xf026XmwmoxwkC0m+38u2Fmfgl0dIlSolQb0igm TtDnS4bYK4GChGRRdt+hQPtyn1hfxNFyNa9nc3KAoQ5VZUN+AWam32W7lLth9DrgIirP prvoopeYqTpPBbA+lOBHl8jYQ1CacgtFBpdZYluuQHHaQYnusSi7QyfVL8KtLMd+B/nc YOLA== X-Gm-Message-State: AOJu0Ywb6j7YT+S3BstqoFVottBq1qtJLVo+QSeDTb1JZyELAYVBQi2g VMK+4vroXREMZJfuXWw2uavTJPY1qHjwgF1J2GmztS63lEkwfwV7jvfJuKE1kFUlb41PzeR6tts jFADQ X-Gm-Gg: AfdE7cmVC7m6IPzpEyOQ+jtfrvlh/3oT+O4bU/KByr8kc6S1cnz0bNyYTxYL+QCFSyX q7fUwoHpUFO4gDUwdWKOXNJHhfo9RGjvcz9McsdIomZMa9hks831vHNo9WT7tVrXkesopb6O6/t rkuJmgyAUAUp9dbnTF6rtUlAldcf4sIZ4QHd/2neO5W9/VqR4o5LG/rtWNByZumasXQ6BhnIH0l igtDPnfmT2ls1eViiBhrrB9UCfI4M7fBUj2mdz6du9VTcX9aGT8wFGbF6ShXFOD9mhj4tdWXp8X Y/o0uH4gchlFxg1MfqbgVsPxLIQ5bb2hBQ5wjqu/gnylfs4nRqlFGqQf6SweKDvbV+kP50wp/KN HIrfMgK/fILrtI/cglCXR7BoVXhKM1AyVYfbddJ6ax8IqJP7NQBNpWh1GQvueFB0XCa4jsJ8VBS SOMWn5s54= X-Received: by 2002:a17:90b:5288:b0:38e:3542:212 with SMTP id 98e67ed59e1d1-38e4b4462f1mr4681781a91.13.1784330592995; Fri, 17 Jul 2026 16:23:12 -0700 (PDT) From: Richard Henderson To: qemu-devel@nongnu.org Cc: qemu-arm@nongnu.org Subject: [PATCH 03/17] target/arm: Move helper_dc_zva to mte_helper.c Date: Fri, 17 Jul 2026 16:22:51 -0700 Message-ID: <20260717232306.378988-5-richard.henderson@linaro.org> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260717232306.378988-1-richard.henderson@linaro.org> References: <20260717232306.378988-1-richard.henderson@linaro.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2607:f8b0:4864:20::102d; envelope-from=richard.henderson@linaro.org; helo=mail-pj1-x102d.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linaro.org) X-ZM-MESSAGEID: 1784330830704158500 Content-Type: text/plain; charset="utf-8" Slightly odd, perhaps, but there are 3 MTE variations of DC_ZVA and this is the easiest way to share code. Signed-off-by: Richard Henderson --- target/arm/tcg/helper-a64.c | 50 ------------------------------------ target/arm/tcg/mte_helper.c | 51 +++++++++++++++++++++++++++++++++++++ 2 files changed, 51 insertions(+), 50 deletions(-) diff --git a/target/arm/tcg/helper-a64.c b/target/arm/tcg/helper-a64.c index 05ab9ab6d3..63ef6d90ec 100644 --- a/target/arm/tcg/helper-a64.c +++ b/target/arm/tcg/helper-a64.c @@ -786,56 +786,6 @@ illegal_return: } #endif /* !CONFIG_USER_ONLY */ =20 -void HELPER(dc_zva)(CPUARMState *env, uint64_t vaddr_in) -{ - uintptr_t ra =3D GETPC(); - - /* - * Implement DC ZVA, which zeroes a fixed-length block of memory. - * Note that we do not implement the (architecturally mandated) - * alignment fault for attempts to use this on Device memory - * (which matches the usual QEMU behaviour of not implementing either - * alignment faults or any memory attribute handling). - */ - int blocklen =3D 4 << get_dczid_bs(env_archcpu(env)); - uint64_t vaddr =3D vaddr_in & ~(blocklen - 1); - int mmu_idx =3D arm_env_mmu_index(env); - void *mem; - - /* - * Trapless lookup. In addition to actual invalid page, may - * return NULL for I/O, watchpoints, clean pages, etc. - */ - mem =3D tlb_vaddr_to_host(env, vaddr, MMU_DATA_STORE, mmu_idx); - -#ifndef CONFIG_USER_ONLY - if (unlikely(!mem)) { - /* - * Trap if accessing an invalid page. DC_ZVA requires that we sup= ply - * the original pointer for an invalid page. But watchpoints requ= ire - * that we probe the actual space. So do both. - */ - (void) probe_write(env, vaddr_in, 1, mmu_idx, ra); - mem =3D probe_write(env, vaddr, blocklen, mmu_idx, ra); - - if (unlikely(!mem)) { - /* - * The only remaining reason for mem =3D=3D NULL is I/O. - * Just do a series of byte writes as the architecture demands. - */ - for (int i =3D 0; i < blocklen; i++) { - cpu_stb_mmuidx_ra(env, vaddr + i, 0, mmu_idx, ra); - } - return; - } - } -#endif - - set_helper_retaddr(ra); - memset(mem, 0, blocklen); - clear_helper_retaddr(); -} - void HELPER(arm_unaligned_access)(CPUARMState *env, uint64_t addr, uint32_t access_type, uint32_t mmu_idx) { diff --git a/target/arm/tcg/mte_helper.c b/target/arm/tcg/mte_helper.c index ad4ad5b4cc..993aba5df4 100644 --- a/target/arm/tcg/mte_helper.c +++ b/target/arm/tcg/mte_helper.c @@ -32,6 +32,7 @@ #endif #include "accel/tcg/cpu-ldst.h" #include "accel/tcg/probe.h" +#include "accel/tcg/helper-retaddr.h" #include "helper-a64.h" #include "exec/tlb-flags.h" #include "accel/tcg/cpu-ops.h" @@ -1017,6 +1018,56 @@ bool mte_probe(CPUARMState *env, uint32_t desc, uint= 64_t ptr) return ret !=3D 0; } =20 +void HELPER(dc_zva)(CPUARMState *env, uint64_t vaddr_in) +{ + uintptr_t ra =3D GETPC(); + + /* + * Implement DC ZVA, which zeroes a fixed-length block of memory. + * Note that we do not implement the (architecturally mandated) + * alignment fault for attempts to use this on Device memory + * (which matches the usual QEMU behaviour of not implementing either + * alignment faults or any memory attribute handling). + */ + int blocklen =3D 4 << get_dczid_bs(env_archcpu(env)); + uint64_t vaddr =3D vaddr_in & ~(blocklen - 1); + int mmu_idx =3D arm_env_mmu_index(env); + void *mem; + + /* + * Trapless lookup. In addition to actual invalid page, may + * return NULL for I/O, watchpoints, clean pages, etc. + */ + mem =3D tlb_vaddr_to_host(env, vaddr, MMU_DATA_STORE, mmu_idx); + +#ifndef CONFIG_USER_ONLY + if (unlikely(!mem)) { + /* + * Trap if accessing an invalid page. DC_ZVA requires that we sup= ply + * the original pointer for an invalid page. But watchpoints requ= ire + * that we probe the actual space. So do both. + */ + (void) probe_write(env, vaddr_in, 1, mmu_idx, ra); + mem =3D probe_write(env, vaddr, blocklen, mmu_idx, ra); + + if (unlikely(!mem)) { + /* + * The only remaining reason for mem =3D=3D NULL is I/O. + * Just do a series of byte writes as the architecture demands. + */ + for (int i =3D 0; i < blocklen; i++) { + cpu_stb_mmuidx_ra(env, vaddr + i, 0, mmu_idx, ra); + } + return; + } + } +#endif + + set_helper_retaddr(ra); + memset(mem, 0, blocklen); + clear_helper_retaddr(); +} + /* * Perform an MTE checked access for DC_ZVA. */ --=20 2.43.0 From nobody Sat Jul 25 13:41:30 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linaro.org ARC-Seal: i=1; a=rsa-sha256; t=1784330785; cv=none; d=zohomail.com; s=zohoarc; b=FOPzYYlH/B+IEGjGiUD48V2IPQpW8we4mrc6xp/0OJn8wZ/Ov7qQtKHHv4ggDrGyJbl0u2ceyOZUfhCz6IQBUNXjtJ60HWYLXKNPPtLtzibtslwytlwBbTQISRfRoxWb3L1QZojVDYJXqqFfeenf5lTzucCLSWCLzjlQxuDNC4E= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784330785; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=/PwnvtkmnND82rvGSpVtWGJUQzkpj2nFU1NpSAxz+X8=; b=gvuloisQMVS47Mng4iRoN7UBhz73NDoi5fqtxyw+VjOcE8zB11J4nuMLsW7LtqbvfzmlFSAnyAhMl5TNGjMHtoH88JpBRJWHgLGwFjgIy/OQwelymKpGbRoPnfwDUnujdHm2ocqxuHVVExHsQCKpUweAL8hneLZ1LktBE30BUBI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784330785007985.7029980807587; Fri, 17 Jul 2026 16:26:25 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wkrto-0001Tk-Tv; Fri, 17 Jul 2026 19:23:20 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkrtl-0001ST-FS for qemu-devel@nongnu.org; Fri, 17 Jul 2026 19:23:17 -0400 Received: from mail-pg1-x535.google.com ([2607:f8b0:4864:20::535]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wkrtj-0006y7-Gf for qemu-devel@nongnu.org; Fri, 17 Jul 2026 19:23:17 -0400 Received: by mail-pg1-x535.google.com with SMTP id 41be03b00d2f7-c95d0a54ea5so6147862a12.0 for ; Fri, 17 Jul 2026 16:23:15 -0700 (PDT) Received: from stoup.. ([32.140.233.50]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13ce2a18a47sm8186261c88.8.2026.07.17.16.23.13 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 17 Jul 2026 16:23:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1784330594; x=1784935394; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=/PwnvtkmnND82rvGSpVtWGJUQzkpj2nFU1NpSAxz+X8=; b=kqvYNqKAKpv3g2TWyWCCG4/odR94j97paC72MzC6wSBx6AXSd1kwmhrjzd2nWOaGwL 6J9t1zQWjRgmshJk62h0Ph506TxgPuMV3hTJC1bwSSAayyhVa2PNM+JwK4nQ1Huu9XJQ NXqyQ8wBR8PsLvrgqFxLXtQzF/fV1MOWTCV8CguSdnBclXb6jlFPHKYWsc+7v0gCah5c fBREW3k3XqQ0PxpRV8kCN8lUnmYZy57NESgqMqYj2KPmmhgMxLcVsfEe4B8C8dTK3pRz nbiHUauCT9Ok9++bz1mCgLbBN3TQsTBKQyyNL0Lq2xl/E7NvIryCPese/1eKFvb7MNjA R3SA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784330594; x=1784935394; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=/PwnvtkmnND82rvGSpVtWGJUQzkpj2nFU1NpSAxz+X8=; b=EXtbKycQk2SZuZDZsClRaR8+XiGb5mvRzqmEDUFjR3vBHDtXT8Vbucczd3sekC5kf3 FPwSRQ6VdCW3ZaSRI+MBpUrL32CxZiwIZcsw7jHR6QsvxUXr4oS2n0APUgzdu9GdjWeD Gu4Tpy+6YWnlBjuepLIy09aRHUptS7TBgak2qQFB8ouRRnJwTBLqrTE9AgVftGmEoFqX D9dLpNU6uyzHd36CV3YuAcVOkcw+epdAGxZ+BcLMMzM84FkIka1h2SaW7Fw9NuskQIuF F5CyHmmp1gONzOMm4Ps3RgWL9A3IW0jrbhKvNXjTsUnwH6rWBWVF4CPYQs4idpQdKepB nwnQ== X-Gm-Message-State: AOJu0YxwSihrUorX8jfhfHzqVRI9olYcjGss1erknaWi2sM5aVPFsuwL xd8I4GxN5SP+5x6rmNEfFSwwie9F30at9nvOBljnEhSkUmzMVhK7aM5uYF92OdeE/HTIqMD0CMI mu0Qh X-Gm-Gg: AfdE7ckbjL04FbYTweEXRDjxk7IrwrrmDZzQgQu+a80mqnOug+qoZtYJ3neuGM8eAZt yISbqMx/d0M1PXS+3BDbhHAsvUaQg0s+Dt7qMmJn6yxCTURao/7T9CQyhCK7v5B8fo+wA+OL8xj lTAnq+ag6XagOGGjOx2Tx9oMyRiVRjpHDBhwmpxdnDlUQt4zhSPZ5m7Z7CN9HHxDOe09dcH6/gN 3taT6XWjXyLTSK2WbMvwEkb8RcKY1zFnaDnHpzHltJvBh/BrKRGQA32HNA1UyBLYe7eKwB3ysJj ow5Zdx9SN/iqpDLxIEGqZPffsVxKOf08Epb8cly1MxxgdoOKGtwBGsTQNjNtC1pMNgGz2fHeU00 OBwhWo/c3yezGWFhEXsDBE9Z5xR4HLHoFsrvgTsAJxRh5bZAafcYG2qzvDt+KQWcsQY2XV3AyJ6 ptrPOS3+YD76exiGr2zg== X-Received: by 2002:a17:90a:d40f:b0:38e:542:6485 with SMTP id 98e67ed59e1d1-38e4b4461e1mr4744360a91.12.1784330594032; Fri, 17 Jul 2026 16:23:14 -0700 (PDT) From: Richard Henderson To: qemu-devel@nongnu.org Cc: qemu-arm@nongnu.org Subject: [PATCH 04/17] target/arm: Raise alignment fault for DC_ZVA on Device memory Date: Fri, 17 Jul 2026 16:22:52 -0700 Message-ID: <20260717232306.378988-6-richard.henderson@linaro.org> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260717232306.378988-1-richard.henderson@linaro.org> References: <20260717232306.378988-1-richard.henderson@linaro.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2607:f8b0:4864:20::535; envelope-from=richard.henderson@linaro.org; helo=mail-pg1-x535.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linaro.org) X-ZM-MESSAGEID: 1784330786545158500 Content-Type: text/plain; charset="utf-8" Raise alignment fault when DC_ZVA targets Device memory, as required by the architecture. With MTE, an alignment exception is not always correctly ordered vs a tag check fail exception -- to be fixed in followup patches. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3005 Signed-off-by: Richard Henderson --- target/arm/tcg/mte_helper.c | 104 ++++++++++++++++++++++-------------- 1 file changed, 65 insertions(+), 39 deletions(-) diff --git a/target/arm/tcg/mte_helper.c b/target/arm/tcg/mte_helper.c index 993aba5df4..dc87dc283f 100644 --- a/target/arm/tcg/mte_helper.c +++ b/target/arm/tcg/mte_helper.c @@ -1018,56 +1018,82 @@ bool mte_probe(CPUARMState *env, uint32_t desc, uin= t64_t ptr) return ret !=3D 0; } =20 -void HELPER(dc_zva)(CPUARMState *env, uint64_t vaddr_in) +/* Traps for DC_ZVA, DC_GVA, and friends, after successful page lookup. */ +static int do_dcxva_traps(CPUARMState *env, vaddr addr, size_t len, int mm= u_idx, + int flags, MemTxAttrs attrs, uintptr_t ra) { - uintptr_t ra =3D GETPC(); - - /* - * Implement DC ZVA, which zeroes a fixed-length block of memory. - * Note that we do not implement the (architecturally mandated) - * alignment fault for attempts to use this on Device memory - * (which matches the usual QEMU behaviour of not implementing either - * alignment faults or any memory attribute handling). - */ - int blocklen =3D 4 << get_dczid_bs(env_archcpu(env)); - uint64_t vaddr =3D vaddr_in & ~(blocklen - 1); - int mmu_idx =3D arm_env_mmu_index(env); - void *mem; - - /* - * Trapless lookup. In addition to actual invalid page, may - * return NULL for I/O, watchpoints, clean pages, etc. - */ - mem =3D tlb_vaddr_to_host(env, vaddr, MMU_DATA_STORE, mmu_idx); - #ifndef CONFIG_USER_ONLY - if (unlikely(!mem)) { - /* - * Trap if accessing an invalid page. DC_ZVA requires that we sup= ply - * the original pointer for an invalid page. But watchpoints requ= ire - * that we probe the actual space. So do both. - */ - (void) probe_write(env, vaddr_in, 1, mmu_idx, ra); - mem =3D probe_write(env, vaddr, blocklen, mmu_idx, ra); + /* + * DC_ZVA traps on pages without caching enabled. This can be either + * pages mapped as Device, or when the mmu is disabled entirely. + * We have already detected such pages and have set TLB_CHECK_ALIGNED + * so that unaligned accesses are trapped under the same conditions. + */ + if (unlikely(flags & TLB_CHECK_ALIGNED)) { + arm_cpu_do_unaligned_access(env_cpu(env), addr, MMU_DATA_STORE, + mmu_idx, ra); + } =20 - if (unlikely(!mem)) { - /* - * The only remaining reason for mem =3D=3D NULL is I/O. - * Just do a series of byte writes as the architecture demands. - */ - for (int i =3D 0; i < blocklen; i++) { - cpu_stb_mmuidx_ra(env, vaddr + i, 0, mmu_idx, ra); - } - return; + /* Watchpoints have lower priority than alignment faults. */ + if (unlikely(flags & TLB_WATCHPOINT)) { + cpu_check_watchpoint(env_cpu(env), addr & -len, len, + attrs, BP_MEM_WRITE, ra); + flags &=3D ~TLB_WATCHPOINT; + } +#endif + return flags; +} + +static void do_dczva_0(CPUARMState *env, vaddr addr, size_t len, void *mem, + int mmu_idx, int flags, uintptr_t ra) +{ +#ifndef CONFIG_USER_ONLY + /* + * There are a couple of cases where QEMU wants the slow path; + * just do a series of byte writes as the architecture demands. + */ + if (unlikely(flags)) { + for (size_t i =3D 0; i < len; i++) { + cpu_stb_mmuidx_ra(env, addr + i, 0, mmu_idx, ra); } + return; } #endif =20 set_helper_retaddr(ra); - memset(mem, 0, blocklen); + memset(mem, 0, len); clear_helper_retaddr(); } =20 +void HELPER(dc_zva)(CPUARMState *env, uint64_t addr) +{ + uintptr_t ra =3D GETPC(); + size_t len =3D (size_t)4 << get_dczid_bs(env_archcpu(env)); + int mmu_idx =3D arm_env_mmu_index(env); + MemTxAttrs attrs =3D MEMTXATTRS_UNSPECIFIED; + int flags; + void *mem; + + /* DC_ZVA requires that we supply the original pointer for traps. */ +#ifdef CONFIG_USER_ONLY + flags =3D probe_access_flags(env, addr, 0, MMU_DATA_STORE, mmu_idx, + false, &mem, ra); +#else + CPUTLBEntryFull *full; + flags =3D probe_access_full(env, addr, 0, MMU_DATA_STORE, mmu_idx, + false, &mem, &full, ra); + attrs =3D full->attrs; +#endif + + flags =3D do_dcxva_traps(env, addr, len, mmu_idx, flags, attrs, ra); + + /* After traps, treat as aligned blocks. */ + addr =3D addr & -len; + mem =3D (void *)((uintptr_t)mem & -len); + + do_dczva_0(env, addr, len, mem, mmu_idx, flags, ra); +} + /* * Perform an MTE checked access for DC_ZVA. */ --=20 2.43.0 From nobody Sat Jul 25 13:41:30 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linaro.org ARC-Seal: i=1; a=rsa-sha256; t=1784330746; cv=none; d=zohomail.com; s=zohoarc; b=bZKMunaykAtIrR8/f4T7FvkSU3xyXdO9620REUbtXOouZRB9hvCWE5NkvgyIuo2QPo5qL8cZHzhR23sC2PtVbWQgcUD83bOKQQrUADOx30OfAnO7ZrI9YBU+WdJb8nw4EOUK8P1gBNcxAE+0c6m3mJ+sXprvTn3OmzJv8hPn+yM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784330746; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=jexTKBibLdxg3RvO/0OqJ7xCxktdejWuZt8hYEIzmj8=; b=RCHnBCiQnfpmREm5GoDByFtcfgwsTl2rW/Asgi9zs9v41z0daq6P0ttuVeub/bFOZFIVshIY+XiSrggOQIEpAtLE+4VsTLywVePxLLvnTch8WdfJ+OJuM+rs4yPtZxazikLNgjVwH4TM/3/un6XC+Gpw+X0X1Pye0pxgxqvlJhY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784330746075662.7828179448119; Fri, 17 Jul 2026 16:25:46 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wkrtt-0001Y1-UL; Fri, 17 Jul 2026 19:23:25 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkrtp-0001UA-3Z for qemu-devel@nongnu.org; Fri, 17 Jul 2026 19:23:21 -0400 Received: from mail-pg1-x52e.google.com ([2607:f8b0:4864:20::52e]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wkrtk-0006yY-Mm for qemu-devel@nongnu.org; Fri, 17 Jul 2026 19:23:18 -0400 Received: by mail-pg1-x52e.google.com with SMTP id 41be03b00d2f7-ca965de53baso2809394a12.0 for ; Fri, 17 Jul 2026 16:23:16 -0700 (PDT) Received: from stoup.. ([32.140.233.50]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13ce2a18a47sm8186261c88.8.2026.07.17.16.23.14 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 17 Jul 2026 16:23:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1784330595; x=1784935395; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=jexTKBibLdxg3RvO/0OqJ7xCxktdejWuZt8hYEIzmj8=; b=hHtKkJsFLGMH2yltT2tKWweY0mybbwvB/b540KmSuoS+Kwll8fZ2ssQGVupjlKbkJO IktznEeQ1J/xyXHiIhIUA6ZkXpgL/cmES8Qavfauj4aVKum6TelTScOA488jDAi/eEup fKFxWF7psv3gyG5L3cel2RGtuiMwm4+Rgbi+OWGd74o5pb+uk5MxGEAW5jFCzM3kb3Wl jRi4cKbhwoezjMire0Sf+/Ok1kazOrDYeX7URBI6dYWL0wzyxVJd0CKvG92n05HTOmpt jSowEAjnX4dHNbvOOE4ty3lNRll3irtS4ka1ugUnxS+Wj6Uyh7JDZs/uvO6Iw26JffjU BDIg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784330595; x=1784935395; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=jexTKBibLdxg3RvO/0OqJ7xCxktdejWuZt8hYEIzmj8=; b=k6mWR0ASr11HHloRrEEjiIsBzzGRz/Jhootm0hwDxdS8c3cCQErdRwlLqLnfD2mD+W /JERCuoS7MF4xmQFObqkGW2WJMd7adbS7sJIz3ImvmSLpTkbwd1nZH3RgyIIGLst7LbE EdkZ1rw7/i2sRsp/cr/j3OsKz31AOdxADCrEikMyy6W63JRMwYZLw6n2/1ufJ/37ofmC 9yvke1TnrGyIpO7ZjaSvKKB9atMw8oTW54gEzY9Tvh40bS9OPqDBc0xkNBZDYhEcVwhA qtjpI7wGwZu9jUj3lCGjxb+1h+1uVsYmPptmmMI8fTz2mvNgCOhNGMw9KWrbxe7xlAot RHNA== X-Gm-Message-State: AOJu0YwKLJ8sgbeAeRwTVTSLsT7xoK+y2nGAFFDzxCOtYpCnLB3oxiDY LWv49iagsvJy/jbw3G8Ma43ZamBRAMB/+6EI7i6qEa+uc+L2u+kxlHHEh0gtko1hNcCfe+ScHB+ OB3lf X-Gm-Gg: AfdE7cmFG6XvXY00AwKTRzqU//kYo+PXaFf3W8Xk6BjsWZ4exrowMm12dSPidtVsnfM sSbzwk2Oal1GRkoqmZOBqemWYzv6mKtJNobc16FUU6AcoXEvYCVV0+FW65T944pQ/llFqWXJ1wZ Na1e298shbnzYaVkGzefg9LuScCKvCUgcIMu4MlOxMROODmNmEPnnvGvg+OvA4NHXDVqduKysYf y5L3KXqeBdpWxxdCJpH1oYTgA+DWOfnkE7d04HuGd61ZCXjKmo0yhZBLZ2mxkcVdxe2PhOm3GE5 bILhNLVBH01991gqFDvQnM+TkDaP4eDD0CFAR+VOki4EVfh39jzEWZda4rdD2nYDpSqfcUI6Mkj EUu9JjJq9d5vBzbv8SRVWvC2QshKlI4hyVzxm6b47rs3DVNTEC/vCMvlLFCEabj5Y5t6cLuobLn tSiYy9oFE= X-Received: by 2002:a17:90b:2151:b0:38e:59c2:cbc5 with SMTP id 98e67ed59e1d1-38e59c2dc76mr1185855a91.18.1784330595170; Fri, 17 Jul 2026 16:23:15 -0700 (PDT) From: Richard Henderson To: qemu-devel@nongnu.org Cc: qemu-arm@nongnu.org Subject: [PATCH 05/17] target/arm: Imply probe from allocation_tag_mem_probe Date: Fri, 17 Jul 2026 16:22:53 -0700 Message-ID: <20260717232306.378988-7-richard.henderson@linaro.org> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260717232306.378988-1-richard.henderson@linaro.org> References: <20260717232306.378988-1-richard.henderson@linaro.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2607:f8b0:4864:20::52e; envelope-from=richard.henderson@linaro.org; helo=mail-pg1-x52e.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linaro.org) X-ZM-MESSAGEID: 1784330746448158500 Content-Type: text/plain; charset="utf-8" Rename current allocation_tag_mem_probe to allocation_tag_mem_internal, then create a new allocation_tag_mem_probe that lacks probe and ra arguments. Force those to true and 0 when passing off to _internal. Signed-off-by: Richard Henderson Reviewed-by: Philippe Mathieu-Daud=C3=A9 --- target/arm/tcg/mte_helper.h | 18 +++--------------- target/arm/gdbstub64.c | 10 +++++----- target/arm/tcg/mte_helper.c | 29 ++++++++++++++++++----------- 3 files changed, 26 insertions(+), 31 deletions(-) diff --git a/target/arm/tcg/mte_helper.h b/target/arm/tcg/mte_helper.h index 1f471fb69b..b23a5de193 100644 --- a/target/arm/tcg/mte_helper.h +++ b/target/arm/tcg/mte_helper.h @@ -19,8 +19,6 @@ * @ptr_access: the access to use for the virtual address * @ptr_size: the number of bytes in the normal memory access * @tag_access: the access to use for the tag memory - * @probe: true to merely probe, never taking an exception - * @ra: the return address for exception handling * * Our tag memory is formatted as a sequence of little-endian nibbles. * That is, the byte at (addr >> (LOG2_TAG_GRANULE + 1)) contains two @@ -31,22 +29,12 @@ * a pointer to the corresponding tag byte. * * If there is no tag storage corresponding to @ptr, return NULL. - * - * If the page is inaccessible for @ptr_access, or has a watchpoint, there= are - * three options: - * (1) probe =3D true, ra =3D 0 : pure probe -- we return NULL if the page= is not - * accessible, and do not take watchpoint traps. The calling code must - * handle those cases in the right priority compared to MTE traps. - * (2) probe =3D false, ra =3D 0 : probe, no fault expected -- the caller = guarantees - * that the page is going to be accessible. We will take watchpoint tr= aps. - * (3) probe =3D false, ra !=3D 0 : non-probe -- we will take both memory = access - * traps and watchpoint traps. - * (probe =3D true, ra !=3D 0 is invalid and will assert.) + * If the page is inaccessible for @ptr_access, return NULL. + * Do not take watcnpoint traps. */ uint8_t *allocation_tag_mem_probe(CPUARMState *env, int ptr_mmu_idx, uint64_t ptr, MMUAccessType ptr_access, - int ptr_size, MMUAccessType tag_access, - bool probe, uintptr_t ra); + int ptr_size, MMUAccessType tag_access); =20 /** * load_tag1 - Load 1 tag (nibble) from byte diff --git a/target/arm/gdbstub64.c b/target/arm/gdbstub64.c index 0c3e5b30bd..08900f6843 100644 --- a/target/arm/gdbstub64.c +++ b/target/arm/gdbstub64.c @@ -725,8 +725,8 @@ static void handle_q_memtag(GArray *params, void *user_= ctx) /* Find out the current translation regime for probe. */ mmu_index =3D cpu_mmu_index(env_cpu(env), false); /* Note that tags are packed here (2 tags packed in one byte). */ - tags =3D allocation_tag_mem_probe(env, mmu_index, addr, MMU_DATA_LOAD,= 1, - MMU_DATA_LOAD, true, 0); + tags =3D allocation_tag_mem_probe(env, mmu_index, addr, MMU_DATA_LOAD, + 1, MMU_DATA_LOAD); if (!tags) { /* Address is not in a tagged region. */ gdb_put_packet("E04"); @@ -753,8 +753,8 @@ static void handle_q_isaddresstagged(GArray *params, vo= id *user_ctx) =20 /* Find out the current translation regime for probe. */ mmu_index =3D cpu_mmu_index(env_cpu(env), false); - tags =3D allocation_tag_mem_probe(env, mmu_index, addr, MMU_DATA_LOAD,= 1, - MMU_DATA_LOAD, true, 0); + tags =3D allocation_tag_mem_probe(env, mmu_index, addr, MMU_DATA_LOAD, + 1, MMU_DATA_LOAD); reply =3D tags ? "01" : "00"; =20 gdb_put_packet(reply); @@ -800,7 +800,7 @@ static void handle_Q_memtag(GArray *params, void *user_= ctx) /* Find out the current translation regime for probe. */ mmu_index =3D cpu_mmu_index(env_cpu(env), false); tags =3D allocation_tag_mem_probe(env, mmu_index, start_addr, MMU_DATA= _STORE, - 1, MMU_DATA_STORE, true, 0); + 1, MMU_DATA_STORE); if (!tags) { /* Address is not in a tagged region. */ gdb_put_packet("E04"); diff --git a/target/arm/tcg/mte_helper.c b/target/arm/tcg/mte_helper.c index dc87dc283f..905e9d7eaf 100644 --- a/target/arm/tcg/mte_helper.c +++ b/target/arm/tcg/mte_helper.c @@ -80,10 +80,11 @@ static void mte_perm_check_fail(CPUARMState *env, uint6= 4_t dirty_ptr, } #endif =20 -uint8_t *allocation_tag_mem_probe(CPUARMState *env, int ptr_mmu_idx, - uint64_t ptr, MMUAccessType ptr_access, - int ptr_size, MMUAccessType tag_access, - bool probe, uintptr_t ra) +static uint8_t * +allocation_tag_mem_internal(CPUARMState *env, int ptr_mmu_idx, + uint64_t ptr, MMUAccessType ptr_access, + int ptr_size, MMUAccessType tag_access, + bool probe, uintptr_t ra) { #ifdef CONFIG_USER_ONLY const size_t page_data_size =3D TARGET_PAGE_SIZE >> (LOG2_TAG_GRANULE = + 1); @@ -92,8 +93,6 @@ uint8_t *allocation_tag_mem_probe(CPUARMState *env, int p= tr_mmu_idx, uint8_t *tags; uintptr_t index; =20 - assert(!(probe && ra)); - if (!(flags & (ptr_access =3D=3D MMU_DATA_STORE ? PAGE_WRITE_ORG : PAG= E_READ))) { if (probe) { return NULL; @@ -250,8 +249,16 @@ static uint8_t *allocation_tag_mem(CPUARMState *env, i= nt ptr_mmu_idx, int ptr_size, MMUAccessType tag_access, uintptr_t ra) { - return allocation_tag_mem_probe(env, ptr_mmu_idx, ptr, ptr_access, - ptr_size, tag_access, false, ra); + return allocation_tag_mem_internal(env, ptr_mmu_idx, ptr, ptr_access, + ptr_size, tag_access, false, ra); +} + +uint8_t *allocation_tag_mem_probe(CPUARMState *env, int ptr_mmu_idx, + uint64_t ptr, MMUAccessType ptr_access, + int ptr_size, MMUAccessType tag_access) +{ + return allocation_tag_mem_internal(env, ptr_mmu_idx, ptr, ptr_access, + ptr_size, tag_access, true, 0); } =20 uint64_t HELPER(irg)(CPUARMState *env, uint64_t rn, uint64_t rm) @@ -1221,7 +1228,7 @@ uint64_t mte_mops_probe(CPUARMState *env, uint64_t pt= r, uint64_t size, /* True probe; this will never fault */ mem =3D allocation_tag_mem_probe(env, mmu_idx, ptr, w ? MMU_DATA_STORE : MMU_DATA_LOAD, - size, MMU_DATA_LOAD, true, 0); + size, MMU_DATA_LOAD); if (!mem) { return size; } @@ -1279,7 +1286,7 @@ uint64_t mte_mops_probe_rev(CPUARMState *env, uint64_= t ptr, uint64_t size, */ mem =3D allocation_tag_mem_probe(env, mmu_idx, ptr, w ? MMU_DATA_STORE : MMU_DATA_LOAD, - 1, MMU_DATA_LOAD, true, 0); + 1, MMU_DATA_LOAD); if (!mem) { return size; } @@ -1331,7 +1338,7 @@ void mte_mops_set_tags(CPUARMState *env, uint64_t ptr= , uint64_t size, mmu_idx =3D FIELD_EX32(desc, MTEDESC, MIDX); /* True probe: this will never fault */ mem =3D allocation_tag_mem_probe(env, mmu_idx, ptr, MMU_DATA_STORE, si= ze, - MMU_DATA_STORE, true, 0); + MMU_DATA_STORE); if (!mem) { return; } --=20 2.43.0 From nobody Sat Jul 25 13:41:30 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linaro.org ARC-Seal: i=1; a=rsa-sha256; t=1784330834; cv=none; d=zohomail.com; s=zohoarc; b=KD2likst5UnLIWzeWHtAExH4kN6YjXyOgnbvj5UIlj7pk7n+cqH96RUP4fQqb1c3ZksUKy9m1tg87GhIxxiJSRw39Xp6RfpMZ2qF0VUPPnQ4B/pVWNi8DrB8FeJHHFOwws7Jeggm6f2hMA3D/L2eK6lJhBq+MZDQ/q4vRIZ2LhQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784330834; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=JU4rrR299+XISy9LcAmasYIokW518EoY+ALWFUyVnMI=; b=QcnZRyQ8jif5WN6EELLI5TDqA/qnp7bDiX/5KzOiaSnCY9qirsrzcVz+Lpi4gXjMWLYAcpp40YNWaXV6RmnJb15Svh/90dtbNK+/3vVc5M5nHz4pAWnnS5GkYLvVEOfIFUwv9HbqkpOy9HhRtqBnmps+m2yb6Ltp8+qtkyJMpYY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784330834585274.178681203505; Fri, 17 Jul 2026 16:27:14 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wkrtr-0001Vz-Bh; Fri, 17 Jul 2026 19:23:23 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkrtq-0001Uv-9W for qemu-devel@nongnu.org; Fri, 17 Jul 2026 19:23:22 -0400 Received: from mail-pl1-x62c.google.com ([2607:f8b0:4864:20::62c]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wkrtm-0006yp-VR for qemu-devel@nongnu.org; Fri, 17 Jul 2026 19:23:22 -0400 Received: by mail-pl1-x62c.google.com with SMTP id d9443c01a7336-2ceab75934dso85665225ad.2 for ; Fri, 17 Jul 2026 16:23:17 -0700 (PDT) Received: from stoup.. ([32.140.233.50]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13ce2a18a47sm8186261c88.8.2026.07.17.16.23.15 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 17 Jul 2026 16:23:15 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1784330596; x=1784935396; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=JU4rrR299+XISy9LcAmasYIokW518EoY+ALWFUyVnMI=; b=wISbja5fsNzhH05Ke1YWjE3YN8lVnpAtdLMXqetUZHuVaiQMZeMh4OjsS47f31sNEg tEJlNZ0KlLgSHKXVyiii6r1a+MxHSQuzZGqkS05k7zbg5R2tRD9yG+C8hzh4ZfavcTrk +0x5M8n06P4TzR5R7Rjvuh1wkMKi7/CvQ++hqHfzoZSbgbD8nBPa8XhnNUzjLNIhiaCB IOU9iG/WpsEoPPGFj0cJWkx7x5qvF23bSmK+iGU7GbKRVSbmDYef2fOk5q43j26q0En5 Zdtmw7ckIwgQnIJ+tT0e2GWYmb75FdELMsHcjgQQTTJyHEEzM2+3EOkRgUpWRVimwbgr t6+w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784330596; x=1784935396; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=JU4rrR299+XISy9LcAmasYIokW518EoY+ALWFUyVnMI=; b=GdEk0PJzkoKZhonS/u2iHIn1fcesT8UGCobgDhewjQ8vpBd6dGHQHk1qGARRqILPhB lJ5Xu69zjMqFtDNHl86pBzj4fw9brVdzL3l3SCbzOAijDzUWGt31/MPp513N13Pp/7wB Th+ir4p75WOIpj3kBRIlyyWiBj918tnr3JXQuArg9WUaT0oR/mD7JIVa1Kr3A2Y/b56F y/pJ2XRIADXHJvnwd40x7mD6eSzR/aWEclkD0QMOXCjNbXLg1JhGR5Go+TmmIAh6MQuC 01cbpsNhnxJXrWntS3kd2StWx8n4XujXmYiQDUr7oLIG47hIWH0eEyvBzVzePYc1OSql logA== X-Gm-Message-State: AOJu0Yw40RBVjsvROuKKNUk2HuBk+Xlkp+ELO5mNWykPI3A17nN6j4D4 ZcQyGcE8vo34Ye6kfMrxvdSl7SVRJGsWOjUFcyWtqpH+aMmF3mh/ORiUsHd/hEcPqjtKKJNdq5Z WEGXo X-Gm-Gg: AfdE7ckJMb9UVUL1NtYqjLo1zjahF0Ol06USh84VuTxz93VQVISW0iwADuJO17kQdnI SkAsKRzRVpnz+9wcs6JaFe5MFLnMjVut7Y+LWzbV81d/GGNcehG1zYlU/RYk9UVgBQaf3qGPKWP jJ/K7NV0xWPKn15TNBcu2BRgILuFYCdhc4tFlTSHfVp1f/parl0Ai8c0rRET7/oufMCrmdgZqKU UXl7VPEC/lOMVU4jznX02aajGnlK0VcD58dKW5Ln/sVDppWtXk42utB3YcWXC8ME94MBtaaY6gg RB/dmhicKg/QDkjpPr2cLg9yYR+fBMkgBKywZa5Rr6ZWTLcmVRkKjjwWCa+7abWhg4XlM646Jde LuwtLLvzs1U9owr0ucvi8JKqMa9lcsFiVk+uTBqWkVE/N8PPdZ4777TY7N7c5HJjS183IlP2lDX OLy+ryyG8= X-Received: by 2002:a17:90b:5588:b0:38d:a150:ee04 with SMTP id 98e67ed59e1d1-38e4b55aabfmr4944229a91.30.1784330596237; Fri, 17 Jul 2026 16:23:16 -0700 (PDT) From: Richard Henderson To: qemu-devel@nongnu.org Cc: qemu-arm@nongnu.org Subject: [PATCH 06/17] target/arm: Simplify invalid page test in allocation_tag_mem_internal Date: Fri, 17 Jul 2026 16:22:54 -0700 Message-ID: <20260717232306.378988-8-richard.henderson@linaro.org> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260717232306.378988-1-richard.henderson@linaro.org> References: <20260717232306.378988-1-richard.henderson@linaro.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2607:f8b0:4864:20::62c; envelope-from=richard.henderson@linaro.org; helo=mail-pl1-x62c.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linaro.org) X-ZM-MESSAGEID: 1784330836556158500 Content-Type: text/plain; charset="utf-8" Signed-off-by: Richard Henderson Reviewed-by: Philippe Mathieu-Daud=C3=A9 --- target/arm/tcg/mte_helper.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/target/arm/tcg/mte_helper.c b/target/arm/tcg/mte_helper.c index 905e9d7eaf..8f7a222b9c 100644 --- a/target/arm/tcg/mte_helper.c +++ b/target/arm/tcg/mte_helper.c @@ -133,10 +133,10 @@ allocation_tag_mem_internal(CPUARMState *env, int ptr= _mmu_idx, */ flags =3D probe_access_full(env, ptr, 0, ptr_access, ptr_mmu_idx, ra =3D=3D 0, &host, &full, ra); - if (probe && (flags & TLB_INVALID_MASK)) { + if (unlikely(flags & TLB_INVALID_MASK)) { + assert(probe); return NULL; } - assert(!(flags & TLB_INVALID_MASK)); =20 switch (full->extra.arm.pte_attrs) { case 0xf0: /* Tagged */ --=20 2.43.0 From nobody Sat Jul 25 13:41:30 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linaro.org ARC-Seal: i=1; a=rsa-sha256; t=1784330700; cv=none; d=zohomail.com; s=zohoarc; b=c07XZQDzFPDRrQu5bt3zwUlU2IDeddyt2XYAgIa6W0t01Rts1X36rFQY7OPpLDoc2IoNCS5U964r7yixx6Kd0/XGXmEeNcmfBbhSzJCSgfS4eChkJpyFmuhybb3W6C0Cu05jDxRSp74pB9C/ogEATBPRabvZfkK+eAX6vVeDW8I= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784330700; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=yFRAsWMA+NNoAvoC+xKcAlWuQ4eHUr0T9NC0Mnxt+fA=; b=gZo/hr67JPcPbnMG+PTAl6HZ3ee9H6adbqv6oEwoNuEk/6lmu4vmVhSAwR3jOj6DD+MPiEutn/uZIJe/+WiijaUeH0q35tPoE5PMpWoSRgV58qMShgjAMlMGcqsVnZ6MQHeUXiJgmDvYDXM5nWbjLeDV0G7RQP9oLkFwLoD1zO0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784330700935233.53483301926326; Fri, 17 Jul 2026 16:25:00 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wkrtz-0001bL-U7; Fri, 17 Jul 2026 19:23:31 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkrts-0001Wm-5K for qemu-devel@nongnu.org; Fri, 17 Jul 2026 19:23:24 -0400 Received: from mail-pj1-x1030.google.com ([2607:f8b0:4864:20::1030]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wkrto-0006zB-SB for qemu-devel@nongnu.org; Fri, 17 Jul 2026 19:23:23 -0400 Received: by mail-pj1-x1030.google.com with SMTP id 98e67ed59e1d1-385ea3ce80dso8297708a91.2 for ; Fri, 17 Jul 2026 16:23:18 -0700 (PDT) Received: from stoup.. ([32.140.233.50]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13ce2a18a47sm8186261c88.8.2026.07.17.16.23.16 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 17 Jul 2026 16:23:17 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1784330597; x=1784935397; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=yFRAsWMA+NNoAvoC+xKcAlWuQ4eHUr0T9NC0Mnxt+fA=; b=EiDZQT0u+qvFJ4HRTBiAEMANPq8iJXFTK2l7jc5g13rTyfpI3zkc8tnX3b6TF69EH0 d7MxlJNH4jmqReXzNFpxQePmoaSykuVoqY0Jfc/bXnogRALiN+Rn4Ml8+27DU3ykv+oX hf52Ep0lH3fP+uEcm47Dk2+xFjjyNhpvnfHdk4mM3hwH61XNji+h4kZFiHnjZQv4MOmP BRP6Lwt9HYe8pACuC0Jap6TIWWmJWob9BrTBGOeEE7vgagoTa4LSyp2jz7BsEqRpTmef TVkrCza1hkJsYNoI/xYeT+bWOC0DO3maIIwZ9zV1Sh7LXBiBaX3ekRk0uTZw+ZfQpeD+ rilg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784330597; x=1784935397; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=yFRAsWMA+NNoAvoC+xKcAlWuQ4eHUr0T9NC0Mnxt+fA=; b=FejYiSAPn/sxlX9KINovPkjCxQoAelt+VHpm9ZFG4r56iH1MT2son/GKfi6qjTHLCN Z2gw6iAzgYLFu3mDfpR/50APF+ehpu0NQdaaPTLCq3INK0Br7rQFxLmWhsnsaujE3Wrn 8BV1klY+t02Y2g7l2auXDl0KbjPuGvPOlDp7250liPSqPIkvU3WAPgI0bFL3h2W5tlfL 0wpUpe/CX4Py8k5Je0R9ieQWrsOsoiQh/QSGz+mZv2aiJlujCHI+cW1fnbZ7mo6yHS61 YCCVCeE6o53uCL7W4Rt2FivSI2tckVw3W+4+aC2wQyYvC1Mx1k8J9VmRhkbKllLhwSmd uBag== X-Gm-Message-State: AOJu0Yz3ttXc70fMM291bthfw0MCL3mNo9dHb2X2BT7vtTAVYJtv9fKQ bqoryph8h4CTsbhxohhopVEHls5ACsa9zH5pd989S0iB+bgpGQ8l7Wpj04apkMunDyRTcw7xSMw sdukM X-Gm-Gg: AfdE7clCVJ7xgyrdKT77NaVcLt+8QLTTU4woRy7MlEVn0BmbuAT4JM3QrvMzfQyBCgF 3h6zz5GQaaO/pMzEfCVKQThleEvVYRLn0kMEhes+lAwSWLB6qKHPIh7bs3/WEB/CjfWeHoB3qv9 TojCj2SQfTAqB7PAuYT3aun0rcPZ7ZqWcyRBMXma9gEGyvE5E9jT2nfd7CYNjPZb1jeGX+vVCWO u7AQleWm/VWn7ocIWBXNUGf1vpMge22j8MnzXjcKQJKy7MdCxzVlUBCKnXUtOzm/h4xMGM2h0c5 cTb5G7eBhDNheh0byaMAHy54AOKcuAu5iT+u7ITN+6vZuL+v+2Q8uC2VYLbpMxlkxowEChnhl4i wsBy6vL7s3d+rnTkkVWx+zsUxqaxqHVQyDEMKF592nnwpVJKCE8y3w8M1lThCGffEeaiKaUWtHk /4u/c5bcs= X-Received: by 2002:a17:90b:5908:b0:380:71eb:4014 with SMTP id 98e67ed59e1d1-38e4b448c32mr5085573a91.15.1784330597467; Fri, 17 Jul 2026 16:23:17 -0700 (PDT) From: Richard Henderson To: qemu-devel@nongnu.org Cc: qemu-arm@nongnu.org Subject: [PATCH 07/17] target/arm: Return struct from allocation_tag_mem_internal Date: Fri, 17 Jul 2026 16:22:55 -0700 Message-ID: <20260717232306.378988-9-richard.henderson@linaro.org> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260717232306.378988-1-richard.henderson@linaro.org> References: <20260717232306.378988-1-richard.henderson@linaro.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2607:f8b0:4864:20::1030; envelope-from=richard.henderson@linaro.org; helo=mail-pj1-x1030.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linaro.org) X-ZM-MESSAGEID: 1784330702421158500 Content-Type: text/plain; charset="utf-8" Return not just the tag memory, but the data memory, flags, and attributes. Make sure probe of NoTagAccess looks like any other page permission failure. Signed-off-by: Richard Henderson Reviewed-by: Philippe Mathieu-Daud=C3=A9 --- target/arm/tcg/mte_helper.c | 102 +++++++++++++++++++++--------------- 1 file changed, 60 insertions(+), 42 deletions(-) diff --git a/target/arm/tcg/mte_helper.c b/target/arm/tcg/mte_helper.c index 8f7a222b9c..e6e78634b6 100644 --- a/target/arm/tcg/mte_helper.c +++ b/target/arm/tcg/mte_helper.c @@ -27,6 +27,7 @@ #ifdef CONFIG_USER_ONLY #include "user/cpu_loop.h" #include "user/page-protection.h" +#include "user/guest-host.h" #else #include "system/physmem.h" #endif @@ -80,46 +81,53 @@ static void mte_perm_check_fail(CPUARMState *env, uint6= 4_t dirty_ptr, } #endif =20 -static uint8_t * +typedef struct AllocationTagMem { + uint8_t *tag_mem; + void *ptr_mem; + int flags; + MemTxAttrs attrs; +} AllocationTagMem; + +static AllocationTagMem allocation_tag_mem_internal(CPUARMState *env, int ptr_mmu_idx, - uint64_t ptr, MMUAccessType ptr_access, + vaddr ptr, MMUAccessType ptr_access, int ptr_size, MMUAccessType tag_access, bool probe, uintptr_t ra) { -#ifdef CONFIG_USER_ONLY - const size_t page_data_size =3D TARGET_PAGE_SIZE >> (LOG2_TAG_GRANULE = + 1); - uint64_t clean_ptr =3D useronly_clean_ptr(ptr); - int flags =3D page_get_flags(clean_ptr); - uint8_t *tags; - uintptr_t index; + AllocationTagMem ret =3D { }; =20 - if (!(flags & (ptr_access =3D=3D MMU_DATA_STORE ? PAGE_WRITE_ORG : PAG= E_READ))) { +#ifdef CONFIG_USER_ONLY + vaddr clean_ptr =3D useronly_clean_ptr(ptr); + int flags =3D page_get_flags(clean_ptr); + int req_flags =3D ptr_access =3D=3D MMU_DATA_STORE ? PAGE_WRITE_ORG : = PAGE_READ; + + if (unlikely(!(flags & req_flags))) { if (probe) { - return NULL; + ret.flags =3D TLB_INVALID_MASK; + goto fini; } cpu_loop_exit_sigsegv(env_cpu(env), ptr, ptr_access, !(flags & PAGE_VALID), ra); } =20 /* Require both MAP_ANON and PROT_MTE for the page. */ - if (!(flags & PAGE_ANON) || !(flags & PAGE_MTE)) { - return NULL; + if ((flags & PAGE_ANON) && (flags & PAGE_MTE)) { + size_t page_data_size =3D TARGET_PAGE_SIZE >> (LOG2_TAG_GRANULE + = 1); + uint8_t *tags =3D page_get_target_data(clean_ptr, page_data_size); + uintptr_t index =3D extract64(ptr, LOG2_TAG_GRANULE + 1, + TARGET_PAGE_BITS - LOG2_TAG_GRANULE - = 1); + ret.tag_mem =3D tags + index; } =20 - tags =3D page_get_target_data(clean_ptr, page_data_size); - - index =3D extract32(ptr, LOG2_TAG_GRANULE + 1, - TARGET_PAGE_BITS - LOG2_TAG_GRANULE - 1); - return tags + index; + ret.ptr_mem =3D g2h_untagged_vaddr(clean_ptr); + ret.attrs =3D MEMTXATTRS_UNSPECIFIED; #else CPUTLBEntryFull *full; - MemTxAttrs attrs; - int in_page, flags; + int in_page; hwaddr ptr_paddr, tag_paddr, xlat; MemoryRegion *mr; ARMASIdx tag_asi; AddressSpace *tag_as; - void *host; =20 /* * Probe the first byte of the virtual address. This raises an @@ -131,12 +139,13 @@ allocation_tag_mem_internal(CPUARMState *env, int ptr= _mmu_idx, * for the pure probe, or assert that we received a valid page for the * no-fault-expected probe. */ - flags =3D probe_access_full(env, ptr, 0, ptr_access, ptr_mmu_idx, - ra =3D=3D 0, &host, &full, ra); - if (unlikely(flags & TLB_INVALID_MASK)) { + ret.flags =3D probe_access_full(env, ptr, 0, ptr_access, ptr_mmu_idx, + ra =3D=3D 0, &ret.ptr_mem, &full, ra); + if (unlikely(ret.flags & TLB_INVALID_MASK)) { assert(probe); - return NULL; + goto fini; } + ret.attrs =3D full->attrs; =20 switch (full->extra.arm.pte_attrs) { case 0xf0: /* Tagged */ @@ -145,7 +154,9 @@ allocation_tag_mem_internal(CPUARMState *env, int ptr_m= mu_idx, case 0xe0: /* NoTagAccess */ if (cpu_isar_feature(aa64_mteperm, env_archcpu(env))) { if (probe) { - return NULL; + ret.ptr_mem =3D NULL; + ret.flags =3D TLB_INVALID_MASK; + goto fini; } assert(ra); mte_perm_check_fail(env, ptr, ra, tag_access =3D=3D MMU_DATA_S= TORE); @@ -153,27 +164,25 @@ allocation_tag_mem_internal(CPUARMState *env, int ptr= _mmu_idx, /* fall through */ =20 default: /* Not Tagged */ - return NULL; + goto fini; } =20 /* * If not backed by host ram, there is no tag storage: access unchecke= d. * This is probably a guest os bug though, so log it. */ - if (unlikely(flags & TLB_MMIO)) { + if (unlikely(ret.flags & TLB_MMIO)) { qemu_log_mask(LOG_GUEST_ERROR, "Page @ 0x%" PRIx64 " indicates Tagged Normal memory= " "but is not backed by host ram\n", ptr); - return NULL; + goto fini; } =20 /* - * Remember these values across the second lookup below, + * Remember this across the second lookup below, * which may invalidate this pointer via tlb resize. */ ptr_paddr =3D full->phys_addr | (ptr & ~TARGET_PAGE_MASK); - attrs =3D full->attrs; - full =3D NULL; =20 /* * The Normal memory access can extend to the next page. E.g. a single @@ -183,26 +192,30 @@ allocation_tag_mem_internal(CPUARMState *env, int ptr= _mmu_idx, */ in_page =3D -(ptr | TARGET_PAGE_MASK); if (unlikely(ptr_size > in_page)) { - flags |=3D probe_access_full(env, ptr + in_page, 0, ptr_access, - ptr_mmu_idx, ra =3D=3D 0, &host, &full,= ra); - assert(!(flags & TLB_INVALID_MASK)); + void *discard_mem; + int flags2 =3D probe_access_full(env, ptr + in_page, 0, ptr_access, + ptr_mmu_idx, ra =3D=3D 0, + &discard_mem, &full, ra); + + assert(!(flags2 & TLB_INVALID_MASK)); + ret.flags |=3D flags2; } =20 /* Any debug exception has priority over a tag check exception. */ - if (!probe && unlikely(flags & TLB_WATCHPOINT)) { + if (!probe && unlikely(ret.flags & TLB_WATCHPOINT)) { int wp =3D ptr_access =3D=3D MMU_DATA_LOAD ? BP_MEM_READ : BP_MEM_= WRITE; assert(ra !=3D 0); - cpu_check_watchpoint(env_cpu(env), ptr, ptr_size, attrs, wp, ra); + cpu_check_watchpoint(env_cpu(env), ptr, ptr_size, ret.attrs, wp, r= a); } =20 /* Convert to the physical address in tag space. */ tag_paddr =3D ptr_paddr >> (LOG2_TAG_GRANULE + 1); =20 /* Look up the address in tag space. */ - tag_asi =3D attrs.secure ? ARMASIdx_TagS : ARMASIdx_TagNS; + tag_asi =3D ret.attrs.secure ? ARMASIdx_TagS : ARMASIdx_TagNS; tag_as =3D cpu_get_address_space(env_cpu(env), tag_asi); mr =3D address_space_translate(tag_as, tag_paddr, &xlat, NULL, - tag_access =3D=3D MMU_DATA_STORE, attrs); + tag_access =3D=3D MMU_DATA_STORE, ret.att= rs); =20 /* * Note that @mr will never be NULL. If there is nothing in the addre= ss @@ -215,7 +228,7 @@ allocation_tag_mem_internal(CPUARMState *env, int ptr_m= mu_idx, "Tag Memory @ 0x%" HWADDR_PRIx " not found for " "Normal Memory @ 0x%" HWADDR_PRIx "\n", tag_paddr, ptr_paddr); - return NULL; + goto fini; } =20 /* @@ -227,8 +240,11 @@ allocation_tag_mem_internal(CPUARMState *env, int ptr_= mmu_idx, physical_memory_set_dirty_flag(tag_ra, DIRTY_MEMORY_MIGRATION); } =20 - return memory_region_get_ram_ptr(mr) + xlat; + ret.tag_mem =3D memory_region_get_ram_ptr(mr) + xlat; #endif + + fini: + return ret; } =20 static G_NORETURN void canonical_tag_write_fail(CPUARMState *env, @@ -250,7 +266,8 @@ static uint8_t *allocation_tag_mem(CPUARMState *env, in= t ptr_mmu_idx, uintptr_t ra) { return allocation_tag_mem_internal(env, ptr_mmu_idx, ptr, ptr_access, - ptr_size, tag_access, false, ra); + ptr_size, tag_access, false, ra) + .tag_mem; } =20 uint8_t *allocation_tag_mem_probe(CPUARMState *env, int ptr_mmu_idx, @@ -258,7 +275,8 @@ uint8_t *allocation_tag_mem_probe(CPUARMState *env, int= ptr_mmu_idx, int ptr_size, MMUAccessType tag_access) { return allocation_tag_mem_internal(env, ptr_mmu_idx, ptr, ptr_access, - ptr_size, tag_access, true, 0); + ptr_size, tag_access, true, 0) + .tag_mem; } =20 uint64_t HELPER(irg)(CPUARMState *env, uint64_t rn, uint64_t rm) --=20 2.43.0 From nobody Sat Jul 25 13:41:30 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linaro.org ARC-Seal: i=1; a=rsa-sha256; t=1784330667; cv=none; d=zohomail.com; s=zohoarc; b=BwsOtjxg3W11de2sje3hvzP9ZKaeMxdguPAvTfI1xe1Fkq97HHGbA9zOXa+AdPaz2trw6LT6cQ3aLUBdVy6XBeHnyucCRK3h35gAh5d8kftKJWPvPXjr9ojXm4Yg+XH9+LgrrjCTMPAm1OcBQo6PG1M0fZGP75aEv9bTc9mpQLI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784330667; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=/HU9UyOqGkjqTpc/QpkyDLeK41rIzSxxgyQ7DWIvTQ8=; b=kUtxNNY/vbaDoemWBKSO9UugqHM0uIwVs029rtv2pgSQ0Rxu7c2lArcNqYcuZxMMrSIvVUwHMZ45f/pOF/bi0lh2vOqIlzZbzaWnKAaI0BGsAPZdE9ka91u0hjHpAW/CXyKmmrjhp9YNvs6YmWGP4NcYIvvxGak/z7HF71Jl03o= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784330667581267.3617805589855; Fri, 17 Jul 2026 16:24:27 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wkrty-0001b5-I1; Fri, 17 Jul 2026 19:23:30 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkrts-0001XA-P5 for qemu-devel@nongnu.org; Fri, 17 Jul 2026 19:23:24 -0400 Received: from mail-pj1-x102f.google.com ([2607:f8b0:4864:20::102f]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wkrto-0006zK-Si for qemu-devel@nongnu.org; Fri, 17 Jul 2026 19:23:24 -0400 Received: by mail-pj1-x102f.google.com with SMTP id 98e67ed59e1d1-38dd55ad76cso1664187a91.1 for ; Fri, 17 Jul 2026 16:23:19 -0700 (PDT) Received: from stoup.. ([32.140.233.50]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13ce2a18a47sm8186261c88.8.2026.07.17.16.23.17 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 17 Jul 2026 16:23:17 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1784330599; x=1784935399; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=/HU9UyOqGkjqTpc/QpkyDLeK41rIzSxxgyQ7DWIvTQ8=; b=eoWX/RwFqZbvfo3rQfiLmrNqC6k+yIzEEyXztUW7O8nE59+G3Clz3UZuLZDW+YbSJp bfkY5rgYk/kR+wM9LSMTa7dSv/XWCxTAGnP7flFl7quNbwI98PVtBPsKVcJ4j3j3DlWc 1OFVQmBkvj9WFHQ7aiAlFBkyqxopqem8SJPDt2qOlfJfiDqiQ11t6+yu7tEMoygYbEeh lO164bl3zPf/aG5fDfN/ovapsmG5CVXaT9mOlxehlxQL2NSzScOSgxsF5OGJtxoA5LR2 Ml7rPBiP+i92bVYSGSIfzUgFtNkpa3Vjp3z8pEdHaXFlteEBXszECnDP6YOXs0Lqfmj5 q1Yg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784330599; x=1784935399; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=/HU9UyOqGkjqTpc/QpkyDLeK41rIzSxxgyQ7DWIvTQ8=; b=oEn0JwidphfM1lUU8jR8P8RWfXnkByobpYB8ydg/0oPMHy0ZF4ndLS4IbrHJ3B0xHF 26JH27vNzT7FVAHNGU9inLvRoHjvKRjWMGXF6O6nhUFS0VG9XgoBPSZFdO1upMRS+n0G dgvMtwcAgPvppdFfP0JzfMZvR3yEl3o5dD75PNjv06pdsrFKT8o9fGUmQzyPhNfve98g brXtHiEO3pJJUV63+6+yqS1cvm65y1QQAuMUtBa3Mful6pHeq6aFOQgq43umXy8LOOJ5 tVPuYN7iEMvlcbHxQ9vqvgWgxIbiDaRnhkixA6FyfbOUtCnn1he2HN/xqVSOBMWk55CC SoTQ== X-Gm-Message-State: AOJu0YyYRZ9sYd351QrSCx2R/ceJbhHIZo8IVlU9fs6915DFt43FsPH2 Ix+jUykyyMJ8sSsk5kO7hpJjgA0dKTAThgy1SL+EAvAN/559nnF0drQdNQHerKeJlkFbuORVj/K Hc9VE X-Gm-Gg: AfdE7clK8JtaxYtgFn7uS3T1tV5Ds+9EgWebiVkg+FBMQ1AuWOz9Tifc5fuy6cbinjM 4L7ypjK7UAOgsV8HfPzbaIcIyxgVM6xothVTW2QJDqNA2LMB6bac29VSxBxW6m8MKX1zP++DWim PTEO4xLz8CP0aiYK5PF2S1Bj9AFvjyTmNreKosjKJ8IQ1k0ZEkcXwpXl6RCERNoDURW+8cxpYGi VBcJgrN1C9czUJQFXKeZXAuLqbcPsMyqJVU0tlWidJVsVkByBJRNo1j1Tx3CNtJjpQ9pEZDHvbq laXCmFnrdzciGEBX9euTHAiBYvY0M/AQEVbqM9z1YCFoPDsqXS5htABn0QB2v2HQqgjXwHm7suk HMxeVoikjp9xAHfETOA0ssIegYMRYKJqkuC/KayLXrmJR446NKC1HBv7MInkigQaLdMeJFr3Kkf awX2YX+og= X-Received: by 2002:a17:90a:da84:b0:38e:5ce1:ae30 with SMTP id 98e67ed59e1d1-38e5ce1b055mr887165a91.14.1784330598600; Fri, 17 Jul 2026 16:23:18 -0700 (PDT) From: Richard Henderson To: qemu-devel@nongnu.org Cc: qemu-arm@nongnu.org Subject: [PATCH 08/17] target/arm: Generalize probe argument to allocation_tag_mem_internal Date: Fri, 17 Jul 2026 16:22:56 -0700 Message-ID: <20260717232306.378988-10-richard.henderson@linaro.org> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260717232306.378988-1-richard.henderson@linaro.org> References: <20260717232306.378988-1-richard.henderson@linaro.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2607:f8b0:4864:20::102f; envelope-from=richard.henderson@linaro.org; helo=mail-pj1-x102f.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linaro.org) X-ZM-MESSAGEID: 1784330670143158501 Content-Type: text/plain; charset="utf-8" We had a confusing relationship between 'probe' and 'ra =3D=3D 0'. Make this explicit via an enumeration. Signed-off-by: Richard Henderson --- target/arm/tcg/mte_helper.c | 130 ++++++++++++++++++++++-------------- 1 file changed, 80 insertions(+), 50 deletions(-) diff --git a/target/arm/tcg/mte_helper.c b/target/arm/tcg/mte_helper.c index e6e78634b6..997248bd57 100644 --- a/target/arm/tcg/mte_helper.c +++ b/target/arm/tcg/mte_helper.c @@ -88,26 +88,46 @@ typedef struct AllocationTagMem { MemTxAttrs attrs; } AllocationTagMem; =20 +typedef enum { + /* Trap on missing pages, invalid tag access, or watchpoints. */ + ATM_NORMAL, + /* Gracefully return no tag memory for invalid pages. */ + ATM_PROBE_PAGES, + /* + * Basic page access has already been checked, + * so a missing tlb entry is some sort of bug. + * Assert the tlb entry is present, but gracefully fail if tag + * access is not permitted to the page. + */ + ATM_ASSERT_PAGES, +} AllocationTagMemKind; + static AllocationTagMem allocation_tag_mem_internal(CPUARMState *env, int ptr_mmu_idx, vaddr ptr, MMUAccessType ptr_access, int ptr_size, MMUAccessType tag_access, - bool probe, uintptr_t ra) + uintptr_t ra, AllocationTagMemKind atm_kind) { AllocationTagMem ret =3D { }; =20 + assert((atm_kind >=3D ATM_PROBE_PAGES) =3D=3D (ra =3D=3D 0)); + #ifdef CONFIG_USER_ONLY vaddr clean_ptr =3D useronly_clean_ptr(ptr); int flags =3D page_get_flags(clean_ptr); int req_flags =3D ptr_access =3D=3D MMU_DATA_STORE ? PAGE_WRITE_ORG : = PAGE_READ; =20 if (unlikely(!(flags & req_flags))) { - if (probe) { + switch (atm_kind) { + case ATM_PROBE_PAGES: ret.flags =3D TLB_INVALID_MASK; goto fini; + case ATM_NORMAL: + cpu_loop_exit_sigsegv(env_cpu(env), ptr, ptr_access, + !(flags & PAGE_VALID), ra); + default: + g_assert_not_reached(); } - cpu_loop_exit_sigsegv(env_cpu(env), ptr, ptr_access, - !(flags & PAGE_VALID), ra); } =20 /* Require both MAP_ANON and PROT_MTE for the page. */ @@ -123,7 +143,6 @@ allocation_tag_mem_internal(CPUARMState *env, int ptr_m= mu_idx, ret.attrs =3D MEMTXATTRS_UNSPECIFIED; #else CPUTLBEntryFull *full; - int in_page; hwaddr ptr_paddr, tag_paddr, xlat; MemoryRegion *mr; ARMASIdx tag_asi; @@ -133,16 +152,12 @@ allocation_tag_mem_internal(CPUARMState *env, int ptr= _mmu_idx, * Probe the first byte of the virtual address. This raises an * exception for inaccessible pages, and resolves the virtual address * into the softmmu tlb. - * - * When RA =3D=3D 0, this is either a pure probe or a no-fault-expecte= d probe. - * Indicate to probe_access_flags no-fault, then either return NULL - * for the pure probe, or assert that we received a valid page for the - * no-fault-expected probe. */ ret.flags =3D probe_access_full(env, ptr, 0, ptr_access, ptr_mmu_idx, - ra =3D=3D 0, &ret.ptr_mem, &full, ra); + atm_kind >=3D ATM_PROBE_PAGES, + &ret.ptr_mem, &full, ra); if (unlikely(ret.flags & TLB_INVALID_MASK)) { - assert(probe); + assert(atm_kind =3D=3D ATM_PROBE_PAGES); goto fini; } ret.attrs =3D full->attrs; @@ -153,12 +168,11 @@ allocation_tag_mem_internal(CPUARMState *env, int ptr= _mmu_idx, =20 case 0xe0: /* NoTagAccess */ if (cpu_isar_feature(aa64_mteperm, env_archcpu(env))) { - if (probe) { + if (atm_kind >=3D ATM_PROBE_PAGES) { ret.ptr_mem =3D NULL; ret.flags =3D TLB_INVALID_MASK; goto fini; } - assert(ra); mte_perm_check_fail(env, ptr, ra, tag_access =3D=3D MMU_DATA_S= TORE); } /* fall through */ @@ -190,22 +204,21 @@ allocation_tag_mem_internal(CPUARMState *env, int ptr= _mmu_idx, * tag on the first page. * Any page access exception has priority over tag check exception. */ - in_page =3D -(ptr | TARGET_PAGE_MASK); - if (unlikely(ptr_size > in_page)) { - void *discard_mem; - int flags2 =3D probe_access_full(env, ptr + in_page, 0, ptr_access, - ptr_mmu_idx, ra =3D=3D 0, - &discard_mem, &full, ra); + if (atm_kind =3D=3D ATM_NORMAL) { + int in_page =3D -(ptr | TARGET_PAGE_MASK); + if (unlikely(ptr_size > in_page)) { + void *discard_mem; + ret.flags |=3D probe_access_full(env, ptr + in_page, 0, ptr_ac= cess, + ptr_mmu_idx, false, + &discard_mem, &full, ra); + } =20 - assert(!(flags2 & TLB_INVALID_MASK)); - ret.flags |=3D flags2; - } - - /* Any debug exception has priority over a tag check exception. */ - if (!probe && unlikely(ret.flags & TLB_WATCHPOINT)) { - int wp =3D ptr_access =3D=3D MMU_DATA_LOAD ? BP_MEM_READ : BP_MEM_= WRITE; - assert(ra !=3D 0); - cpu_check_watchpoint(env_cpu(env), ptr, ptr_size, ret.attrs, wp, r= a); + /* Any debug exception has priority over a tag check exception. */ + if (unlikely(ret.flags & TLB_WATCHPOINT)) { + int wp =3D ptr_access =3D=3D MMU_DATA_LOAD ? BP_MEM_READ : BP_= MEM_WRITE; + cpu_check_watchpoint(env_cpu(env), ptr, ptr_size, + ret.attrs, wp, ra); + } } =20 /* Convert to the physical address in tag space. */ @@ -266,8 +279,8 @@ static uint8_t *allocation_tag_mem(CPUARMState *env, in= t ptr_mmu_idx, uintptr_t ra) { return allocation_tag_mem_internal(env, ptr_mmu_idx, ptr, ptr_access, - ptr_size, tag_access, false, ra) - .tag_mem; + ptr_size, tag_access, + ra, ATM_NORMAL).tag_mem; } =20 uint8_t *allocation_tag_mem_probe(CPUARMState *env, int ptr_mmu_idx, @@ -275,8 +288,8 @@ uint8_t *allocation_tag_mem_probe(CPUARMState *env, int= ptr_mmu_idx, int ptr_size, MMUAccessType tag_access) { return allocation_tag_mem_internal(env, ptr_mmu_idx, ptr, ptr_access, - ptr_size, tag_access, true, 0) - .tag_mem; + ptr_size, tag_access, + 0, ATM_PROBE_PAGES).tag_mem; } =20 uint64_t HELPER(irg)(CPUARMState *env, uint64_t rn, uint64_t rm) @@ -880,6 +893,7 @@ static int checkNrev(uint8_t *mem, int odd, int cmp, in= t count) * @desc: MTEDESC descriptor * @ptr: virtual address of the base of the access * @fault: return virtual address of the first check failure + * @kind: per allocation_tag_mem_internal * * Internal routine for both mte_probe and mte_check. * Return zero on failure, filling in *fault. @@ -887,13 +901,14 @@ static int checkNrev(uint8_t *mem, int odd, int cmp, = int count) * Return positive on success with tbi enabled. */ static int mte_probe_int(CPUARMState *env, uint32_t desc, uint64_t ptr, - uintptr_t ra, uint64_t *fault) + uintptr_t ra, uint64_t *fault, + AllocationTagMemKind atm_kind) { int mmu_idx, ptr_tag, bit55; uint64_t ptr_last, prev_page, next_page; uint64_t tag_first, tag_last; uint32_t sizem1, tag_count, n, c; - uint8_t *mem1, *mem2; + AllocationTagMem r1, r2; MMUAccessType type; =20 bit55 =3D extract64(ptr, 55, 1); @@ -931,9 +946,14 @@ static int mte_probe_int(CPUARMState *env, uint32_t de= sc, uint64_t ptr, =20 if (likely(tag_last - prev_page < TARGET_PAGE_SIZE)) { /* Memory access stays on one page. */ - mem1 =3D allocation_tag_mem(env, mmu_idx, ptr, type, sizem1 + 1, - MMU_DATA_LOAD, ra); - if (!mem1) { + r1 =3D allocation_tag_mem_internal(env, mmu_idx, ptr, type, sizem1= + 1, + MMU_DATA_LOAD, ra, atm_kind); + if (unlikely(r1.flags & TLB_INVALID_MASK)) { + /* Tag access disabled on an otherwise accessible page. */ + assert(atm_kind =3D=3D ATM_ASSERT_PAGES); + return 0; + } + if (r1.tag_mem =3D=3D NULL) { /* * If mtx is enabled, then the access is MemTag_CanonicallyTag= ged, * otherwise it is Untagged. See AArch64.S1DecodeMemAttrs and @@ -945,15 +965,22 @@ static int mte_probe_int(CPUARMState *env, uint32_t d= esc, uint64_t ptr, return 1; } /* Perform all of the comparisons. */ - n =3D checkN(mem1, ptr & TAG_GRANULE, ptr_tag, tag_count); + n =3D checkN(r1.tag_mem, ptr & TAG_GRANULE, ptr_tag, tag_count); } else { /* Memory access crosses to next page. */ - mem1 =3D allocation_tag_mem(env, mmu_idx, ptr, type, next_page - p= tr, - MMU_DATA_LOAD, ra); + r1 =3D allocation_tag_mem_internal(env, mmu_idx, ptr, type, + next_page - ptr, MMU_DATA_LOAD, + ra, atm_kind); =20 - mem2 =3D allocation_tag_mem(env, mmu_idx, next_page, type, - ptr_last - next_page + 1, - MMU_DATA_LOAD, ra); + if (r1.flags & TLB_INVALID_MASK) { + /* Tag access disabled on an otherwise accessible page. */ + assert(atm_kind =3D=3D ATM_ASSERT_PAGES); + return 0; + } + + r2 =3D allocation_tag_mem_internal(env, mmu_idx, next_page, type, + ptr_last - next_page + 1, + MMU_DATA_LOAD, ra, atm_kind); =20 /* * Perform all of the comparisons. @@ -962,15 +989,18 @@ static int mte_probe_int(CPUARMState *env, uint32_t d= esc, uint64_t ptr, * happen with or without mtx (canonical tagging) enabled. */ n =3D c =3D (next_page - tag_first) / TAG_GRANULE; - if (mem1) { - n =3D checkN(mem1, ptr & TAG_GRANULE, ptr_tag, c); + if (r1.tag_mem) { + n =3D checkN(r1.tag_mem, ptr & TAG_GRANULE, ptr_tag, c); } else if (mtx_check(desc, bit55) && !tag_is_canonical(ptr_tag, bit55)) { return 0; } if (n =3D=3D c) { - if (mem2) { - n +=3D checkN(mem2, 0, ptr_tag, tag_count - c); + if (r2.flags & TLB_INVALID_MASK) { + /* Tag access disabled on an otherwise accessible page. */ + assert(atm_kind =3D=3D ATM_ASSERT_PAGES); + } else if (r2.tag_mem) { + n +=3D checkN(r2.tag_mem, 0, ptr_tag, tag_count - c); } else if (!mtx_check(desc, bit55) || tag_is_canonical(ptr_tag, bit55)) { return 1; @@ -996,7 +1026,7 @@ static int mte_probe_int(CPUARMState *env, uint32_t de= sc, uint64_t ptr, uint64_t mte_check(CPUARMState *env, uint32_t desc, uint64_t ptr, uintptr_= t ra) { uint64_t fault; - int ret =3D mte_probe_int(env, desc, ptr, ra, &fault); + int ret =3D mte_probe_int(env, desc, ptr, ra, &fault, ATM_NORMAL); =20 if (unlikely(ret =3D=3D 0)) { mte_check_fail(env, desc, fault, ra); @@ -1038,7 +1068,7 @@ uint64_t HELPER(mte_check)(CPUARMState *env, uint32_t= desc, uint64_t ptr) bool mte_probe(CPUARMState *env, uint32_t desc, uint64_t ptr) { uint64_t fault; - int ret =3D mte_probe_int(env, desc, ptr, 0, &fault); + int ret =3D mte_probe_int(env, desc, ptr, 0, &fault, ATM_ASSERT_PAGES); =20 return ret !=3D 0; } --=20 2.43.0 From nobody Sat Jul 25 13:41:30 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linaro.org ARC-Seal: i=1; a=rsa-sha256; t=1784330814; cv=none; d=zohomail.com; s=zohoarc; b=VNlHWyQIB6AZwL2iE06Uu5wyRr1SpvLpDtvoHnnWe0gl9ryD9lLDwQczrM+GVdAA8SXV5tUcAzBcFyPp7T6lmdIdOyK3TTiSBgJTv/iR2ameTErQNBeSusqtTmmgRhEBJMrGlsRUSVHGmUhFRu0W2mHY3tg+5ookVxhFq6W1Vuo= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784330814; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=mZTwqniLxRl1m+Mbcq6QdOuxrIA10SI062fGGhdr3eE=; b=GJNx2FthyAQd5wz6O3mZkFGBtnBDS9WD/oIHWh7GamjU1e+Ouy+N1CukRHbfG4ActypWLYGbpS5KnIxvDLfznsxpAzmTOrpPAg7UriTb9Jdi5tBZta7aJF+nUUNThJad6xsdanOIK8kAJ8d805mlNSTEeb66f9LEhQUTJIN0bKs= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784330814802817.288545951387; Fri, 17 Jul 2026 16:26:54 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wkrtu-0001YO-Dk; Fri, 17 Jul 2026 19:23:26 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkrts-0001X9-Oc for qemu-devel@nongnu.org; Fri, 17 Jul 2026 19:23:24 -0400 Received: from mail-pj1-x1033.google.com ([2607:f8b0:4864:20::1033]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wkrtp-0006zX-KF for qemu-devel@nongnu.org; Fri, 17 Jul 2026 19:23:24 -0400 Received: by mail-pj1-x1033.google.com with SMTP id 98e67ed59e1d1-38e07ebd263so3453858a91.1 for ; Fri, 17 Jul 2026 16:23:21 -0700 (PDT) Received: from stoup.. ([32.140.233.50]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13ce2a18a47sm8186261c88.8.2026.07.17.16.23.18 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 17 Jul 2026 16:23:19 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1784330600; x=1784935400; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=mZTwqniLxRl1m+Mbcq6QdOuxrIA10SI062fGGhdr3eE=; b=C4lIwUMCm+LHM7FJ9yZAFzuPJIlIm781TOP0bDaz+GTi12KLeTc1TGjGpVSpdq5ve5 BChw47oM5wzuhxvcFjhCPlprYzbPddOtTxGIokZocor8Q7HrKJmZ2KluOqBNnOBP0wHV 2Moapuku5mnQYZFeiLJLg6sEEE/N/mEnmxZNSUop12Cnk5yB+hFXLS60uPltTsaEVN0p /YT8Kd/OgqeSV9D+DZNN+pATzltlvKhqVHU13l0IyTphDqDT0HA003MUNtPTQBVGu5Dn +nlG2z+n/KDoNmM35zo3PEqABqR6ueu5Pkhp27WeLPhne7BT/jwaoGOWB5D2bki8KDo0 aNEQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784330600; x=1784935400; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=mZTwqniLxRl1m+Mbcq6QdOuxrIA10SI062fGGhdr3eE=; b=msTgRZX57uEZ4mwXKGOtN4JG2KzqsGmbnaT+ZUUnqFA0CNnk2IPjeirbP1eAEd9wOP phAcXa3f2ieV+0q7i52N9Arwv7yk5lkMWH/wKQlr+Z0k6ffR4TGtRvJQ5S1hPRNA2spR LI4EVWw7zfM9s655v3H5f8eCGO9PqZOFbu53xjLiYth+10HuCq8lNfq17UtdW1HJlT25 QQ3fpGT1NEwP9Jzpd1w4oqAZkO0Vt3C8bl/o8AIeeR6B5BEn+EhUzcyEpdJdVKlTpbS3 h01ny083HFT1Q9ait1UzN07bjh1PmgWxNSMBBbv1+t6833tN8FIOk73n93SUqsiqnkp9 sn4w== X-Gm-Message-State: AOJu0YyXpBF6DkJFs0eUj2jk7Z5BrTjOCIecNXpXY1PLrH94/t3fccLA aq5SL6roR4AlsdCfa+IGej07zsW2AbISqbfr11nUYI/uAYU8aaP+iVgL7lscazgppUBWC51tQH+ 465v9 X-Gm-Gg: AfdE7clYh9gZSAA7xo1zohDCaBLj0DgT73OdQPBIR3GSPLFnAWlt3z6tv+lybieBDFq 9NglnoZrH8/v885Jv8XVoDiVwb2o3NuQXH36cWySlEqHpYPRfxoHO0JOnUKbkpKZtAR3CxlNCSu y6biijj1OnYplocWgpNiWY8D1aUJIU0iE8knbhduYZtX2PG3YV6OY/OBSKKHoD6BYzZGESQFWvm ujWbAe88ZFIJNhymVtsKNq8Zm9O8XfWh347Ah6mGK6AdvDtGT+iLZseekXiIWw+EFHmPi9TiCm1 U/W6Ay+Ru7leS0rXKG5yf3eUScNOysxtQTib+4ZAO+BE3cyry23EeB/IjFc0UEPG1a6M6q6a1fI Alck41kkDeKWI0wTLvfUQk+DUltBavHVzZmj+Rd5Sa6S0L2xcp7q6RY9xmUa/U6MlAT9S3RLHGs J9V8rnNfs= X-Received: by 2002:a17:90b:3ec7:b0:38e:cb1:8ec9 with SMTP id 98e67ed59e1d1-38e4b585bfcmr4868782a91.42.1784330600120; Fri, 17 Jul 2026 16:23:20 -0700 (PDT) From: Richard Henderson To: qemu-devel@nongnu.org Cc: qemu-arm@nongnu.org Subject: [PATCH 09/17] target/arm: Drop TLB_MMIO check in allocation_tag_mem_internal Date: Fri, 17 Jul 2026 16:22:57 -0700 Message-ID: <20260717232306.378988-11-richard.henderson@linaro.org> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260717232306.378988-1-richard.henderson@linaro.org> References: <20260717232306.378988-1-richard.henderson@linaro.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2607:f8b0:4864:20::1033; envelope-from=richard.henderson@linaro.org; helo=mail-pj1-x1033.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linaro.org) X-ZM-MESSAGEID: 1784330816529158500 Content-Type: text/plain; charset="utf-8" There is a memory_region_is_ram check later that actually does that this was trying to do. Signed-off-by: Richard Henderson --- target/arm/tcg/mte_helper.c | 11 ----------- 1 file changed, 11 deletions(-) diff --git a/target/arm/tcg/mte_helper.c b/target/arm/tcg/mte_helper.c index 997248bd57..6177dea842 100644 --- a/target/arm/tcg/mte_helper.c +++ b/target/arm/tcg/mte_helper.c @@ -181,17 +181,6 @@ allocation_tag_mem_internal(CPUARMState *env, int ptr_= mmu_idx, goto fini; } =20 - /* - * If not backed by host ram, there is no tag storage: access unchecke= d. - * This is probably a guest os bug though, so log it. - */ - if (unlikely(ret.flags & TLB_MMIO)) { - qemu_log_mask(LOG_GUEST_ERROR, - "Page @ 0x%" PRIx64 " indicates Tagged Normal memory= " - "but is not backed by host ram\n", ptr); - goto fini; - } - /* * Remember this across the second lookup below, * which may invalidate this pointer via tlb resize. --=20 2.43.0 From nobody Sat Jul 25 13:41:30 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linaro.org ARC-Seal: i=1; a=rsa-sha256; t=1784330807; cv=none; d=zohomail.com; s=zohoarc; b=Qka6QrFnV38gRQ81N9XUVFG/t9Mmlk/38yDIPQfUNJcrU2SpbAzn5++LexhhxMi0+1aJ2ffT4+QxMCWMG0uMsarYy/AihJYfKkYpey7INDtpB4jdLcldHG4HNf24a3D+Y2IY9xzHt8fTvnmNrzJhEh/cKUu5rAwxXJF1/MsqiTk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784330807; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=lhhqC/hOwEz9oJ5MIevvbAiCo2J0aN9y+C175uWjrEg=; b=RhHW8cGz3HYwqVCLXYjoHOpqU6yX92opODEAUlfZvGEgyh72JnSceY96Lz6zIydbhgQFjYPqE/X0FLTVit/eJ0dhuOQ+IG79PFWhTKJe8RJqT6AvP+tqHLTX83WnHGok5kgp4XlxbkLjBEVR/l955RsvjLPLfukh+dI4q0M3dpA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784330807711948.4499254727484; Fri, 17 Jul 2026 16:26:47 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wkrtu-0001ZA-TB; Fri, 17 Jul 2026 19:23:26 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkrtt-0001Xj-HK for qemu-devel@nongnu.org; Fri, 17 Jul 2026 19:23:25 -0400 Received: from mail-pj1-x1031.google.com ([2607:f8b0:4864:20::1031]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wkrtr-0006zz-8u for qemu-devel@nongnu.org; Fri, 17 Jul 2026 19:23:25 -0400 Received: by mail-pj1-x1031.google.com with SMTP id 98e67ed59e1d1-38dfe7eb825so4156912a91.0 for ; Fri, 17 Jul 2026 16:23:22 -0700 (PDT) Received: from stoup.. ([32.140.233.50]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13ce2a18a47sm8186261c88.8.2026.07.17.16.23.20 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 17 Jul 2026 16:23:21 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1784330602; x=1784935402; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=lhhqC/hOwEz9oJ5MIevvbAiCo2J0aN9y+C175uWjrEg=; b=K14lUA2q0RzRzlCOUa8/TfpckDJkZ0PzCrkq7YzK/NIv0ABIbivtnwbBMhRmkKI9x7 ghScR7fag77WOmnXhVKCwevKaY7Iq24ddzVjK2JOaj/xMHp2nVn+dZra2v9o1i5sv1Ow 6B+ZX6vdZq5+ioi29W7szGmgEK6bI3HgoTepLGKhTAh/yZHbu0tpxVdHUw7t+K973/Eu UKGdhg5dhBfe8aj/6FFjkJttNaopqYTy7fkd6wuDOQJta9bvti7/FN7/221nk2KIzoS8 gNwtW5iukcPVIaNqj1nKfzzJyNiwlB4v6Jm9KSLoWYq7ZDtwMrYO0Wx55UzLd4NqEGdn 6lrA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784330602; x=1784935402; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=lhhqC/hOwEz9oJ5MIevvbAiCo2J0aN9y+C175uWjrEg=; b=CZ2dANV4VbFVVL7pBlMFGdHsXGbRSt3cwX6LquhclLPG6PkJq5ETWRUbdNsSoI6BZn 7D082WyeLG/INlrfmTSwheMSbDBiitz24US/eei6ScuzmpTevG02kFq7DcIa0imPKcqk 41SK48AqZc/fRXlWANRFm2FY7AbFu7/XdKyeR0Ailloj+DNaQcU6QRI+LxX7kQMkW8Rw j6WuA0ELa5z2mLUR9xrnLmyFGFH/DGM4MZWhSPAEjfNfiaV1YTeFBxRVjg9iilO/I+DL 9rv8AIkY4JgMpmGkYuEqWWLVvcimtazHYuP0xMb7SbBM1eH+luVp3eU3M1uInlcCfZA2 Gjxw== X-Gm-Message-State: AOJu0YwCCtoCmNtidxdZlx17yret5y+fldlgZJqy6SCta4WzHkqJZDx0 K9tI2LVEZ9cunuRoz+d7q9WpvYk8zzRDAeIFmkwpiYVbsW8ormerYMpzGA/i8ijf9Kie1XfiMc8 QOPYS X-Gm-Gg: AfdE7cmZKUwnPJLcp4RJUzWcQ1LZy+aI03tkQxQIMjkOMSG00uvHHXs55XodXCqyxBK YkqIFqaQeo+gEee3QcNdeRVsXnrrVharLRrvuq6yVIYdR+yRH8xmEk6jQTcdqu/fRYNyafOMu3T OwIMJaeZHqn3fJ3+gFzcBMCX2icAwlEDvXFzYR6nvNXiNtOxWv34JuBJzb91PY6XyFYfs/7nnWn inKWfQ7OcbST2y1dxTaEo35pHpeFKS0/MFe1ZgZ0gw8lJ7HbZnFxQX3NXXKOChkQViQllyxT5N0 WyAbHtaaJ/6BIKpF51ijER39ryU6dJA8K8CpVEWUgnxy0JRWKoW/jnrlZdArOcp7/1Ve5zlvqaU zBERugsAvNZXlms1HuKibpVMiuP4QKz5dIYzFEvksYwsH2DGzJxt3YMmmVriQwAkmC/4GQpvskE aR/ws1JPg= X-Received: by 2002:a17:90b:534d:b0:37f:a915:1c29 with SMTP id 98e67ed59e1d1-38e4b42ebd6mr4918785a91.19.1784330601769; Fri, 17 Jul 2026 16:23:21 -0700 (PDT) From: Richard Henderson To: qemu-devel@nongnu.org Cc: qemu-arm@nongnu.org Subject: [PATCH 10/17] target/arm: Probe second page earlier in allocation_tag_mem_internal Date: Fri, 17 Jul 2026 16:22:58 -0700 Message-ID: <20260717232306.378988-12-richard.henderson@linaro.org> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260717232306.378988-1-richard.henderson@linaro.org> References: <20260717232306.378988-1-richard.henderson@linaro.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2607:f8b0:4864:20::1031; envelope-from=richard.henderson@linaro.org; helo=mail-pj1-x1031.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linaro.org) X-ZM-MESSAGEID: 1784330808500158500 Content-Type: text/plain; charset="utf-8" Translation faults have priority over everything else in this function. We were failing to trap for the second page entirely in the user-only case, and when tag access is disabled on the first page for the system case. Signed-off-by: Richard Henderson --- target/arm/tcg/mte_helper.c | 64 +++++++++++++++++++++---------------- 1 file changed, 36 insertions(+), 28 deletions(-) diff --git a/target/arm/tcg/mte_helper.c b/target/arm/tcg/mte_helper.c index 6177dea842..6e1f701c4c 100644 --- a/target/arm/tcg/mte_helper.c +++ b/target/arm/tcg/mte_helper.c @@ -129,6 +129,13 @@ allocation_tag_mem_internal(CPUARMState *env, int ptr_= mmu_idx, g_assert_not_reached(); } } + if (atm_kind =3D=3D ATM_NORMAL) { + int in_page =3D -(ptr | TARGET_PAGE_MASK); + if (unlikely(ptr_size > in_page)) { + probe_access(env, ptr + in_page, ptr_size - in_page, + ptr_access, MMU_USER_IDX, ra); + } + } =20 /* Require both MAP_ANON and PROT_MTE for the page. */ if ((flags & PAGE_ANON) && (flags & PAGE_MTE)) { @@ -147,6 +154,7 @@ allocation_tag_mem_internal(CPUARMState *env, int ptr_m= mu_idx, MemoryRegion *mr; ARMASIdx tag_asi; AddressSpace *tag_as; + uint8_t pte_attrs; =20 /* * Probe the first byte of the virtual address. This raises an @@ -160,9 +168,32 @@ allocation_tag_mem_internal(CPUARMState *env, int ptr_= mmu_idx, assert(atm_kind =3D=3D ATM_PROBE_PAGES); goto fini; } + + /* + * Remember these across the second lookup below, + * which may invalidate this pointer via tlb resize. + */ + ptr_paddr =3D full->phys_addr | (ptr & ~TARGET_PAGE_MASK); + pte_attrs =3D full->extra.arm.pte_attrs; ret.attrs =3D full->attrs; =20 - switch (full->extra.arm.pte_attrs) { + /* + * The Normal memory access can extend to the next page. E.g. a single + * 8-byte access to the last byte of a page will check only the last + * tag on the first page. + * Any page access exception has priority over tag check exception. + */ + if (atm_kind =3D=3D ATM_NORMAL) { + int in_page =3D -(ptr | TARGET_PAGE_MASK); + if (unlikely(ptr_size > in_page)) { + void *discard_mem; + ret.flags |=3D probe_access_full(env, ptr + in_page, 0, ptr_ac= cess, + ptr_mmu_idx, false, + &discard_mem, &full, ra); + } + } + + switch (pte_attrs) { case 0xf0: /* Tagged */ break; =20 @@ -181,33 +212,10 @@ allocation_tag_mem_internal(CPUARMState *env, int ptr= _mmu_idx, goto fini; } =20 - /* - * Remember this across the second lookup below, - * which may invalidate this pointer via tlb resize. - */ - ptr_paddr =3D full->phys_addr | (ptr & ~TARGET_PAGE_MASK); - - /* - * The Normal memory access can extend to the next page. E.g. a single - * 8-byte access to the last byte of a page will check only the last - * tag on the first page. - * Any page access exception has priority over tag check exception. - */ - if (atm_kind =3D=3D ATM_NORMAL) { - int in_page =3D -(ptr | TARGET_PAGE_MASK); - if (unlikely(ptr_size > in_page)) { - void *discard_mem; - ret.flags |=3D probe_access_full(env, ptr + in_page, 0, ptr_ac= cess, - ptr_mmu_idx, false, - &discard_mem, &full, ra); - } - - /* Any debug exception has priority over a tag check exception. */ - if (unlikely(ret.flags & TLB_WATCHPOINT)) { - int wp =3D ptr_access =3D=3D MMU_DATA_LOAD ? BP_MEM_READ : BP_= MEM_WRITE; - cpu_check_watchpoint(env_cpu(env), ptr, ptr_size, - ret.attrs, wp, ra); - } + /* Any debug exception has priority over a tag check exception. */ + if (unlikely(ret.flags & TLB_WATCHPOINT) && atm_kind =3D=3D ATM_NORMAL= ) { + int wp =3D ptr_access =3D=3D MMU_DATA_LOAD ? BP_MEM_READ : BP_MEM_= WRITE; + cpu_check_watchpoint(env_cpu(env), ptr, ptr_size, ret.attrs, wp, r= a); } =20 /* Convert to the physical address in tag space. */ --=20 2.43.0 From nobody Sat Jul 25 13:41:30 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linaro.org ARC-Seal: i=1; a=rsa-sha256; t=1784330644; cv=none; d=zohomail.com; s=zohoarc; b=MzrdPM+oXe+TSwrBaT34S9J5yDA+Wxq2+EJHm2hI0i8YxkzIuzFTVQaJDgFJibvKm9yWAkFkaW83tCzSWOiJ6gpiShT8GEmr44hnI/h8bljD3SPjJAFpH6r/uZ3EtrgmbBcJa07/Ph0dayjgGa+MwYlOI4PBilYF8KmJ0sQ0e0M= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784330644; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=w27FmDXuFalab8HQ6vxOQFZ2EK3lrOZoQbI54mzAq/A=; b=j9F4PYXX5un3cTfbQFi5RVSadYyJU0ZgjC++Iw4kcxtNbXHNIPv/Pr03KrFDQTdMukHFIq4+29sh6ZYUqpZD1VUmzgrRiwhObz9b8aqADFXd5/0C97lt416h+reQP4XfqbH40QqqRKkDyCoC5kiBo9r/7sbR0o8uZIW/tLnBZAw= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784330644786312.94835390517335; Fri, 17 Jul 2026 16:24:04 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wkrty-0001bK-Vt; Fri, 17 Jul 2026 19:23:31 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkrtu-0001Y6-4o for qemu-devel@nongnu.org; Fri, 17 Jul 2026 19:23:26 -0400 Received: from mail-pj1-x102c.google.com ([2607:f8b0:4864:20::102c]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wkrts-00070S-Gc for qemu-devel@nongnu.org; Fri, 17 Jul 2026 19:23:25 -0400 Received: by mail-pj1-x102c.google.com with SMTP id 98e67ed59e1d1-382ef647e20so7821279a91.1 for ; Fri, 17 Jul 2026 16:23:24 -0700 (PDT) Received: from stoup.. ([32.140.233.50]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13ce2a18a47sm8186261c88.8.2026.07.17.16.23.22 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 17 Jul 2026 16:23:22 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1784330603; x=1784935403; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=w27FmDXuFalab8HQ6vxOQFZ2EK3lrOZoQbI54mzAq/A=; b=mUDP58AIIi+9DdvqcfsIHB53V46mXMV/DnLiUSGK3wEH5Y15BqBtiHvGR7GwB7HHai vaMJHXOM9rYFyONLnf2xutqrR/AxG4iBuF+EIkYXlnHGhnPizIkZr+UZgqBBSgtB3dL1 ghsn9V1IVZa7rE0LbPaQqDRXPKrJHp0bMKH388ykZjFDGbIaTaragPmiGkYl23ufu8pr Mu9kNUT1mulwI9ouRZpLTP+XEV1A+m6JJQD5bT31dPr2yOWLMyhjdizFGlfjRjCUE23z cNjSeu/ugWzqN0Ot5Mogs7JUf9SB40q8urU3+zoFxx0Hyqw5HcgezLYehynmPbpbePGM AZMg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784330603; x=1784935403; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=w27FmDXuFalab8HQ6vxOQFZ2EK3lrOZoQbI54mzAq/A=; b=P+qnxZfQAZO4vmHPXYX+q3qRyZXUHSRre+V6zOjWmdHczTUPPWDsNNcZl/dgaEj5c3 w+DnBGMfTMYKGaEqNNKc60/+ZnzyVGmz+Y9qAjNHIaZDTYHZgok4/vVKqtLVTLtlX/Qp R+6TDcBWHCExSCCkAoldIqdCUaM9Fl1+S5OFRegv6ugPRlAhpwWJ69sc05EAce5bl1gs /LNfa/ABaE6IK5RUvrkW6yt4v6/tbQDiaBzLROta1qUprt0PcI3/muHHDVi5deYskp97 JnwTuaPeqazrYcZ0x8gz/g5um1iUynAQpFE/uWc8Drn9b9ziKjEoCDNbQwqEwG8K+xVK Z1IQ== X-Gm-Message-State: AOJu0YxLAd/yYC9JIOSV6255pHlcDU47sLqIaxFFS0JM7i6gVaKMIC4s zDJbsv8SCZB/HDvmexmerZEQzK1Qx+HxxczMi+F+cQIwsLN6PGEd9vgDPiXhYZq9VEqVk38XD2u M+gMo X-Gm-Gg: AfdE7ckTw9Z1Xhvr4Ub2eL53ZBW+PFa/CJBmmfzHro/GLfqX0gGKNIY49M2ADWDga/t 2Y6/77/efS9RZ3Rt9BwpiQgvBgyuHf7YJxK7oOJreOQZREom1Li+62SGZF8g+xlV5/YM1Au36w/ mmURx2SxhRLTa2PNRNc27tT21FgJP6VTAabwDsr1EMTcCGZcTJL5WciIaHcF9L/kbUrrSEOxZcu Ewx96c/1tbvLOn83cjShB25sZBvqaE44AHX7v3Bq+yxGM9nro6xfAZ5rw6rRpWEZUPlmblOu5x9 zx5aj2nC/uwy9+/VjtvwL56D9agWp9EXuu1by9oDtYQ9MpLD2mzNXoQ+rChdFiQAOAulYlrWBdV sAFXOXQtXZpFGwbm5V5KOq+dnRp2qoH1AgywDqlJfhM/6Hh5tVhWWJwrRgspR8+WqpkoMkWT3DC kJgZ2Xcwo= X-Received: by 2002:a17:90b:3cce:b0:37f:db06:229c with SMTP id 98e67ed59e1d1-38e4b534228mr5178982a91.22.1784330603069; Fri, 17 Jul 2026 16:23:23 -0700 (PDT) From: Richard Henderson To: qemu-devel@nongnu.org Cc: qemu-arm@nongnu.org Subject: [PATCH 11/17] target/arm: Expand dczid_bs in DisasContext Date: Fri, 17 Jul 2026 16:22:59 -0700 Message-ID: <20260717232306.378988-13-richard.henderson@linaro.org> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260717232306.378988-1-richard.henderson@linaro.org> References: <20260717232306.378988-1-richard.henderson@linaro.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2607:f8b0:4864:20::102c; envelope-from=richard.henderson@linaro.org; helo=mail-pj1-x102c.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linaro.org) X-ZM-MESSAGEID: 1784330645909158500 Content-Type: text/plain; charset="utf-8" Store the true blocksize, not the encoding. Signed-off-by: Richard Henderson Reviewed-by: Philippe Mathieu-Daud=C3=A9 --- target/arm/tcg/translate.h | 4 ++-- target/arm/tcg/translate-a64.c | 5 ++--- 2 files changed, 4 insertions(+), 5 deletions(-) diff --git a/target/arm/tcg/translate.h b/target/arm/tcg/translate.h index a3d03159ad..bab91eea22 100644 --- a/target/arm/tcg/translate.h +++ b/target/arm/tcg/translate.h @@ -197,14 +197,14 @@ typedef struct DisasContext { * < 0, set by the current instruction. */ int8_t btype; - /* A copy of DCZID_EL0.BS. */ - uint8_t dcz_blocksize; /* A copy of cpu->gm_blocksize. */ uint8_t gm_blocksize; /* True if the current insn_start has been updated. */ bool insn_start_updated; /* FPMR access exception EL or 0 if enabled. */ uint8_t fpmr_el; + /* An expansion of DCZID_EL0.BS. */ + int dcz_blocksize; /* Offset from VNCR_EL2 when FEAT_NV2 redirects this reg to memory */ uint32_t nv2_redirect_offset; } DisasContext; diff --git a/target/arm/tcg/translate-a64.c b/target/arm/tcg/translate-a64.c index 1780490065..3d838a4cc1 100644 --- a/target/arm/tcg/translate-a64.c +++ b/target/arm/tcg/translate-a64.c @@ -4752,7 +4752,6 @@ static bool trans_LD_single_repl(DisasContext *s, arg= _LD_single_repl *a) static bool trans_STZGM(DisasContext *s, arg_ldst_tag *a) { TCGv_i64 addr, clean_addr, tcg_rt; - int size =3D 4 << s->dcz_blocksize; =20 if (!dc_isar_feature(aa64_mte, s)) { return false; @@ -4777,7 +4776,7 @@ static bool trans_STZGM(DisasContext *s, arg_ldst_tag= *a) * except the alignment happens before the access. */ clean_addr =3D clean_data_tbi(s, addr); - tcg_gen_andi_i64(clean_addr, clean_addr, -size); + tcg_gen_andi_i64(clean_addr, clean_addr, -s->dcz_blocksize); gen_helper_dc_zva(tcg_env, clean_addr); return true; } @@ -11055,7 +11054,7 @@ static void aarch64_tr_init_disas_context(DisasCont= extBase *dcbase, dc->vec_stride =3D 0; dc->cp_regs =3D arm_cpu->cp_regs; dc->features =3D env->features; - dc->dcz_blocksize =3D get_dczid_bs(arm_cpu); + dc->dcz_blocksize =3D 4 << get_dczid_bs(arm_cpu); dc->gm_blocksize =3D arm_cpu->gm_blocksize; =20 #ifdef CONFIG_USER_ONLY --=20 2.43.0 From nobody Sat Jul 25 13:41:30 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linaro.org ARC-Seal: i=1; a=rsa-sha256; t=1784330841; cv=none; d=zohomail.com; s=zohoarc; b=lXaWq7QnSXa0q4V83dobnoFwwqfJXQxoMPzag9OsOpdxMMIVNHPfTpP6NMskO+rzAoSX1b+i+bUY1o1hP0ozkmwQTSHTosG7cDreQLMk/+aFunwT/Wjm1jwrydYSsU062vECLkieA9QPO1GeYvYPfQLZ3ASCfmQAeSd/K5BvaHE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784330841; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=axCNshnRaz9sCH+JYe9sKgtaQsPlSADENghL889xQUY=; b=kvtKqPOEvuWVRm7mM007tnv1YFHKeqEo9ae+WvtuRPpgvNdK9BuhLSprGDs0ikpCYKGW4/VMHyghxR7HgAVaIpg7SiPkKzU1rNKGaSVPbTQqAsHuz6TeICTVqwefMkpgNaaqnuRHK3sRyl+yob6BEq2xAuJDygN9UgsqGYVl7GQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784330841901913.1643583323131; Fri, 17 Jul 2026 16:27:21 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wkru0-0001bl-Eh; Fri, 17 Jul 2026 19:23:32 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkrtw-0001Zw-1K for qemu-devel@nongnu.org; Fri, 17 Jul 2026 19:23:28 -0400 Received: from mail-pj1-x1032.google.com ([2607:f8b0:4864:20::1032]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wkrtt-000717-Vj for qemu-devel@nongnu.org; Fri, 17 Jul 2026 19:23:27 -0400 Received: by mail-pj1-x1032.google.com with SMTP id 98e67ed59e1d1-38e58034d05so557253a91.2 for ; Fri, 17 Jul 2026 16:23:25 -0700 (PDT) Received: from stoup.. ([32.140.233.50]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13ce2a18a47sm8186261c88.8.2026.07.17.16.23.23 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 17 Jul 2026 16:23:23 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1784330604; x=1784935404; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=axCNshnRaz9sCH+JYe9sKgtaQsPlSADENghL889xQUY=; b=jMQXmI+GP4Z8tRctsLixEZRmnkvyHeA3JQdlBwN/T1pm+PIvWbg8ZWZNJuDdE/7tb5 zWDCWHwi+Hyq8bBx++/Nw7adz90JV7gtH7D/iJq4VromN1ww/6anJQJIigq9zPN+VDyN vlUfIzS6Fdc8mD7zSzTkElqxoYBuQnDSB1w+75M/Coev23PTX8ubEaSEM8uMZkqbKbD+ 0SX2lj898Ul22tmbaMXl1HvhYyUdiCvpuX1RA5V57k/CjwPNwD4oSGOLPh9S9NjxO05y pI+/lrwoGH6cHRuEfv6o1F6XFZsZSo98tGujNXs8h0EhahDjxvgtPJxGJ5YqWsFDa1kC T5BA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784330604; x=1784935404; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=axCNshnRaz9sCH+JYe9sKgtaQsPlSADENghL889xQUY=; b=k2xSY6m69lUN9eqADWiXFact4FvFV/+QnTpQTnaFa05fWbO6BmNkqp+YVOR92PL576 6LnCLuISd2FSE0duRibww+/hl69hrFitKM/sNl/eVGj3OnEF4lBGvedx4h4l1fWPZL61 KVXTtS/MA1TWoo2JZApmK6cuiFKajMMTvpcIR/9PmkDolhxHFTbc+aOD7f260kAKcenT AggOVUctnJlK3Ehcu1P53X3JphqIa2sIqjpxlCfpx0HmTUUecyr7r9isIT8L1iLjIQzt RkDkTLNIhGVzxgErJvsqZ2TDWnZuSLpdpAvejTxdpxF1OFSwxqbIAL1eOSbyROz4ILa6 8VZA== X-Gm-Message-State: AOJu0YxnaeJUgdrClK1N4+KAIzJFfeCVjA5MJhugDqhLwjVUCQTlsRN7 Iws9BzNSH44PXNmcpt85BS/dAkOy/YrrKOC6jgyxoKVVwfJrqBos1PCGViW+IYJmmGrJicpqyHD CfY6s X-Gm-Gg: AfdE7cnWS5EQakLKO+nwiiGSP8Vi4VkEDsZjtJVCo7S+JWNImqS8O4wMscNj5AlVyR7 P56wjNYRXuuRN97VG0DPPywZUSV+y5j8gX/tBbyyDWoZ9BjRG+FnDkSyV9J5RC6KzTW+Qxqcou5 bI3A/y+k8RV6k3coujq3vcbVxfUXCPsqPHIQseSsnhvgvnawY+BTIcLAP9tIqHDV9OYz7VYiJuE 9E7yoh+VldR6rO/jm6Vcx2vXbs3I8XcaSY0bVw+zOi0w83x6mRvhKKTuoPfT+SzOZKyJaOZOhe6 fj4h3al02VutJVlWhaISCIAQhHhyvXozzFAoc3l6kpsr+wrI27ay1pyjivNlL9sV9pjEHE2JOiK 0rAe4Q7BNTekRKfBYFAT7nKk2XHw7ttnHNalNOWF4ZYY58OZ3EkzB94f4qVY4YPLyxMkFQ8IVkN jlLlIyIb6GjdlLwhpdKA== X-Received: by 2002:a17:90b:3808:b0:381:cef1:11bb with SMTP id 98e67ed59e1d1-38e4b51c562mr4861888a91.22.1784330604256; Fri, 17 Jul 2026 16:23:24 -0700 (PDT) From: Richard Henderson To: qemu-devel@nongnu.org Cc: qemu-arm@nongnu.org Subject: [PATCH 12/17] target/arm: Split out helpers for creating MTEDESC Date: Fri, 17 Jul 2026 16:23:00 -0700 Message-ID: <20260717232306.378988-14-richard.henderson@linaro.org> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260717232306.378988-1-richard.henderson@linaro.org> References: <20260717232306.378988-1-richard.henderson@linaro.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2607:f8b0:4864:20::1032; envelope-from=richard.henderson@linaro.org; helo=mail-pj1-x1032.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linaro.org) X-ZM-MESSAGEID: 1784330842576158500 Content-Type: text/plain; charset="utf-8" Assert that align and size values fit in their fields. This results in more fields being filled than some helpers actually use, but uniformity is for the best. Signed-off-by: Richard Henderson Reviewed-by: Philippe Mathieu-Daud=C3=A9 --- target/arm/tcg/translate-a64.c | 123 ++++++++++++++++----------------- 1 file changed, 58 insertions(+), 65 deletions(-) diff --git a/target/arm/tcg/translate-a64.c b/target/arm/tcg/translate-a64.c index 3d838a4cc1..590c7d8064 100644 --- a/target/arm/tcg/translate-a64.c +++ b/target/arm/tcg/translate-a64.c @@ -292,6 +292,43 @@ static void gen_probe_access(DisasContext *s, TCGv_i64= ptr, tcg_constant_i32(1 << log2_size)); } =20 +static TCGv_i32 gen_mtedesc_xas(DisasContext *s, bool write, int idx, + unsigned align, unsigned size) +{ + int desc =3D 0; + + desc =3D FIELD_DP32(desc, MTEDESC, MIDX, idx); + desc =3D FIELD_DP32(desc, MTEDESC, TBI, s->tbid); + desc =3D FIELD_DP32(desc, MTEDESC, TCMA, s->tcma); + desc =3D FIELD_DP32(desc, MTEDESC, WRITE, write); + desc =3D FIELD_DP32(desc, MTEDESC, ALIGN, align); + desc =3D FIELD_DP32(desc, MTEDESC, MTX, s->mtx); + desc =3D FIELD_DP32(desc, MTEDESC, SIZEM1, size - 1); + + assert(FIELD_EX32(desc, MTEDESC, ALIGN) =3D=3D align); + assert(FIELD_EX32(desc, MTEDESC, SIZEM1) =3D=3D size - 1); + + return tcg_constant_i32(desc); +} + +static TCGv_i32 gen_mtedesc_xmop(DisasContext *s, bool write, + int idx, MemOp memop) +{ + return gen_mtedesc_xas(s, write, idx, memop_alignment_bits(memop), + memop_size(memop)); +} + +static TCGv_i32 gen_mtedesc_as(DisasContext *s, bool write, + unsigned align, unsigned size) +{ + return gen_mtedesc_xas(s, write, get_mem_index(s), align, size); +} + +static TCGv_i32 gen_mtedesc_zva(DisasContext *s) +{ + return gen_mtedesc_as(s, true, 0, s->dcz_blocksize); +} + /* * For MTE, check a single logical or atomic access. This probes a single * address, the exact one specified. The size and alignment of the access @@ -305,20 +342,10 @@ static TCGv_i64 gen_mte_check1_mmuidx(DisasContext *s= , TCGv_i64 addr, { if (tag_checked && s->mte_active[is_unpriv] && (is_write || !s->mte_store_only[is_unpriv])) { - TCGv_i64 ret; - int desc =3D 0; - - desc =3D FIELD_DP32(desc, MTEDESC, MIDX, core_idx); - desc =3D FIELD_DP32(desc, MTEDESC, TBI, s->tbid); - desc =3D FIELD_DP32(desc, MTEDESC, TCMA, s->tcma); - desc =3D FIELD_DP32(desc, MTEDESC, WRITE, is_write); - desc =3D FIELD_DP32(desc, MTEDESC, ALIGN, memop_alignment_bits(mem= op)); - desc =3D FIELD_DP32(desc, MTEDESC, MTX, s->mtx); - desc =3D FIELD_DP32(desc, MTEDESC, SIZEM1, memop_size(memop) - 1); - - ret =3D tcg_temp_new_i64(); - gen_helper_mte_check(ret, tcg_env, tcg_constant_i32(desc), addr); + TCGv_i64 ret =3D tcg_temp_new_i64(); + TCGv_i32 desc =3D gen_mtedesc_xmop(s, is_write, core_idx, memop); =20 + gen_helper_mte_check(ret, tcg_env, desc, addr); return ret; } return clean_data_tbi(s, addr); @@ -339,20 +366,12 @@ TCGv_i64 gen_mte_checkN(DisasContext *s, TCGv_i64 add= r, bool is_write, { if (tag_checked && s->mte_active[0] && (is_write || !s->mte_store_only[0])) { - TCGv_i64 ret; - int desc =3D 0; - - desc =3D FIELD_DP32(desc, MTEDESC, MIDX, get_mem_index(s)); - desc =3D FIELD_DP32(desc, MTEDESC, TBI, s->tbid); - desc =3D FIELD_DP32(desc, MTEDESC, TCMA, s->tcma); - desc =3D FIELD_DP32(desc, MTEDESC, WRITE, is_write); - desc =3D FIELD_DP32(desc, MTEDESC, ALIGN, memop_alignment_bits(sin= gle_mop)); - desc =3D FIELD_DP32(desc, MTEDESC, MTX, s->mtx); - desc =3D FIELD_DP32(desc, MTEDESC, SIZEM1, total_size - 1); - - ret =3D tcg_temp_new_i64(); - gen_helper_mte_check(ret, tcg_env, tcg_constant_i32(desc), addr); + TCGv_i64 ret =3D tcg_temp_new_i64(); + TCGv_i32 desc =3D gen_mtedesc_as(s, is_write, + memop_alignment_bits(single_mop), + total_size); =20 + gen_helper_mte_check(ret, tcg_env, desc, addr); return ret; } return clean_data_tbi(s, addr); @@ -3119,16 +3138,9 @@ static void handle_sys(DisasContext *s, bool isread, case ARM_CP_DC_ZVA: /* Writes clear the aligned block of memory which rt points into. = */ if (s->mte_active[0]) { - int desc =3D 0; - - desc =3D FIELD_DP32(desc, MTEDESC, MIDX, get_mem_index(s)); - desc =3D FIELD_DP32(desc, MTEDESC, TBI, s->tbid); - desc =3D FIELD_DP32(desc, MTEDESC, TCMA, s->tcma); - desc =3D FIELD_DP32(desc, MTEDESC, MTX, s->mtx); - tcg_rt =3D tcg_temp_new_i64(); - gen_helper_mte_check_zva(tcg_rt, tcg_env, - tcg_constant_i32(desc), cpu_reg(s, rt= )); + gen_helper_mte_check_zva(tcg_rt, tcg_env, gen_mtedesc_zva(s), + cpu_reg(s, rt)); } else { tcg_rt =3D clean_data_tbi(s, cpu_reg(s, rt)); } @@ -4967,7 +4979,8 @@ static bool do_SET(DisasContext *s, arg_set *a, bool = is_epilogue, bool is_setg, SetFn fn) { int memidx; - uint32_t syndrome, desc =3D 0; + uint32_t syndrome; + TCGv_i32 desc; =20 if (is_setg && !dc_isar_feature(aa64_mte, s)) { return false; @@ -4992,23 +5005,15 @@ static bool do_SET(DisasContext *s, arg_set *a, boo= l is_epilogue, syndrome =3D syn_mop(true, is_setg, (a->nontemp << 1) | a->unpriv, is_epilogue, false, true, a->rd, a->rs, a->rn); =20 - if (is_setg ? s->ata[a->unpriv] : s->mte_active[a->unpriv]) { - /* We may need to do MTE tag checking, so assemble the descriptor = */ - desc =3D FIELD_DP32(desc, MTEDESC, TBI, s->tbid); - desc =3D FIELD_DP32(desc, MTEDESC, TCMA, s->tcma); - desc =3D FIELD_DP32(desc, MTEDESC, WRITE, true); - desc =3D FIELD_DP32(desc, MTEDESC, MTX, s->mtx); - /* SIZEM1 and ALIGN we leave 0 (byte write) */ - } - /* The helper function always needs the memidx even with MTE disabled = */ - desc =3D FIELD_DP32(desc, MTEDESC, MIDX, memidx); + /* Construct the descriptor whether MTE is enabled or not. */ + desc =3D gen_mtedesc_xmop(s, true, memidx, MO_UB); =20 /* * The helper needs the register numbers, but since they're in * the syndrome anyway, we let it extract them from there rather * than passing in an extra three integer arguments. */ - fn(tcg_env, tcg_constant_i32(syndrome), tcg_constant_i32(desc)); + fn(tcg_env, tcg_constant_i32(syndrome), desc); return true; } =20 @@ -5024,7 +5029,8 @@ typedef void CpyFn(TCGv_env, TCGv_i32, TCGv_i32, TCGv= _i32); static bool do_CPY(DisasContext *s, arg_cpy *a, bool is_epilogue, CpyFn fn) { int rmemidx, wmemidx; - uint32_t syndrome, rdesc =3D 0, wdesc =3D 0; + uint32_t syndrome; + TCGv_i32 rdesc, wdesc; bool wunpriv =3D extract32(a->options, 0, 1); bool runpriv =3D extract32(a->options, 1, 1); =20 @@ -5048,29 +5054,16 @@ static bool do_CPY(DisasContext *s, arg_cpy *a, boo= l is_epilogue, CpyFn fn) syndrome =3D syn_mop(false, false, a->options, is_epilogue, false, true, a->rd, a->rs, a->rn); =20 - /* If we need to do MTE tag checking, assemble the descriptors */ - if (s->mte_active[runpriv]) { - rdesc =3D FIELD_DP32(rdesc, MTEDESC, TBI, s->tbid); - rdesc =3D FIELD_DP32(rdesc, MTEDESC, TCMA, s->tcma); - rdesc =3D FIELD_DP32(rdesc, MTEDESC, MTX, s->mtx); - } - if (s->mte_active[wunpriv]) { - wdesc =3D FIELD_DP32(wdesc, MTEDESC, TBI, s->tbid); - wdesc =3D FIELD_DP32(wdesc, MTEDESC, TCMA, s->tcma); - wdesc =3D FIELD_DP32(wdesc, MTEDESC, WRITE, true); - wdesc =3D FIELD_DP32(wdesc, MTEDESC, MTX, s->mtx); - } - /* The helper function needs these parts of the descriptor regardless = */ - rdesc =3D FIELD_DP32(rdesc, MTEDESC, MIDX, rmemidx); - wdesc =3D FIELD_DP32(wdesc, MTEDESC, MIDX, wmemidx); + /* Assemble the descriptors regardless of MTE enabled. */ + rdesc =3D gen_mtedesc_xmop(s, false, rmemidx, MO_UB); + wdesc =3D gen_mtedesc_xmop(s, true, wmemidx, MO_UB); =20 /* * The helper needs the register numbers, but since they're in * the syndrome anyway, we let it extract them from there rather * than passing in an extra three integer arguments. */ - fn(tcg_env, tcg_constant_i32(syndrome), tcg_constant_i32(wdesc), - tcg_constant_i32(rdesc)); + fn(tcg_env, tcg_constant_i32(syndrome), wdesc, rdesc); return true; } =20 --=20 2.43.0 From nobody Sat Jul 25 13:41:30 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linaro.org ARC-Seal: i=1; a=rsa-sha256; t=1784330838; cv=none; d=zohomail.com; s=zohoarc; b=CFjsU9iWXZAkVkYQbzWq0fjIi28iCsI7hQ6BMHjdMcmywHV603NYV7R/NwxvG35KeovtuixcYZaUENp+2bEkETAp8SFRjIclLpbRM97IvJCowEruP93BVPMwRwXRposg7tpmhBiUWd/OoVOdHGI/p2Zf7z8cdikHgUGGJMerL6k= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784330838; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=+w4gM7iFRV4DJ/pj745QODhhizrJBFDLfIGD0SvwnhQ=; b=MC4PhvcT/hBks74kLbdfRjl4eJ+JtFF8BLo4yYzjLIjqLXu0s3FCl1L7lwjkKLhAMbPPQVbX9tx7krzt+xBUiQBn5FyrxIVhqenbMyFohR6oiED33L8ac8aZQkLEwKSZS83veP1zl9VfPJYwKqGOUj6QFmzohncyo1gHKnRgZns= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784330838558611.3338639882942; Fri, 17 Jul 2026 16:27:18 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wkru0-0001bR-4N; Fri, 17 Jul 2026 19:23:32 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkrtw-0001ad-N9 for qemu-devel@nongnu.org; Fri, 17 Jul 2026 19:23:30 -0400 Received: from mail-pj1-x102d.google.com ([2607:f8b0:4864:20::102d]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wkrtv-00071d-7p for qemu-devel@nongnu.org; Fri, 17 Jul 2026 19:23:28 -0400 Received: by mail-pj1-x102d.google.com with SMTP id 98e67ed59e1d1-38175907a56so1524424a91.0 for ; Fri, 17 Jul 2026 16:23:26 -0700 (PDT) Received: from stoup.. ([32.140.233.50]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13ce2a18a47sm8186261c88.8.2026.07.17.16.23.24 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 17 Jul 2026 16:23:24 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1784330606; x=1784935406; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=+w4gM7iFRV4DJ/pj745QODhhizrJBFDLfIGD0SvwnhQ=; b=X6QcDhXFWYtTddJfZzOMrZ1unD8DomSrXtYRSq8xbYh8dpgpx35lmeDr2NWOmimJ4J qyxAsvh5dx+cECaFR3jH6rQ5vtRAP7WoH3AdZ6HcPBCMHiXk/dL+g6tTOBKqd/8Uwwhl gluCTZOQywz8JKchBhwGnGMAzAs+CrEjDhPMBc4Ym0k+qkOUkx0idPme2V38OWcRK+RL YuWnUBEY3FC6imgs1Fm3znX2TkMHCcZbS5dgHgVWh2j0OwL8sbFcMfwH/9wYsFK9oYK8 I5cRLsCrNsVJCt10RDyeia5seVuHgGwUifMFU5fHghFB2pwcmWxdRHlWFgBo4NzoZdHR Oi8A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784330606; x=1784935406; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=+w4gM7iFRV4DJ/pj745QODhhizrJBFDLfIGD0SvwnhQ=; b=XCMrRr+zcy7/aSn4mM1oWK0oufPDkZj+sK/+7SXa6NiTLcq/QhVy/Br6v1OVoVKYrx I75s0810hzSi1ZZbnLY/zqMkErv3NmvVd48HD4yEjMXkCduDB0PHTieQhUhVn50mDrBg bRmjjSP/f+9q2/3dwW8TfeSQhBR3oFHffmNJXEqv/Jbh7PqAMjYce04XhKREo3QPm8Gy /5OLrA3PsvZa2IboUR2/NePP/roSEIS6HwlmFeL8Kz71ywl6oSx110akTgWQRm7yBFP4 T7kDo8Q5RTYW240191QnAdehbEq/5uSeXU7rvvw3Epl0qLBoQVPCY4N7tV4akCFTFV9e Xr8Q== X-Gm-Message-State: AOJu0Yx9Hh2GBMu+D1BmWSNGaPY2DQbQ62K8bEBEeXsvhoEZ5aWXjVwg Rjrr67EES35r4ytAZ3gbZrc22/FWXPTP7SYgLVROf1hpo2EsvwRR5/ASxsjkYyVA59QQTUdzpMy R8yoI X-Gm-Gg: AfdE7cn24nMDlEcgsyo3HDVGRQKgTjmCfxTI2RONH1fCyBYfZ5GmQP9APG9PPD3yMSz Rp8uOgO8uFLkmToREQgPC52Kyjm3QwRibcHxyPCOMZ2dA8Vb17FdkbC3HRiPWSmiXP2CL60gY58 NRqZ11U0kXzd1WETy7yUUzubLzBH7GzLjlTpZVMLGwN+jV2cGxGjBViaIH5P5/Jy/08aeQxUQyo 9vNRKKGWoly5hGooUobIniFBZczuXH1zI38wdCSrWS978xk73rR4ysxgvlDFzF6Y/Lq6ZdmVnyC 2j98SXTg+8XUDLO421mc4B6PBrkTqe03L8RgFb33cF2gCC+pWUF9nlGVL8DOX6yz7rqE3TymisJ V8Jqr80oyPo/4Hqr234ANerXPYmrqXW+CUdHR030P8TiIbhzGQnNM5ulL1z8kebDK6ihdv5T478 /AntJhbBA= X-Received: by 2002:a17:90b:4e85:b0:380:86d8:8162 with SMTP id 98e67ed59e1d1-38e3d299be4mr9939591a91.18.1784330605511; Fri, 17 Jul 2026 16:23:25 -0700 (PDT) From: Richard Henderson To: qemu-devel@nongnu.org Cc: qemu-arm@nongnu.org Subject: [PATCH 13/17] accel/tcg: Clean addreses in the user-only probe_access api Date: Fri, 17 Jul 2026 16:23:01 -0700 Message-ID: <20260717232306.378988-15-richard.henderson@linaro.org> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260717232306.378988-1-richard.henderson@linaro.org> References: <20260717232306.378988-1-richard.henderson@linaro.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2607:f8b0:4864:20::102d; envelope-from=richard.henderson@linaro.org; helo=mail-pj1-x102d.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linaro.org) X-ZM-MESSAGEID: 1784330840591158500 Content-Type: text/plain; charset="utf-8" On the system side, tagged addresses are automatically handled by the target's tlb_fill callback. Allow user-only to accept tagged pointers as well. Signed-off-by: Richard Henderson Reviewed-by: Philippe Mathieu-Daud=C3=A9 --- accel/tcg/user-exec.c | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/accel/tcg/user-exec.c b/accel/tcg/user-exec.c index a35aca7889..3b3ee73d4e 100644 --- a/accel/tcg/user-exec.c +++ b/accel/tcg/user-exec.c @@ -752,6 +752,7 @@ static int probe_access_internal(CPUArchState *env, vad= dr addr, int fault_size, MMUAccessType access_type, bool nonfault, uintptr_t ra) { + vaddr clean_addr =3D cpu_untagged_addr_vaddr(env_cpu(env), addr); int acc_flag; bool maperr; =20 @@ -769,8 +770,8 @@ static int probe_access_internal(CPUArchState *env, vad= dr addr, g_assert_not_reached(); } =20 - if (guest_addr_valid_untagged_vaddr(addr)) { - int page_flags =3D page_get_flags(addr); + if (guest_addr_valid_untagged_vaddr(clean_addr)) { + int page_flags =3D page_get_flags(clean_addr); if (page_flags & acc_flag) { if (access_type !=3D MMU_INST_FETCH && cpu_plugin_mem_cbs_enabled(env_cpu(env))) { @@ -823,11 +824,10 @@ void *tlb_vaddr_to_host(CPUArchState *env, vaddr addr, tb_page_addr_t get_page_addr_code_hostp(CPUArchState *env, vaddr addr, void **hostp) { - int flags; - - flags =3D probe_access_internal(env, addr, 1, MMU_INST_FETCH, false, 0= ); + int flags =3D probe_access_internal(env, addr, 1, MMU_INST_FETCH, fals= e, 0); g_assert(flags =3D=3D 0); =20 + addr =3D cpu_untagged_addr_vaddr(env_cpu(env), addr); *hostp =3D g2h_untagged_vaddr(addr); return addr; } --=20 2.43.0 From nobody Sat Jul 25 13:41:30 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linaro.org ARC-Seal: i=1; a=rsa-sha256; t=1784330813; cv=none; d=zohomail.com; s=zohoarc; b=GbsGxVodhEJc1Ebc8r8FclcO491a2XpjZs8dzGCIro0y98P3VDFJY3dYDBomj1zIoN2V6o7WO1lNYzk91hv0DzYPYw/qFF4P54oT4ArfDhUTKNZpfYZoenYddVMw43/HXrQso35dBSM2XMPK9jvsnjt4p+9xIAVcIXSjql1hEk8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784330813; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=hoKL+T5ZAMVBhG4qjN+wRa38usEFNIxUeO3xCWyHIIM=; b=Mg/rFv+G8vcY7V9Xeiyu3f/MUucherVYRHPg79xOknTPTpjE5+I9Pj+JzAS7mKBLFQ2/bR4ePgld5/ZSLWOJnTngjE83EzOuwO2xuNtcVU/9nqTugp7g4mlukNAtKbvrjONe/VuBxfKSfR7uASzTXgTzC93eC39o42inmg0aEjk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784330813479447.8852067293243; Fri, 17 Jul 2026 16:26:53 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wkru0-0001br-KT; Fri, 17 Jul 2026 19:23:32 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkrty-0001au-Ah for qemu-devel@nongnu.org; Fri, 17 Jul 2026 19:23:30 -0400 Received: from mail-pg1-x52b.google.com ([2607:f8b0:4864:20::52b]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wkrtw-00071q-9n for qemu-devel@nongnu.org; Fri, 17 Jul 2026 19:23:29 -0400 Received: by mail-pg1-x52b.google.com with SMTP id 41be03b00d2f7-c9c26a5fb98so1527499a12.0 for ; Fri, 17 Jul 2026 16:23:27 -0700 (PDT) Received: from stoup.. ([32.140.233.50]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13ce2a18a47sm8186261c88.8.2026.07.17.16.23.25 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 17 Jul 2026 16:23:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1784330607; x=1784935407; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=hoKL+T5ZAMVBhG4qjN+wRa38usEFNIxUeO3xCWyHIIM=; b=m3IRTIyUUrImJNcPSCcQ8eGPJpHyemnqZ9yDLIrsUyiGFLhLoTVZstCoC8Ox6hQKzi ogXtQ5LSYKPsg1d3mGKOUJsBSpu1ys6QwwChau7YdHlVI0ES3IFy9g9gfBRQrQp7QIqh b2T9ar5zMiWOS874HvZu9KDvfAytDXuBqgdtFtFWWV64Lap4cO9JR3NJ/UYhRjcdr7S9 Ci/9n+G3fO/j8D4ImlJJV0pyjErDjBqmXYqSU/fLIWZBw6SCwjoNgcnm0IDtdG/mGAc/ UnZsqTRcHINVYI1e433V5gWtqShZ59BhZWFsqIp74KpvQV7pBiK3hAQ+sxGuh3db7u/C I52g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784330607; x=1784935407; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=hoKL+T5ZAMVBhG4qjN+wRa38usEFNIxUeO3xCWyHIIM=; b=I1X7jT+ZLtRwd6pOErTRpcnvulYXOzUELeM98YvOY5OW8nuP79ZPIMAcQhyXXkWwY6 AfEUKJzvzoLilszHbWKcbGbjEch2VAA2iUE7kvxBjOK/NduYXoNkMcbeN15rLbqUpw6Z dL3avCK2/ijJpag8gCKUt6o4tJEpU8VSHOPIwm3Vtu8z19SMXuLXmUvEqy+K7AnFYR5C 1dOEpd0zEGDYoGw8Cd1Ygf4FKzOC+UkSHMf2PcEIbV5r8I96K6yssytUxBw1/cH27WW8 vdFtSMqPYvNBFoG8Jo0dDXx0/0G5FqkP0gU/YCtmH2KSrx4QsuUG/S3VyqHksKWQPwZK V8SQ== X-Gm-Message-State: AOJu0YzLDCaF0YnW+6znRiT4rb1d3uwYYdreoV7I+lgb/7SkuCfBoumE V7d/jU5viH0vgBRJBsmM9ott30aiRZpg6Xi3JeVu32Zsl+UtMGz5jnH7hzpw0VAWgONb3BoWSkb qZKoH X-Gm-Gg: AfdE7ck7fyqSxz2GY6snx3Wrp42qC57WoZClYCmNaMm8h7bD4x0eMueGkWsPEJR/ZqL 9u04YKp0N1dOnapTYSu+tbWp9QT6StyZ2+hFA479sP7ejICncKprOXgXEZhAzzj9PuhPkzW6Hzd xVW0c64j+nqGOBjNCmsIqnbys0ekMgf70xe7wlz8wvJ+mePWbOzvqXudibBambSj/vUStrFP9sK Lo/OC8T6LDxn7skvj8ZvWrNh3zwy3QQXYXz2ezfFAR9yJ8OC3BbEasUJBRUC1KoCy1YmLBM3ShU LRk/BXWnCN1KXjlcI7zANV0Tr1iVDWMHwIR+rfSNFe1uIgI+tgo7maAisxGF0N1207eFCT0FN3N qpoH3NG3vQ3SgFq/oByzKkuQWNRJvLVfXMm27JsHSG+BkEa9Co2AY9Jyf1/DEFlmV4nGN0KfwWP /46HVmgtA= X-Received: by 2002:a17:90b:1345:b0:37e:1620:dabc with SMTP id 98e67ed59e1d1-38e3cfd30a6mr9211116a91.0.1784330606704; Fri, 17 Jul 2026 16:23:26 -0700 (PDT) From: Richard Henderson To: qemu-devel@nongnu.org Cc: qemu-arm@nongnu.org Subject: [PATCH 14/17] target/arm: Drop clean_addr_tbi before helper_dc_zva Date: Fri, 17 Jul 2026 16:23:02 -0700 Message-ID: <20260717232306.378988-16-richard.henderson@linaro.org> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260717232306.378988-1-richard.henderson@linaro.org> References: <20260717232306.378988-1-richard.henderson@linaro.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2607:f8b0:4864:20::52b; envelope-from=richard.henderson@linaro.org; helo=mail-pg1-x52b.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linaro.org) X-ZM-MESSAGEID: 1784330814674158500 Content-Type: text/plain; charset="utf-8" Now that probe_write always handles tagged pointers, we don't need to handle this during translation. Signed-off-by: Richard Henderson --- target/arm/tcg/translate-a64.c | 9 ++++----- 1 file changed, 4 insertions(+), 5 deletions(-) diff --git a/target/arm/tcg/translate-a64.c b/target/arm/tcg/translate-a64.c index 590c7d8064..24a0cd8345 100644 --- a/target/arm/tcg/translate-a64.c +++ b/target/arm/tcg/translate-a64.c @@ -3142,7 +3142,7 @@ static void handle_sys(DisasContext *s, bool isread, gen_helper_mte_check_zva(tcg_rt, tcg_env, gen_mtedesc_zva(s), cpu_reg(s, rt)); } else { - tcg_rt =3D clean_data_tbi(s, cpu_reg(s, rt)); + tcg_rt =3D cpu_reg(s, rt); } gen_helper_dc_zva(tcg_env, tcg_rt); return; @@ -4763,7 +4763,7 @@ static bool trans_LD_single_repl(DisasContext *s, arg= _LD_single_repl *a) =20 static bool trans_STZGM(DisasContext *s, arg_ldst_tag *a) { - TCGv_i64 addr, clean_addr, tcg_rt; + TCGv_i64 addr, tcg_rt; =20 if (!dc_isar_feature(aa64_mte, s)) { return false; @@ -4787,9 +4787,8 @@ static bool trans_STZGM(DisasContext *s, arg_ldst_tag= *a) * The non-tags portion of STZGM is mostly like DC_ZVA, * except the alignment happens before the access. */ - clean_addr =3D clean_data_tbi(s, addr); - tcg_gen_andi_i64(clean_addr, clean_addr, -s->dcz_blocksize); - gen_helper_dc_zva(tcg_env, clean_addr); + tcg_gen_andi_i64(addr, addr, -s->dcz_blocksize); + gen_helper_dc_zva(tcg_env, addr); return true; } =20 --=20 2.43.0 From nobody Sat Jul 25 13:41:30 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linaro.org ARC-Seal: i=1; a=rsa-sha256; t=1784330734; cv=none; d=zohomail.com; s=zohoarc; b=eW4PqktddEK6SCJ+PGphIq4uDbJeLKmWv0Il+ryQ9s3bx1nHHx/CQg/pBfkzoSyupo9dyGw9sJhLwWAF4FBZw2+7zWcqujni69Pux/kqhUmxGxjnEvg3YLR4viPdejfNIITzGcJ6KVbjMoHAax4udurCDJu5UVHakcFgBWFKPk8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784330734; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=4HeBVv7zNWopmwOur9m+FBODN8PMLRBceVz2vLyib0k=; b=hx7vbVUJwiHxWF2aq64LSYgZdP+stRPDZd9176kkGjLBWaUx/1LoTQ7KrwWJdHQaAwOAv0+09gOyNNkmutFpV+GBT3vgROX+HOigxzMmpddKf61NO/GcV/0E+oF2dt4qFOxaxuVbndjhmZbSmVmbhZEbhy7+yNlY8GQAYN9i5Co= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784330734613373.43025342619103; Fri, 17 Jul 2026 16:25:34 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wkru1-0001cx-PK; Fri, 17 Jul 2026 19:23:33 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkru0-0001bS-3A for qemu-devel@nongnu.org; Fri, 17 Jul 2026 19:23:32 -0400 Received: from mail-pj1-x102a.google.com ([2607:f8b0:4864:20::102a]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wkrty-00072H-18 for qemu-devel@nongnu.org; Fri, 17 Jul 2026 19:23:31 -0400 Received: by mail-pj1-x102a.google.com with SMTP id 98e67ed59e1d1-381b831d535so5699752a91.0 for ; Fri, 17 Jul 2026 16:23:29 -0700 (PDT) Received: from stoup.. ([32.140.233.50]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13ce2a18a47sm8186261c88.8.2026.07.17.16.23.26 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 17 Jul 2026 16:23:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1784330608; x=1784935408; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=4HeBVv7zNWopmwOur9m+FBODN8PMLRBceVz2vLyib0k=; b=rAcE1KjUTktf0GpAyE1cGpDS4VHF/PS5mGuNAzv5ByexgYtmikJFKqPXbNJzR4RvjT ThPpSE8FcvWJf1o7FXZL0S7VvtFZFTrMkrr+DNDbuOOqxoRcqb1B4jWiTMOOCgxVfpDm Iz7Gn4RJWfG3ujyCR/3sgdXt+BosJ7gj9p0LGSUDtwsAifpIXbYshgnv8MN+7rJ8QYM5 18aEFe16vb+BsOBwAwDWjaLambPVfiAt3t/3y11AMamO+3+4zsPfTCJOkpoIEfWDA4/H 7AZL82INtJZL+EZ+TkDVqbwRX1BOrd/5ZU+hOaY4fU/8Zfgj9+Sa4nuDRghP+Yk7f7zO 8I5Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784330608; x=1784935408; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=4HeBVv7zNWopmwOur9m+FBODN8PMLRBceVz2vLyib0k=; b=AoMS1FYuML/8N4Si+toO9xEFaU4S2s+5CixhVLUPTB6p8c8uHG90Qj/49LdidIssp+ R+qzecFGirUknmZu5C9W2qu0fEbdpp6Gtq2tyxmFs7YGr3PLco0mMbZoIUroMqJngmlk nNmYDEOlEL/oYffO0naj2Z9RgUf9mUJiCytKVuX35vNR8+pURGEyWVxKQ4xWg9q7Hx6m J8Q3nbQQDSKLe/fu0bNTx8RWTd2yFz3v+W6BHKbrK4Ivoumd5ZHlBOIaqhbkfI+YEuod TrvI4bu2DVIcz7bJrS9lvAsR9msM1018Ub3S1O0Jiz2OKeG8JZhoWbuYRLsRGhf4Eu6l jUig== X-Gm-Message-State: AOJu0Yx9UWWlblk4NrhRlMOrPkC++3LrJAqXyRpbCho1EV5Vf9lg3QgG pLjtu1f+iz4n30utyIRLWbW0FjIi37d8FOxB7+9mwOLOnKIbXkken4BXqJV/chI41HzqoIn2G/X /KrhE X-Gm-Gg: AfdE7cm8aeKq4/Ur1YF5sfVdVFBDkn8DOK1dGpvH8Oa3hDHoGi98c6XyCnZ5BCjuRN0 NJBDbwUOXx29KO5OuEBdno5F9QKdrYfPvg9vwthx/mztwxNXbmYAh1CFBbO/27TqM2+kIfnk+mz tuqy7n9/RyMLnW9Y66l8YvE+uUV2o4dlJPf9JncIvBHOoySmcHcRjygg7oae9WjQg8eUCtdIczL J7ZTonkca9Ta5KAnG0Su7iRP+nT726O/GYf/pF01MzKnNYwADWb5FV5AGTmRV5Utzyfuz2NKhGz 3WHGk3xNAYAHazSN0EXqBIgVkpdgr8TabhYIa4hafXF33365obDsA1MH+tcSRZ6juun9iLWiMFX AOzaDGPHxXiMBVoe5oAloHTDyCEaGY7af+0N1PLNRIR6/0az7EN4aaRuUHehqaHG9gAS0ylmQiP GD9xT0S50= X-Received: by 2002:a17:90b:3f85:b0:38d:dbc7:5178 with SMTP id 98e67ed59e1d1-38e4b54610fmr5035493a91.22.1784330607940; Fri, 17 Jul 2026 16:23:27 -0700 (PDT) From: Richard Henderson To: qemu-devel@nongnu.org Cc: qemu-arm@nongnu.org Subject: [PATCH 15/17] target/arm: Pass MTEDESC to helper_dc_zva Date: Fri, 17 Jul 2026 16:23:03 -0700 Message-ID: <20260717232306.378988-17-richard.henderson@linaro.org> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260717232306.378988-1-richard.henderson@linaro.org> References: <20260717232306.378988-1-richard.henderson@linaro.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2607:f8b0:4864:20::102a; envelope-from=richard.henderson@linaro.org; helo=mail-pj1-x102a.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linaro.org) X-ZM-MESSAGEID: 1784330736297158500 Content-Type: text/plain; charset="utf-8" Passing the mmu_idx and dcz blocksize in the descriptor is helpful, as is unifying the helper interface with other DC insns. Signed-off-by: Richard Henderson --- target/arm/tcg/helper-a64-defs.h | 2 +- target/arm/tcg/mte_helper.c | 6 +++--- target/arm/tcg/translate-a64.c | 21 ++++++++++++--------- 3 files changed, 16 insertions(+), 13 deletions(-) diff --git a/target/arm/tcg/helper-a64-defs.h b/target/arm/tcg/helper-a64-d= efs.h index 0e56e00f45..ac8f460ffb 100644 --- a/target/arm/tcg/helper-a64-defs.h +++ b/target/arm/tcg/helper-a64-defs.h @@ -80,7 +80,7 @@ DEF_HELPER_3(vfp_ah_maxh, f16, f16, f16, fpst) DEF_HELPER_3(vfp_ah_maxs, f32, f32, f32, fpst) DEF_HELPER_3(vfp_ah_maxd, f64, f64, f64, fpst) =20 -DEF_HELPER_FLAGS_2(dc_zva, TCG_CALL_NO_WG, void, env, i64) +DEF_HELPER_FLAGS_3(dc_zva, TCG_CALL_NO_WG, void, env, i64, i32) =20 DEF_HELPER_FLAGS_3(pacia, TCG_CALL_NO_WG, i64, env, i64, i64) DEF_HELPER_FLAGS_3(pacib, TCG_CALL_NO_WG, i64, env, i64, i64) diff --git a/target/arm/tcg/mte_helper.c b/target/arm/tcg/mte_helper.c index 6e1f701c4c..4fa6066cbc 100644 --- a/target/arm/tcg/mte_helper.c +++ b/target/arm/tcg/mte_helper.c @@ -1117,11 +1117,11 @@ static void do_dczva_0(CPUARMState *env, vaddr addr= , size_t len, void *mem, clear_helper_retaddr(); } =20 -void HELPER(dc_zva)(CPUARMState *env, uint64_t addr) +void HELPER(dc_zva)(CPUARMState *env, uint64_t addr, uint32_t desc) { uintptr_t ra =3D GETPC(); - size_t len =3D (size_t)4 << get_dczid_bs(env_archcpu(env)); - int mmu_idx =3D arm_env_mmu_index(env); + size_t len =3D FIELD_EX32(desc, MTEDESC, SIZEM1) + 1; + int mmu_idx =3D FIELD_EX32(desc, MTEDESC, MIDX); MemTxAttrs attrs =3D MEMTXATTRS_UNSPECIFIED; int flags; void *mem; diff --git a/target/arm/tcg/translate-a64.c b/target/arm/tcg/translate-a64.c index 24a0cd8345..c3ff46989a 100644 --- a/target/arm/tcg/translate-a64.c +++ b/target/arm/tcg/translate-a64.c @@ -3137,14 +3137,16 @@ static void handle_sys(DisasContext *s, bool isread, } case ARM_CP_DC_ZVA: /* Writes clear the aligned block of memory which rt points into. = */ - if (s->mte_active[0]) { - tcg_rt =3D tcg_temp_new_i64(); - gen_helper_mte_check_zva(tcg_rt, tcg_env, gen_mtedesc_zva(s), - cpu_reg(s, rt)); - } else { - tcg_rt =3D cpu_reg(s, rt); + { + TCGv_i32 desc =3D gen_mtedesc_zva(s); + if (s->mte_active[0]) { + tcg_rt =3D tcg_temp_new_i64(); + gen_helper_mte_check_zva(tcg_rt, tcg_env, desc, cpu_reg(s,= rt)); + } else { + tcg_rt =3D cpu_reg(s, rt); + } + gen_helper_dc_zva(tcg_env, tcg_rt, desc); } - gen_helper_dc_zva(tcg_env, tcg_rt); return; case ARM_CP_DC_GVA: { @@ -3170,11 +3172,12 @@ static void handle_sys(DisasContext *s, bool isread, case ARM_CP_DC_GZVA: { TCGv_i64 clean_addr, tag; + TCGv_i32 desc =3D gen_mtedesc_zva(s); =20 /* For DC_GZVA, we can rely on DC_ZVA for the proper fault. */ tcg_rt =3D cpu_reg(s, rt); clean_addr =3D clean_data_tbi(s, tcg_rt); - gen_helper_dc_zva(tcg_env, clean_addr); + gen_helper_dc_zva(tcg_env, clean_addr, desc); =20 if (s->ata[0]) { /* Extract the tag from the register to match STZGM. */ @@ -4788,7 +4791,7 @@ static bool trans_STZGM(DisasContext *s, arg_ldst_tag= *a) * except the alignment happens before the access. */ tcg_gen_andi_i64(addr, addr, -s->dcz_blocksize); - gen_helper_dc_zva(tcg_env, addr); + gen_helper_dc_zva(tcg_env, addr, gen_mtedesc_zva(s)); return true; } =20 --=20 2.43.0 From nobody Sat Jul 25 13:41:30 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linaro.org ARC-Seal: i=1; a=rsa-sha256; t=1784330701; cv=none; d=zohomail.com; s=zohoarc; b=CrtwGw6xQNmSTeH2uoSy9F0l1lPx6de+25fxZcZc6+kCle8HAZWNowlNV30hFbRUdOHdXGf2SenA/AWwhB8Vew8QpFousdqJqixGN3Fh/2wEef0LfYRJqDNp73iHJI2aK5uP8ZOalS84a947tcHji8S1pPQ35PVt7za5nwqRbDQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784330701; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=8+n0chjhgHEG/9+gtVo6LG9MboZPR/anVOwxZf16NKo=; b=W89rkrPwul4b4OJG/XyD3D6CuKJQoKLdbQufeoFu6r/EknRMzjb3djDmCCRAfGE5c3bzIEiZD644vAbx+Qq5bYLgyk2PMHosQMGhi7jWMiGpGP8xeBaSHvAisaIuxMGUaEdCb7tbqY5ydeK5YsP0mF85mIViTWEzIIbJFVZWQAw= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178433070097966.82268609981361; Fri, 17 Jul 2026 16:25:00 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wkru3-0001e9-K4; Fri, 17 Jul 2026 19:23:35 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkru2-0001dT-4H for qemu-devel@nongnu.org; Fri, 17 Jul 2026 19:23:34 -0400 Received: from mail-pj1-x1029.google.com ([2607:f8b0:4864:20::1029]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wkrty-00072h-Pi for qemu-devel@nongnu.org; Fri, 17 Jul 2026 19:23:33 -0400 Received: by mail-pj1-x1029.google.com with SMTP id 98e67ed59e1d1-383cb94f742so7816318a91.3 for ; Fri, 17 Jul 2026 16:23:30 -0700 (PDT) Received: from stoup.. ([32.140.233.50]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13ce2a18a47sm8186261c88.8.2026.07.17.16.23.28 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 17 Jul 2026 16:23:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1784330609; x=1784935409; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=8+n0chjhgHEG/9+gtVo6LG9MboZPR/anVOwxZf16NKo=; b=YjzEGx8RFl52EIMm+hCFRjcuF+9BE4dUaK7+g298DXAaNNWlWxNPYuRe3qt+NRSJnZ 0xTYfBj2nZB+vFaeJXIrYtIui8W2DbVR4FlzNkTjTrFQ7P93mNUGKWhlRE5V9uXZoFKK 0Aj+IelH1qOMbnzsHq08jpS7g6aYmfmolWGbLwVpVTzpZzOFnoqDZg5iIvNVTSxbtgVC bhIUuLx0HgbqcagbZwPayX7RlCLZwxAgPHJtS4lSI65OpHsoFUhF5uMdTOfS0zgxG2SN XGw7YBy4XfAz0tUPscSBo4juwkiSJ1Vk0JA/ja/4jYyCXTQwadtcXzLo7d5tLI4c/2AH xPWA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784330609; x=1784935409; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=8+n0chjhgHEG/9+gtVo6LG9MboZPR/anVOwxZf16NKo=; b=LG/HH4gnuHi2AXt5dwYM7EJuWtAdVttf+0F38yJcLu2+P6J2RnueKmFrOy45tQSnwp fwXoZIIEPekE+li6hZyBS0dGS3UU2OxpynH6akrwM0VM5ABcloJXT5l2ImpoXHBK8IKx E1jsFy3TlluHd5jqcAqEQTYJlFjGX+uyb7dcynuMd340OQN3yRhJO7dhJEn/pWPl1XEC AIhI0E6lnRWmlgPxH2q5vpeSyUj4nDoCYVE7PoIYmF9K6zn6/d63ItH4zaqnQ1GOr3XD W9ZaguWZkn/tM7J72JZyEaaypZYKlsRx+uE6sRNDIo1DueQv41pLZXPUryCL1XBqRpdw CyaQ== X-Gm-Message-State: AOJu0Yyjqv40gpCIRGNNjntlH7CpbFtzLDSY4K8R2L2ZB9YTHTjhSdPY +JJp0KZKxEJ4dKYrWCtxZonC8Rj4bQaCJyAd0nSFovupPXM9ZVhKMRJjP+YrDXTPOhCnquYyaxU b3F3i X-Gm-Gg: AfdE7clhbOBN8/Y9VYyr0VpH0dKZImQFsn4IHL6LKX3r5dAjd3w03UGtDUrwm7X/Jq2 wc1BEmZ7JEpbmvip94jqd0vlaZADwlP003p11y9F0u8YVywJxej++zSeAEzNN4+D3qqsvbcer+B TYfIQ326ZxXzUTZVjsuj6m7wEZCHmUx0ZzwXAnjjTAlvcXeQCoTXCFGWCYebphHSdkcpS2F6Q5d J13AMCHZ84999Mwy57lpDP0qIVPuxt75fNBBXOQUkHQ1zk1zgQK70pwaXLm4FQ0nxmnnrGIVeL3 B08OOaa6PVkyGWMgM2o+a3kVltS0w5mRecOiXH7wR98yvlbYF/551wfI9eeyIkyJzP/hjJiAFz/ zxg+wVY1ioo+TSyMuA9vzVNZH6MoJeG/zzmLstJmVYwIj5Cz6r4pnGPK0zsewOp7049MhYmPQ6a cccauu+PWqOk1uGgcHQg== X-Received: by 2002:a17:90b:39cc:b0:381:22d6:f7a3 with SMTP id 98e67ed59e1d1-38e4b49a92amr5642930a91.18.1784330609093; Fri, 17 Jul 2026 16:23:29 -0700 (PDT) From: Richard Henderson To: qemu-devel@nongnu.org Cc: qemu-arm@nongnu.org Subject: [PATCH 16/17] target/arm: Create helper_dc_zva_mte Date: Fri, 17 Jul 2026 16:23:04 -0700 Message-ID: <20260717232306.378988-18-richard.henderson@linaro.org> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260717232306.378988-1-richard.henderson@linaro.org> References: <20260717232306.378988-1-richard.henderson@linaro.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2607:f8b0:4864:20::1029; envelope-from=richard.henderson@linaro.org; helo=mail-pj1-x1029.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linaro.org) X-ZM-MESSAGEID: 1784330702403158500 Content-Type: text/plain; charset="utf-8" Reorganize helper_mte_check_zva into helper_dc_zva_mte so that we only require one function call from tcg generated code. Signed-off-by: Richard Henderson --- target/arm/tcg/helper-a64-defs.h | 2 +- target/arm/tcg/mte_helper.c | 210 ++++++++++++++++--------------- target/arm/tcg/translate-a64.c | 8 +- 3 files changed, 113 insertions(+), 107 deletions(-) diff --git a/target/arm/tcg/helper-a64-defs.h b/target/arm/tcg/helper-a64-d= efs.h index ac8f460ffb..518e74c8aa 100644 --- a/target/arm/tcg/helper-a64-defs.h +++ b/target/arm/tcg/helper-a64-defs.h @@ -81,6 +81,7 @@ DEF_HELPER_3(vfp_ah_maxs, f32, f32, f32, fpst) DEF_HELPER_3(vfp_ah_maxd, f64, f64, f64, fpst) =20 DEF_HELPER_FLAGS_3(dc_zva, TCG_CALL_NO_WG, void, env, i64, i32) +DEF_HELPER_FLAGS_3(dc_zva_mte, TCG_CALL_NO_WG, void, env, i64, i32) =20 DEF_HELPER_FLAGS_3(pacia, TCG_CALL_NO_WG, i64, env, i64, i64) DEF_HELPER_FLAGS_3(pacib, TCG_CALL_NO_WG, i64, env, i64, i64) @@ -99,7 +100,6 @@ DEF_HELPER_FLAGS_2(xpaci, TCG_CALL_NO_RWG_SE, i64, env, = i64) DEF_HELPER_FLAGS_2(xpacd, TCG_CALL_NO_RWG_SE, i64, env, i64) =20 DEF_HELPER_FLAGS_3(mte_check, TCG_CALL_NO_WG, i64, env, i32, i64) -DEF_HELPER_FLAGS_3(mte_check_zva, TCG_CALL_NO_WG, i64, env, i32, i64) DEF_HELPER_FLAGS_3(irg, TCG_CALL_NO_RWG, i64, env, i64, i64) DEF_HELPER_FLAGS_4(addsubg, TCG_CALL_NO_RWG_SE, i64, env, i64, s32, i32) DEF_HELPER_FLAGS_4(ldg, TCG_CALL_NO_WG, i64, env, i64, i64, i32) diff --git a/target/arm/tcg/mte_helper.c b/target/arm/tcg/mte_helper.c index 4fa6066cbc..4161f4eb32 100644 --- a/target/arm/tcg/mte_helper.c +++ b/target/arm/tcg/mte_helper.c @@ -91,6 +91,12 @@ typedef struct AllocationTagMem { typedef enum { /* Trap on missing pages, invalid tag access, or watchpoints. */ ATM_NORMAL, + /* + * Trap on missing pages, invalid tag access. + * Align the pointer after initial DATA_ACCESS faults. + * Do not check for watchpoints. + */ + ATM_ZVA, /* Gracefully return no tag memory for invalid pages. */ ATM_PROBE_PAGES, /* @@ -104,7 +110,7 @@ typedef enum { =20 static AllocationTagMem allocation_tag_mem_internal(CPUARMState *env, int ptr_mmu_idx, - vaddr ptr, MMUAccessType ptr_access, + vaddr ptr_orig, MMUAccessType ptr_access, int ptr_size, MMUAccessType tag_access, uintptr_t ra, AllocationTagMemKind atm_kind) { @@ -113,7 +119,7 @@ allocation_tag_mem_internal(CPUARMState *env, int ptr_m= mu_idx, assert((atm_kind >=3D ATM_PROBE_PAGES) =3D=3D (ra =3D=3D 0)); =20 #ifdef CONFIG_USER_ONLY - vaddr clean_ptr =3D useronly_clean_ptr(ptr); + vaddr clean_ptr =3D useronly_clean_ptr(ptr_orig); int flags =3D page_get_flags(clean_ptr); int req_flags =3D ptr_access =3D=3D MMU_DATA_STORE ? PAGE_WRITE_ORG : = PAGE_READ; =20 @@ -123,25 +129,29 @@ allocation_tag_mem_internal(CPUARMState *env, int ptr= _mmu_idx, ret.flags =3D TLB_INVALID_MASK; goto fini; case ATM_NORMAL: - cpu_loop_exit_sigsegv(env_cpu(env), ptr, ptr_access, + case ATM_ZVA: + cpu_loop_exit_sigsegv(env_cpu(env), ptr_orig, ptr_access, !(flags & PAGE_VALID), ra); default: g_assert_not_reached(); } } + if (atm_kind =3D=3D ATM_NORMAL) { - int in_page =3D -(ptr | TARGET_PAGE_MASK); + int in_page =3D -(ptr_orig | TARGET_PAGE_MASK); if (unlikely(ptr_size > in_page)) { - probe_access(env, ptr + in_page, ptr_size - in_page, + probe_access(env, ptr_orig + in_page, ptr_size - in_page, ptr_access, MMU_USER_IDX, ra); } + } else if (atm_kind =3D=3D ATM_ZVA) { + clean_ptr &=3D -ptr_size; } =20 /* Require both MAP_ANON and PROT_MTE for the page. */ if ((flags & PAGE_ANON) && (flags & PAGE_MTE)) { size_t page_data_size =3D TARGET_PAGE_SIZE >> (LOG2_TAG_GRANULE + = 1); uint8_t *tags =3D page_get_target_data(clean_ptr, page_data_size); - uintptr_t index =3D extract64(ptr, LOG2_TAG_GRANULE + 1, + uintptr_t index =3D extract64(clean_ptr, LOG2_TAG_GRANULE + 1, TARGET_PAGE_BITS - LOG2_TAG_GRANULE - = 1); ret.tag_mem =3D tags + index; } @@ -149,6 +159,7 @@ allocation_tag_mem_internal(CPUARMState *env, int ptr_m= mu_idx, ret.ptr_mem =3D g2h_untagged_vaddr(clean_ptr); ret.attrs =3D MEMTXATTRS_UNSPECIFIED; #else + uint64_t ptr =3D ptr_orig; CPUTLBEntryFull *full; hwaddr ptr_paddr, tag_paddr, xlat; MemoryRegion *mr; @@ -169,6 +180,15 @@ allocation_tag_mem_internal(CPUARMState *env, int ptr_= mmu_idx, goto fini; } =20 + /* + * For DC_ZVA and friends, the initial page lookup and trap is perform= ed + * with the original address, but we need to align the further results. + */ + if (atm_kind =3D=3D ATM_ZVA) { + ptr &=3D -ptr_size; + ret.ptr_mem =3D (void *)((uintptr_t)ret.ptr_mem & -ptr_size); + } + /* * Remember these across the second lookup below, * which may invalidate this pointer via tlb resize. @@ -204,7 +224,8 @@ allocation_tag_mem_internal(CPUARMState *env, int ptr_m= mu_idx, ret.flags =3D TLB_INVALID_MASK; goto fini; } - mte_perm_check_fail(env, ptr, ra, tag_access =3D=3D MMU_DATA_S= TORE); + mte_perm_check_fail(env, ptr_orig, ra, + tag_access =3D=3D MMU_DATA_STORE); } /* fall through */ =20 @@ -1146,118 +1167,103 @@ void HELPER(dc_zva)(CPUARMState *env, uint64_t ad= dr, uint32_t desc) do_dczva_0(env, addr, len, mem, mmu_idx, flags, ra); } =20 -/* - * Perform an MTE checked access for DC_ZVA. - */ -uint64_t HELPER(mte_check_zva)(CPUARMState *env, uint32_t desc, uint64_t p= tr) +void HELPER(dc_zva_mte)(CPUARMState *env, uintptr_t ptr_orig, uint32_t des= c) { + int dcz_bytes =3D FIELD_EX32(desc, MTEDESC, SIZEM1) + 1; + int mmu_idx =3D FIELD_EX32(desc, MTEDESC, MIDX); uintptr_t ra =3D GETPC(); - int log2_dcz_bytes, log2_tag_bytes; - int mmu_idx, bit55; - intptr_t dcz_bytes, tag_bytes, i; - void *mem; - uint64_t ptr_tag, mem_tag, align_ptr; + uint64_t ptr =3D ptr_orig, ptr_tag, mem_tag; + int bit55; + + AllocationTagMem r =3D + allocation_tag_mem_internal(env, mmu_idx, ptr, MMU_DATA_STORE, + dcz_bytes, MMU_DATA_LOAD, ra, ATM_ZVA); + + r.flags =3D do_dcxva_traps(env, ptr, dcz_bytes, mmu_idx, + r.flags, r.attrs, ra); =20 bit55 =3D extract64(ptr, 55, 1); - - /* If TBI is disabled, the access is unchecked, and ptr is not dirty. = */ - if (unlikely(!tbi_or_mtx_check(desc, bit55))) { - return ptr; - } - ptr_tag =3D allocation_tag_from_addr(ptr); + ptr &=3D -dcz_bytes; =20 - if (tcma_check(desc, bit55, ptr_tag)) { - goto done; - } + if (unlikely(!tbi_or_mtx_check(desc, bit55)) || + tcma_check(desc, bit55, ptr_tag)) { + /* If TBI is disabled, or TCMA disabled, the access is unchecked. = */ + } else if (r.tag_mem) { + /* + * In arm_cpu_realizefn, we asserted that dcz > LOG2_TAG_GRANULE+1, + * i.e. 32 bytes, which is an unreasonably small dcz anyway, to ma= ke + * sure that we can access one complete tag byte here. + */ + int tag_bytes =3D dcz_bytes / (TAG_GRANULE * 2); =20 - /* - * In arm_cpu_realizefn, we asserted that dcz > LOG2_TAG_GRANULE+1, - * i.e. 32 bytes, which is an unreasonably small dcz anyway, to make - * sure that we can access one complete tag byte here. - */ - log2_dcz_bytes =3D get_dczid_bs(env_archcpu(env)) + 2; - log2_tag_bytes =3D log2_dcz_bytes - (LOG2_TAG_GRANULE + 1); - dcz_bytes =3D (intptr_t)1 << log2_dcz_bytes; - tag_bytes =3D (intptr_t)1 << log2_tag_bytes; - align_ptr =3D ptr & -dcz_bytes; + /* + * Unlike the reasoning for checkN, DC_ZVA is always aligned, and = thus + * it is quite easy to perform all of the comparisons at once with= out + * any extra masking. + * + * The most common zva block size is 64; some of the thunderx cpus= use + * a block size of 128. For user-only, aarch64_max_initfn will se= t the + * block size to 512. Fill out the other cases for future-proofin= g. + * + * In order to be able to find the first miscompare later, we want= the + * tag bytes to be in little-endian order. + */ + switch (tag_bytes) { + case 1: /* zva_blocksize 32 */ + mem_tag =3D *(uint8_t *)r.tag_mem; + ptr_tag *=3D 0x11u; + goto cmp_tag; + case 2: /* zva_blocksize 64 */ + mem_tag =3D cpu_to_le16(*(uint16_t *)r.tag_mem); + ptr_tag *=3D 0x1111u; + goto cmp_tag; + case 4: /* zva_blocksize 128 */ + mem_tag =3D cpu_to_le32(*(uint32_t *)r.tag_mem); + ptr_tag *=3D 0x11111111u; + goto cmp_tag; + case 8: /* zva_blocksize 256 */ + mem_tag =3D cpu_to_le64(*(uint64_t *)r.tag_mem); + ptr_tag *=3D 0x1111111111111111ull; + cmp_tag: + if (unlikely(mem_tag !=3D ptr_tag)) { + goto fail; + } + break; =20 - /* - * Trap if accessing an invalid page. DC_ZVA requires that we supply - * the original pointer for an invalid page. But watchpoints require - * that we probe the actual space. So do both. - */ - mmu_idx =3D FIELD_EX32(desc, MTEDESC, MIDX); - (void) probe_write(env, ptr, 1, mmu_idx, ra); - mem =3D allocation_tag_mem(env, mmu_idx, align_ptr, MMU_DATA_STORE, - dcz_bytes, MMU_DATA_LOAD, ra); - if (!mem) { + case 16: /* zva_blocksize 512 */ + case 32: /* zva_blocksize 1024 */ + case 64: /* zva_blocksize 2048 */ + ptr_tag *=3D 0x1111111111111111ull; + for (int i =3D 0; i < tag_bytes; i +=3D 8, ptr +=3D 16 * TAG_G= RANULE) { + mem_tag =3D cpu_to_le64(*(uint64_t *)(r.tag_mem + i)); + if (unlikely(mem_tag !=3D ptr_tag)) { + goto fail; + } + } + break; + + default: + /* Values above 2KiB are architecturally invalid. */ + g_assert_not_reached(); + + fail: + /* Locate the first nibble that differs. */ + ptr +=3D (ctz64(mem_tag ^ ptr_tag) >> 4) * TAG_GRANULE; + mte_check_fail(env, desc, ptr, ra); + } + } else { /* * If mtx is enabled, then the access is MemTag_CanonicallyTagged, * otherwise it is Untagged. See AArch64.S1DecodeMemAttrs and * AArch64.S1DisabledOutput. */ if (mtx_check(desc, bit55) && !tag_is_canonical(ptr_tag, bit55)) { - mte_check_fail(env, desc, ptr, ra); + mte_check_fail(env, desc, ptr_orig, ra); } - goto done; } =20 - /* - * Unlike the reasoning for checkN, DC_ZVA is always aligned, and thus - * it is quite easy to perform all of the comparisons at once without - * any extra masking. - * - * The most common zva block size is 64; some of the thunderx cpus use - * a block size of 128. For user-only, aarch64_max_initfn will set the - * block size to 512. Fill out the other cases for future-proofing. - * - * In order to be able to find the first miscompare later, we want the - * tag bytes to be in little-endian order. - */ - switch (log2_tag_bytes) { - case 0: /* zva_blocksize 32 */ - mem_tag =3D *(uint8_t *)mem; - ptr_tag *=3D 0x11u; - break; - case 1: /* zva_blocksize 64 */ - mem_tag =3D cpu_to_le16(*(uint16_t *)mem); - ptr_tag *=3D 0x1111u; - break; - case 2: /* zva_blocksize 128 */ - mem_tag =3D cpu_to_le32(*(uint32_t *)mem); - ptr_tag *=3D 0x11111111u; - break; - case 3: /* zva_blocksize 256 */ - mem_tag =3D cpu_to_le64(*(uint64_t *)mem); - ptr_tag *=3D 0x1111111111111111ull; - break; - - default: /* zva_blocksize 512, 1024, 2048 */ - ptr_tag *=3D 0x1111111111111111ull; - i =3D 0; - do { - mem_tag =3D cpu_to_le64(*(uint64_t *)(mem + i)); - if (unlikely(mem_tag !=3D ptr_tag)) { - goto fail; - } - i +=3D 8; - align_ptr +=3D 16 * TAG_GRANULE; - } while (i < tag_bytes); - goto done; - } - - if (likely(mem_tag =3D=3D ptr_tag)) { - goto done; - } - - fail: - /* Locate the first nibble that differs. */ - i =3D ctz64(mem_tag ^ ptr_tag) >> 4; - mte_check_fail(env, desc, align_ptr + i * TAG_GRANULE, ra); - - done: - return useronly_clean_ptr(ptr); + do_dczva_0(env, ptr, dcz_bytes, r.ptr_mem, mmu_idx, r.flags, ra); } =20 uint64_t mte_mops_probe(CPUARMState *env, uint64_t ptr, uint64_t size, diff --git a/target/arm/tcg/translate-a64.c b/target/arm/tcg/translate-a64.c index c3ff46989a..cae8d6826f 100644 --- a/target/arm/tcg/translate-a64.c +++ b/target/arm/tcg/translate-a64.c @@ -3139,13 +3139,13 @@ static void handle_sys(DisasContext *s, bool isread, /* Writes clear the aligned block of memory which rt points into. = */ { TCGv_i32 desc =3D gen_mtedesc_zva(s); + + tcg_rt =3D cpu_reg(s, rt); if (s->mte_active[0]) { - tcg_rt =3D tcg_temp_new_i64(); - gen_helper_mte_check_zva(tcg_rt, tcg_env, desc, cpu_reg(s,= rt)); + gen_helper_dc_zva_mte(tcg_env, tcg_rt, desc); } else { - tcg_rt =3D cpu_reg(s, rt); + gen_helper_dc_zva(tcg_env, tcg_rt, desc); } - gen_helper_dc_zva(tcg_env, tcg_rt, desc); } return; case ARM_CP_DC_GVA: --=20 2.43.0 From nobody Sat Jul 25 13:41:30 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linaro.org ARC-Seal: i=1; a=rsa-sha256; t=1784330749; cv=none; d=zohomail.com; s=zohoarc; b=NfFIgbt4j2iod04y1CUAvGJRsRe5mAmd71dCLK5gAWa7qgWLhTd4gssCekCHRhqn9JymvQK9ZI9qaGv2SL3t/YvsHjkBka/UYh4EcJUr/sy8IUITeD0ve7DjxGJzw7hGLOc+L0SJKBdiT/PiMMLDJnvIG69yLR9hx2Km35YQ1A8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784330749; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=/+gOtEK+4wt+LDZh97nLyEPdOI5ONUbxlvkS7t1kf94=; b=ERl/WzfNdv8bD/MNoENshtw4ce7nD5keFzFZ+ARJhj3PkUR/faZ8m/CfuJtAw65jDa+2d+Bk9rlfiCLMutVSGz823bEqUkbnavA81IESM9zz+GmydejsIMmkakP6hKKyZnEvRrJQwO+qxZ/h6FGejvqqYkc/1E9tV8NLkTHBw3E= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784330749649161.37636382277594; Fri, 17 Jul 2026 16:25:49 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wkru7-0001hV-Op; Fri, 17 Jul 2026 19:23:39 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkru4-0001em-1g for qemu-devel@nongnu.org; Fri, 17 Jul 2026 19:23:36 -0400 Received: from mail-pj1-x102b.google.com ([2607:f8b0:4864:20::102b]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wkru0-00073D-3F for qemu-devel@nongnu.org; Fri, 17 Jul 2026 19:23:35 -0400 Received: by mail-pj1-x102b.google.com with SMTP id 98e67ed59e1d1-38dfe910e9dso5470718a91.3 for ; Fri, 17 Jul 2026 16:23:31 -0700 (PDT) Received: from stoup.. ([32.140.233.50]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13ce2a18a47sm8186261c88.8.2026.07.17.16.23.29 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 17 Jul 2026 16:23:30 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1784330610; x=1784935410; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=/+gOtEK+4wt+LDZh97nLyEPdOI5ONUbxlvkS7t1kf94=; b=NqFTXrzEExv8TuUe0xkLtuz2c6HfTwiPqFiS1384eNiNynvJ1FrzdBdNCughp1cLAr U2PQLYOhyYOBb6+ZRHPLKqI6V670iwD5RuuUEHDtiGy70YQVGpCkkvQ4JFpEX1S/M9oT LVc492Ybw6L1WoUSs8TzFKjj21V1Gr03RaZ2Eg1sLmI3RTfKyGrzcbYGPAeyfJZ9kmE6 42g3MiR6qdFRXWeB+WsFeD0bVaDlc+qxmCpi9yqgu12ZiDO23LBqGtMSA10t7t4IsniV gKPkGawq3LZr0DqGFCUKyweMVtOQOo4IkorLfRbcDKvRuzrL6WdI/Tw+dA3L5tAY6w8p Gkcw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784330610; x=1784935410; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=/+gOtEK+4wt+LDZh97nLyEPdOI5ONUbxlvkS7t1kf94=; b=LXjAcquE6NbMR24KKAb9rVsfaTqqCE9TSs8y2Up+NRTQSaQK1JpXJl7PMGjcDrSf8+ 2zBDMqnfc/kLwRg7I1P+JfC8DzEUJbeVcs7y8fERFg9vdoFX8rNoCdqSLsl1//30mxVR h83SJzQyzdqiEsbJkn+atLQH4nedQAgOZipP636yOzPhmVHTsYeymHesAxp7qnG1r1LU KbekauLMGcUeYzX6cH0K6OUPJmcDZBGPvNEiorNpJSVtQGtzVHQHm+SG3+CgcexbWlsn noi9bFWVa2xgZZMsciTsoCxaDLdDRlVeUBdYXdnBut+z/G/kzkiPiioyNz6CXBh0mgwx mPKQ== X-Gm-Message-State: AOJu0YwkTmxmn3BgKGp7iXFBhLHLFYKa2jWXQZxaaHLW7cd2A9Yt0BT6 wvtZBVixeVKcz1iFZ8a5iohmsdfDJ5X2vdFAelbvY1Et7XV4OC8IW6UPvghnCLsl/FX8HrnOqMU cYQiV X-Gm-Gg: AfdE7ck1bBvOIfChG/lchbU1K1ik6KwVbMV/N8vIytw8l65V58Ty31LiBz1t1ftzQ/D cRlc5S7bqD3ZFq8w2ocUCGaO9E3LNRg+zyHhGf+QOzm9zr6OHao+qdzbBCWS4EW6d3hS8Fl5f40 4pAAjkmymS8WNsTZwgvZvnXYsqILuSdlVZOmUikjlSDY2BkuvkCmZsKcyAZtHrfWs3RVAdMW8LJ qpDetOC4ywWUoRGs/jfe64sUvb9kfX5vAP6bU1cZQaY3NgXrbH8KteVsnFZstY+sj8jSuT/fkBA lOddI9w3fhMRi9/dg0Mv2gEDqN5mqouUkqNysEoDjKN2ul3B8RGAttkRJqVamptCgdVRsL74MpD nqMGO5Ds+3T2XbyMAexEJ1deITSBysfP9RjPTJYnwN8jCuw2WDejWwXqfmxQtBeVSoRnBwIEr1g cjhwyD5AY= X-Received: by 2002:a17:90b:574c:b0:387:e0cb:7ee with SMTP id 98e67ed59e1d1-38e4b585dd2mr4650729a91.34.1784330610477; Fri, 17 Jul 2026 16:23:30 -0700 (PDT) From: Richard Henderson To: qemu-devel@nongnu.org Cc: qemu-arm@nongnu.org Subject: [PATCH 17/17] target/arm: Rewrite DC_GVA, DC_GZVA, STZGM Date: Fri, 17 Jul 2026 16:23:05 -0700 Message-ID: <20260717232306.378988-19-richard.henderson@linaro.org> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260717232306.378988-1-richard.henderson@linaro.org> References: <20260717232306.378988-1-richard.henderson@linaro.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2607:f8b0:4864:20::102b; envelope-from=richard.henderson@linaro.org; helo=mail-pj1-x102b.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linaro.org) X-ZM-MESSAGEID: 1784330750293158500 Content-Type: text/plain; charset="utf-8" Perform alignment trap on device memory. Recognize watchpoints. Perform both in the correct order wrt MTX faults. Signed-off-by: Richard Henderson --- target/arm/tcg/helper-a64-defs.h | 5 +- target/arm/tcg/mte_helper.c | 127 ++++++++++++++++++++++--------- target/arm/tcg/translate-a64.c | 49 +++++------- 3 files changed, 115 insertions(+), 66 deletions(-) diff --git a/target/arm/tcg/helper-a64-defs.h b/target/arm/tcg/helper-a64-d= efs.h index 518e74c8aa..0d0830c837 100644 --- a/target/arm/tcg/helper-a64-defs.h +++ b/target/arm/tcg/helper-a64-defs.h @@ -82,6 +82,9 @@ DEF_HELPER_3(vfp_ah_maxd, f64, f64, f64, fpst) =20 DEF_HELPER_FLAGS_3(dc_zva, TCG_CALL_NO_WG, void, env, i64, i32) DEF_HELPER_FLAGS_3(dc_zva_mte, TCG_CALL_NO_WG, void, env, i64, i32) +DEF_HELPER_FLAGS_3(dc_gva, TCG_CALL_NO_WG, void, env, i64, i32) +DEF_HELPER_FLAGS_3(dc_gva_stub, TCG_CALL_NO_WG, void, env, i64, i32) +DEF_HELPER_FLAGS_3(dc_gzva, TCG_CALL_NO_WG, void, env, i64, i32) =20 DEF_HELPER_FLAGS_3(pacia, TCG_CALL_NO_WG, i64, env, i64, i64) DEF_HELPER_FLAGS_3(pacib, TCG_CALL_NO_WG, i64, env, i64, i64) @@ -111,7 +114,7 @@ DEF_HELPER_FLAGS_4(st2g_parallel, TCG_CALL_NO_WG, void,= env, i64, i64, i32) DEF_HELPER_FLAGS_2(st2g_stub, TCG_CALL_NO_WG, void, env, i64) DEF_HELPER_FLAGS_3(ldgm, TCG_CALL_NO_WG, i64, env, i64, i32) DEF_HELPER_FLAGS_4(stgm, TCG_CALL_NO_WG, void, env, i64, i64, i32) -DEF_HELPER_FLAGS_4(stzgm_tags, TCG_CALL_NO_WG, void, env, i64, i64, i32) +DEF_HELPER_FLAGS_4(stzgm, TCG_CALL_NO_WG, void, env, i64, i64, i32) =20 DEF_HELPER_FLAGS_4(arm_unaligned_access, TCG_CALL_NO_WG, noreturn, env, i64, i32, i32) diff --git a/target/arm/tcg/mte_helper.c b/target/arm/tcg/mte_helper.c index 4161f4eb32..25adc8c714 100644 --- a/target/arm/tcg/mte_helper.c +++ b/target/arm/tcg/mte_helper.c @@ -671,36 +671,6 @@ void HELPER(stgm)(CPUARMState *env, uint64_t ptr, uint= 64_t val, uint32_t mtx) } } =20 -void HELPER(stzgm_tags)(CPUARMState *env, uint64_t ptr, uint64_t val, - uint32_t mtx) -{ - uintptr_t ra =3D GETPC(); - int mmu_idx =3D arm_env_mmu_index(env); - int log2_dcz_bytes, log2_tag_bytes; - intptr_t dcz_bytes, tag_bytes; - uint8_t *mem; - - /* - * In arm_cpu_realizefn, we assert that dcz > LOG2_TAG_GRANULE+1, - * i.e. 32 bytes, which is an unreasonably small dcz anyway, - * to make sure that we can access one complete tag byte here. - */ - log2_dcz_bytes =3D get_dczid_bs(env_archcpu(env)) + 2; - log2_tag_bytes =3D log2_dcz_bytes - (LOG2_TAG_GRANULE + 1); - dcz_bytes =3D (intptr_t)1 << log2_dcz_bytes; - tag_bytes =3D (intptr_t)1 << log2_tag_bytes; - ptr &=3D -dcz_bytes; - - mem =3D allocation_tag_mem(env, mmu_idx, ptr, MMU_DATA_STORE, dcz_byte= s, - MMU_DATA_STORE, ra); - if (mem) { - int tag_pair =3D (val & 0xf) * 0x11; - memset(mem, tag_pair, tag_bytes); - } else if (raw_mtx_check(mtx, extract64(ptr, 55, 1))) { - canonical_tag_write_fail(env, ptr, ra); - } -} - static void mte_sync_check_fail(CPUARMState *env, uint32_t desc, uint64_t dirty_ptr, uintptr_t ra) { @@ -1092,8 +1062,9 @@ bool mte_probe(CPUARMState *env, uint32_t desc, uint6= 4_t ptr) } =20 /* Traps for DC_ZVA, DC_GVA, and friends, after successful page lookup. */ -static int do_dcxva_traps(CPUARMState *env, vaddr addr, size_t len, int mm= u_idx, - int flags, MemTxAttrs attrs, uintptr_t ra) +static int do_dcxva_traps(CPUARMState *env, vaddr addr, size_t len, + int mmu_idx, int flags, MemTxAttrs attrs, + uint32_t mtx_write, uintptr_t ra) { #ifndef CONFIG_USER_ONLY /* @@ -1106,7 +1077,17 @@ static int do_dcxva_traps(CPUARMState *env, vaddr ad= dr, size_t len, int mmu_idx, arm_cpu_do_unaligned_access(env_cpu(env), addr, MMU_DATA_STORE, mmu_idx, ra); } +#endif =20 + /* + * MTX write fault is via AArch64_S1CheckPermissions, which happens + * after AArch64_S1HasAlignmentFaultDueToMemType. + */ + if (mtx_check(mtx_write, extract64(addr, 55, 1))) { + canonical_tag_write_fail(env, addr, ra); + } + +#ifndef CONFIG_USER_ONLY /* Watchpoints have lower priority than alignment faults. */ if (unlikely(flags & TLB_WATCHPOINT)) { cpu_check_watchpoint(env_cpu(env), addr & -len, len, @@ -1158,7 +1139,7 @@ void HELPER(dc_zva)(CPUARMState *env, uint64_t addr, = uint32_t desc) attrs =3D full->attrs; #endif =20 - flags =3D do_dcxva_traps(env, addr, len, mmu_idx, flags, attrs, ra); + flags =3D do_dcxva_traps(env, addr, len, mmu_idx, flags, attrs, 0, ra); =20 /* After traps, treat as aligned blocks. */ addr =3D addr & -len; @@ -1180,7 +1161,7 @@ void HELPER(dc_zva_mte)(CPUARMState *env, uintptr_t p= tr_orig, uint32_t desc) dcz_bytes, MMU_DATA_LOAD, ra, ATM_ZVA); =20 r.flags =3D do_dcxva_traps(env, ptr, dcz_bytes, mmu_idx, - r.flags, r.attrs, ra); + r.flags, r.attrs, 0, ra); =20 bit55 =3D extract64(ptr, 55, 1); ptr_tag =3D allocation_tag_from_addr(ptr); @@ -1266,6 +1247,84 @@ void HELPER(dc_zva_mte)(CPUARMState *env, uintptr_t = ptr_orig, uint32_t desc) do_dczva_0(env, ptr, dcz_bytes, r.ptr_mem, mmu_idx, r.flags, ra); } =20 +static void do_stzgm_tags(void *mem, int dcz_bytes, int tag) +{ + /* + * In arm_cpu_realizefn, we asserted that dcz > LOG2_TAG_GRANULE+1, + * i.e. 32 bytes, which is an unreasonably small dcz anyway, to make + * sure that we can access one complete tag byte here. + */ + int tag_bytes =3D dcz_bytes / (TAG_GRANULE * 2); + int tag_pair =3D (tag & 0xf) * 0x11; + memset(mem, tag_pair, tag_bytes); +} + +void HELPER(dc_gva)(CPUARMState *env, uint64_t ptr, uint32_t desc) +{ + int dcz_bytes =3D FIELD_EX32(desc, MTEDESC, SIZEM1) + 1; + int mmu_idx =3D FIELD_EX32(desc, MTEDESC, MIDX); + uintptr_t ra =3D GETPC(); + + AllocationTagMem r =3D + allocation_tag_mem_internal(env, mmu_idx, ptr, MMU_DATA_STORE, + dcz_bytes, MMU_DATA_STORE, ra, ATM_ZVA= ); + + do_dcxva_traps(env, ptr, dcz_bytes, mmu_idx, r.flags, r.attrs, + r.tag_mem ? 0 : desc, ra); + + if (r.tag_mem) { + do_stzgm_tags(r.tag_mem, dcz_bytes, allocation_tag_from_addr(ptr)); + } +} + +/* DC GVA when tag access is disabled -- we still want all of the traps. */ +void HELPER(dc_gva_stub)(CPUARMState *env, uint64_t ptr, uint32_t desc) +{ + uintptr_t ra =3D GETPC(); + int mmu_idx =3D FIELD_EX32(desc, MTEDESC, MIDX); + +#ifdef CONFIG_USER_ONLY + probe_write(env, ptr, 0, mmu_idx, ra); +#else + int len =3D FIELD_EX32(desc, MTEDESC, SIZEM1) + 1; + void *mem; + CPUTLBEntryFull *full; + int flags =3D probe_access_full(env, ptr, 0, MMU_DATA_STORE, mmu_idx, + false, &mem, &full, ra); + do_dcxva_traps(env, ptr, len, mmu_idx, flags, full->attrs, 0, ra); +#endif +} + +static void do_gzva_stzgm(CPUARMState *env, uint64_t ptr, uint64_t tag, + uint32_t desc, uintptr_t ra) +{ + int dcz_bytes =3D FIELD_EX32(desc, MTEDESC, SIZEM1) + 1; + int mmu_idx =3D FIELD_EX32(desc, MTEDESC, MIDX); + + AllocationTagMem r =3D + allocation_tag_mem_internal(env, mmu_idx, ptr, MMU_DATA_STORE, + dcz_bytes, MMU_DATA_STORE, ra, ATM_ZVA= ); + + r.flags =3D do_dcxva_traps(env, ptr, dcz_bytes, mmu_idx, r.flags, r.at= trs, + r.tag_mem ? 0 : desc, ra); + + if (r.tag_mem) { + do_stzgm_tags(r.tag_mem, dcz_bytes, tag); + } + do_dczva_0(env, ptr, dcz_bytes, r.ptr_mem, mmu_idx, r.flags, ra); +} + +void HELPER(dc_gzva)(CPUARMState *env, uint64_t ptr, uint32_t desc) +{ + do_gzva_stzgm(env, ptr, allocation_tag_from_addr(ptr), desc, GETPC()); +} + +void HELPER(stzgm)(CPUARMState *env, uint64_t ptr, uint64_t tag, uint32_t = desc) +{ + int dcz_bytes =3D FIELD_EX32(desc, MTEDESC, SIZEM1) + 1; + do_gzva_stzgm(env, ptr & -dcz_bytes, tag, desc, GETPC()); +} + uint64_t mte_mops_probe(CPUARMState *env, uint64_t ptr, uint64_t size, uint32_t desc) { diff --git a/target/arm/tcg/translate-a64.c b/target/arm/tcg/translate-a64.c index cae8d6826f..6ce123eafc 100644 --- a/target/arm/tcg/translate-a64.c +++ b/target/arm/tcg/translate-a64.c @@ -3150,41 +3150,25 @@ static void handle_sys(DisasContext *s, bool isread, return; case ARM_CP_DC_GVA: { - TCGv_i64 clean_addr, tag; + TCGv_i32 desc =3D gen_mtedesc_zva(s); =20 - /* - * DC_GVA, like DC_ZVA, requires that we supply the original - * pointer for an invalid page. Probe that address first. - */ tcg_rt =3D cpu_reg(s, rt); - clean_addr =3D clean_data_tbi(s, tcg_rt); - gen_probe_access(s, clean_addr, MMU_DATA_STORE, MO_8); - if (s->ata[0]) { - /* Extract the tag from the register to match STZGM. */ - tag =3D tcg_temp_new_i64(); - tcg_gen_shri_i64(tag, tcg_rt, 56); - gen_helper_stzgm_tags(tcg_env, clean_addr, tag, - tcg_constant_i32(s->mtx)); + gen_helper_dc_gva(tcg_env, tcg_rt, desc); + } else { + gen_helper_dc_gva_stub(tcg_env, tcg_rt, desc); } } return; case ARM_CP_DC_GZVA: { - TCGv_i64 clean_addr, tag; TCGv_i32 desc =3D gen_mtedesc_zva(s); =20 - /* For DC_GZVA, we can rely on DC_ZVA for the proper fault. */ tcg_rt =3D cpu_reg(s, rt); - clean_addr =3D clean_data_tbi(s, tcg_rt); - gen_helper_dc_zva(tcg_env, clean_addr, desc); - if (s->ata[0]) { - /* Extract the tag from the register to match STZGM. */ - tag =3D tcg_temp_new_i64(); - tcg_gen_shri_i64(tag, tcg_rt, 56); - gen_helper_stzgm_tags(tcg_env, clean_addr, tag, - tcg_constant_i32(s->mtx)); + gen_helper_dc_gzva(tcg_env, tcg_rt, desc); + } else { + gen_helper_dc_zva(tcg_env, tcg_rt, desc); } } return; @@ -4767,6 +4751,7 @@ static bool trans_LD_single_repl(DisasContext *s, arg= _LD_single_repl *a) static bool trans_STZGM(DisasContext *s, arg_ldst_tag *a) { TCGv_i64 addr, tcg_rt; + TCGv_i32 desc; =20 if (!dc_isar_feature(aa64_mte, s)) { return false; @@ -4781,17 +4766,19 @@ static bool trans_STZGM(DisasContext *s, arg_ldst_t= ag *a) =20 addr =3D read_cpu_reg_sp(s, a->rn, true); tcg_gen_addi_i64(addr, addr, a->imm); - tcg_rt =3D cpu_reg(s, a->rt); =20 + desc =3D gen_mtedesc_zva(s); if (s->ata[0]) { - gen_helper_stzgm_tags(tcg_env, addr, tcg_rt, tcg_constant_i32(s->m= tx)); + tcg_rt =3D cpu_reg(s, a->rt); + gen_helper_stzgm(tcg_env, addr, tcg_rt, desc); + } else { + /* + * The non-tags portion of STZGM is mostly like DC_ZVA, + * except the alignment happens before the access. + */ + tcg_gen_andi_i64(addr, addr, -s->dcz_blocksize); + gen_helper_dc_zva(tcg_env, addr, desc); } - /* - * The non-tags portion of STZGM is mostly like DC_ZVA, - * except the alignment happens before the access. - */ - tcg_gen_andi_i64(addr, addr, -s->dcz_blocksize); - gen_helper_dc_zva(tcg_env, addr, gen_mtedesc_zva(s)); return true; } =20 --=20 2.43.0 From nobody Sat Jul 25 13:41:30 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linaro.org ARC-Seal: i=1; a=rsa-sha256; t=1784330724; cv=none; d=zohomail.com; s=zohoarc; b=YyJgZDdsti3ONKEzXCVQ2x55qMpGq35OjHmBxk52+05PYsTA4v/9PZznTscljcCuSRp+9g4RMZQXWWW4IiAALBJsfR7+7+YploTIP7KJ/eTVEtQuSkHf95JvOZDX0StEcwEFXWxa/uGLN0lUnJ5J4Ip/v2Q0CLEcdgjN85IkRkk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784330724; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=vt3DiaqW5qG2P2oPwNInNzI8OWYzGcBaBG9ClXHUZ0A=; b=bAqiRorEsz58p43HN+iclkNv6QeIoaen4+rKagz8IQtyGYNnSpRQ7E0TZz7PrGcpBrQ6OeeF4gHZHaQR/aE83bjXxWELCoewwV12gTpv1NnlED10hGq01t+d17E6XUocOpn7Mcy2ZZ33w13gvB7D6oBHZr2Qjmd3WZzgmzNeB6M= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784330724127939.8034606817496; Fri, 17 Jul 2026 16:25:24 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wkrtl-0001T2-Q4; Fri, 17 Jul 2026 19:23:17 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkrth-0001Qk-RN for qemu-devel@nongnu.org; Fri, 17 Jul 2026 19:23:13 -0400 Received: from mail-pj1-x1032.google.com ([2607:f8b0:4864:20::1032]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wkrtg-0006xA-2O for qemu-devel@nongnu.org; Fri, 17 Jul 2026 19:23:13 -0400 Received: by mail-pj1-x1032.google.com with SMTP id 98e67ed59e1d1-381c51fde6bso8331325a91.2 for ; Fri, 17 Jul 2026 16:23:11 -0700 (PDT) Received: from stoup.. ([32.140.233.50]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13ce2a18a47sm8186261c88.8.2026.07.17.16.23.09 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 17 Jul 2026 16:23:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1784330591; x=1784935391; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=vt3DiaqW5qG2P2oPwNInNzI8OWYzGcBaBG9ClXHUZ0A=; b=xD9q541/6ZQljVILJODX8YwKqDL72ro0GByGEzQmF17jWMi+v6RHfnn7D4FgrryUNM gqIXhaKmgRK0PFJ+g+1TG98I+BpFc5MeYxzQLq0+mdCyJedQbh6/YrtISflEKaeW+356 6lAyX7d9MgDrVbnqDLp26paiMKsLRLIjAu4ABACbAa+10sRgCPezcDYhdVONkiregUcl P3OVhyA9EFoqyqGZYT738jdPcXoj4E/ZzgNzg8L0uwt7mpKq4ZIbJRCnUcS6DIgp8IVe FSZpAmuJ/vv+DqWUJroCG4DYuJrefsPiK5EzwMVCg8LjK82W4qWwRJVxzwhBvSP4CHEd PmSA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784330591; x=1784935391; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=vt3DiaqW5qG2P2oPwNInNzI8OWYzGcBaBG9ClXHUZ0A=; b=SuxvhPDkzQtqRDvc/3pb51TboGWEgcxzRx7I2c4X1X0zK7uzd4ip+Mv9dDNX67bbRX Fohs/MIztiGZiZfoX9RzxN6x/aepLcSuudsslpVErrhxCohwf8yNxIsBvnosr1WzUyZm 5TrpJ1g0vN96r9wUx+nht71MOaFXLqweVvS1HJhDYxSusCRCGvGoaRpnkO08R+zWns7U iy+idKK4l/7RbBMdFlzKZ18344YZ9apTPnC2CSFR2WoRfEBg3Kd3BGCTgAQSFnehxu2H eWeU6JFySJbBHAm1MVXkh0wouL1ASwjUOAofTUuCicEewjIX4dM+KC1sA7RXUwa9EWHC XyKQ== X-Gm-Message-State: AOJu0YxngUoX849dJ76QolkDCE1mDqpDmMEIWV9er9n6a3USP0xHESYR tmt+h+7bFdeDnC5dBOt/fQD8qy2VqfmZbPf0N10V5WGSDsOc2wUmooq8M7PSG/fJdQ7pty0YWlG WUqUy X-Gm-Gg: AfdE7clqS9Tm261UduhyY0RlEAuLYKzQX7W1cf6a6xlXTTp9OVCQGq2kgWr8fStuHRH dlC2dwzJWeHFCcyjgz7RFwvAeH/Hmo5UgV+bHfSPrUj9xAU5tkgfRxw+dibDTIgfHO1SYNQII8h 55y2QrYHa76/M32J5XFcE4WbBG7ZV0D8Q4Bs2DGhbL+kKV9KM+6TOy5h4EhiLkFriHQjmNKrJT/ ke8sZRNnNvZHP2FTIkn0Qr65go8cqt+tn2AO2ZS+2oGCOgGbRIVhL03ab57hFKRg8/6a9ahIfKs TlRDycNe6z3oLquM0cXHfEmhAHMQoi7noLbkcnKhR8NTVhqmApmH5uKxyshNn8RT9yXPP+VM44j llhcvF3IGdR5/u2Dq9OsMVRXjKaMLyC6ShL2uCQs/2xGT44PPyeJk+x740Fi5L7iA8Ji5ZRlyOX 2TVX4ROjU= X-Received: by 2002:a17:90b:1804:b0:38d:ecfe:41ac with SMTP id 98e67ed59e1d1-38e4b2948admr4575340a91.0.1784330590589; Fri, 17 Jul 2026 16:23:10 -0700 (PDT) From: Richard Henderson To: qemu-devel@nongnu.org Cc: qemu-arm@nongnu.org Subject: [PATCH for-11.1] target/arm: Fix testing of raw mtx value Date: Fri, 17 Jul 2026 16:22:49 -0700 Message-ID: <20260717232306.378988-3-richard.henderson@linaro.org> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260717232306.378988-1-richard.henderson@linaro.org> References: <20260717232306.378988-1-richard.henderson@linaro.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2607:f8b0:4864:20::1032; envelope-from=richard.henderson@linaro.org; helo=mail-pj1-x1032.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linaro.org) X-ZM-MESSAGEID: 1784330726446158500 Content-Type: text/plain; charset="utf-8" MTX is always a pair of bits, one for each half of the address space. Testing it like a boolean is incorrect. Introduce raw_mte_check, a mirror of the similar mte_check function that applies when MTX is passed in MTEDESC. Fixes: 8912ceced815 ("target/arm: load on canonical tag loads ext bits") Signed-off-by: Richard Henderson Reviewed-by: Philippe Mathieu-Daud=C3=A9 --- target/arm/tcg/mte_helper.c | 25 +++++++++++++++++-------- 1 file changed, 17 insertions(+), 8 deletions(-) diff --git a/target/arm/tcg/mte_helper.c b/target/arm/tcg/mte_helper.c index 04c637a9e2..616c395cb3 100644 --- a/target/arm/tcg/mte_helper.c +++ b/target/arm/tcg/mte_helper.c @@ -374,6 +374,12 @@ int load_tag1(uint64_t ptr, uint8_t *mem) return extract32(*mem, ofs, 4); } =20 +/* Like mtx_check, but simple mtx bit pair instead of MTEDESC. */ +static bool raw_mtx_check(unsigned mtx, unsigned bit55) +{ + return (mtx >> bit55) & 1; +} + uint64_t HELPER(ldg)(CPUARMState *env, uint64_t ptr, uint64_t xt, uint32_t= mtx) { int mmu_idx =3D arm_env_mmu_index(env); @@ -387,9 +393,11 @@ uint64_t HELPER(ldg)(CPUARMState *env, uint64_t ptr, u= int64_t xt, uint32_t mtx) /* Load if page supports tags. */ if (mem) { rtag =3D load_tag1(ptr, mem); - } else if (mtx) { - uint64_t bit55 =3D extract64(ptr, 55, 1); - rtag =3D 0xF * bit55; + } else { + bool bit55 =3D extract64(ptr, 55, 1); + if (raw_mtx_check(mtx, bit55)) { + rtag =3D 0xF * bit55; + } } =20 return address_with_allocation_tag(xt, rtag); @@ -444,7 +452,7 @@ static inline void do_stg(CPUARMState *env, uint64_t pt= r, uint64_t xt, /* Store if page supports tags. */ if (mem) { store1(ptr, mem, allocation_tag_from_addr(xt)); - } else if (mtx) { + } else if (raw_mtx_check(mtx, extract64(ptr, 55, 1))) { canonical_tag_write_fail(env, ptr, ra); } } @@ -477,6 +485,7 @@ static inline void do_st2g(CPUARMState *env, uint64_t p= tr, uint64_t xt, uint8_t *mem1, *mem2; =20 check_tag_aligned(env, ptr, ra); + mtx =3D raw_mtx_check(mtx, extract64(ptr, 55, 1)); =20 /* * Trap if accessing an invalid page(s). @@ -561,8 +570,8 @@ uint64_t HELPER(ldgm)(CPUARMState *env, uint64_t ptr, u= int32_t mtx) /* The tag is squashed to zero if the page does not support tags. */ if (!tag_mem) { /* Load canonical value if mtx is set (untagged memory region) */ - if (mtx) { - bool bit55 =3D extract64(ptr, 55, 1); + bool bit55 =3D extract64(ptr, 55, 1); + if (raw_mtx_check(mtx, bit55)) { ret =3D extract64(-bit55, 0, 1 << gm_bs); shift =3D extract64(ptr, LOG2_TAG_GRANULE, 4) * 4; return ret << shift; @@ -630,7 +639,7 @@ void HELPER(stgm)(CPUARMState *env, uint64_t ptr, uint6= 4_t val, uint32_t mtx) */ if (!tag_mem) { /* Storing tags to canonically tagged region: fault. */ - if (mtx) { + if (raw_mtx_check(mtx, extract64(ptr, 55, 1))) { canonical_tag_write_fail(env, ptr, ra); } return; @@ -687,7 +696,7 @@ void HELPER(stzgm_tags)(CPUARMState *env, uint64_t ptr,= uint64_t val, if (mem) { int tag_pair =3D (val & 0xf) * 0x11; memset(mem, tag_pair, tag_bytes); - } else if (mtx) { + } else if (raw_mtx_check(mtx, extract64(ptr, 55, 1))) { canonical_tag_write_fail(env, ptr, ra); } } --=20 2.43.0