From nobody Sat Sep 26 20:52:28 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linaro.org ARC-Seal: i=1; a=rsa-sha256; t=1789602769; cv=none; d=zohomail.com; s=zohoarc; b=cKu2hVRgI/HHv3rGDieihWyJb0ipcxAH5OkdoN3cz/I5DRZZ5nVdEfOjGnWWN0k4QyLs7GoR7UrgBWx3y69rvNNXYjFWYqgq6HVk+Ioma7lX4g7IseBM7fwzJN37+rx+dIUrPKk62OYLKTj9InUxSqU4BsvCnmPhSrs6XGrf7bk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789602769; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=AWO3deFtSiKyFUxh5UBV31HbQHuWjBkV/oJXPBrfIqI=; b=Xm/nlgFNnpoD9wffQ/sfO1kv+7uKWoybLUuFQS7PMmhAkqUr9lB31yTV+QTARSI+3SdaVZm3pxHlTxH6v8Ws/MLb2a9EMTPrQHNh/i4CnCJ/irWCNqgcPVjcSAZutU6QQERo/3UTyvhxLOmPK8IPsyPAXdylKu2nSTQyOn1eAfM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789602768966955.0131846870847; Wed, 16 Sep 2026 16:52:48 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x6zQQ-00063F-2y; Wed, 16 Sep 2026 19:52:26 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x6zQJ-00062l-RT for qemu-devel@nongnu.org; Wed, 16 Sep 2026 19:52:20 -0400 Received: from mail-pj2-x10.google.com ([2607:f8b0:4864:39::10]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1x6zQ3-0006bC-P6 for qemu-devel@nongnu.org; Wed, 16 Sep 2026 19:52:05 -0400 Received: by mail-pj2-x10.google.com with SMTP id 98e67ed59e1d1-396ccafb74fso224376a91.3 for ; Wed, 16 Sep 2026 16:52:03 -0700 (PDT) Received: from stoup ([2603:800c:7900:ed00:325f:1938:d075:8c13]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-33bfb05e604sm9240454eec.12.2026.09.16.16.52.01 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 16 Sep 2026 16:52:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1789602722; x=1790207522; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=AWO3deFtSiKyFUxh5UBV31HbQHuWjBkV/oJXPBrfIqI=; b=znaRktGUhuxZyYIK5K6F7VWZ2solhCguzdv73je9WQc1pRBDaJYhpR1t9WaFlGp/eq b+0dLMVfcsyP80j5PA1hForvg4sgC1TuEW/bOVJzKKFO8xQ0Ztohm/1HbOm/qM4MmZXz l1tff21Ej5Uudvc6l0NCpds/NELFvZoiqxoKWf4M4W8quin5Xk8LSpDHKZIDpe9YFgse f530rnihy/AMTuhVijAAgZTWUbGQol7vCwmm9SzObBkNcznHGbwwRuYZHsNVmpYD5upi uIqaJqWx+6+bKYtXDhXQLPkWfHaNgyZD3PtW4ao4wi4/IFD/WAlLhN2kJUusRudCSqX1 VIZA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789602722; x=1790207522; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=AWO3deFtSiKyFUxh5UBV31HbQHuWjBkV/oJXPBrfIqI=; b=QikSmxxhqvszP8L3WtNP10bIuk7iNVCJZX3frq8eGAj8TQhMORfjR/ofBX2eyK+gM+ LCwhLFDxQDAQ4eE7/cFC4hCvHvQ5hk51MO4ftzfqlpQmldHqbfkqX9YP3b31ElQZb378 +9Zq5vIx6zVpcmQ+ElIDMO9c8OS2rZYi1Tg1/qRiR2fDLp+NBFPG2fwer+TEpcs6g3Nn RDYVPHOR1GT8b7PhXMrLe+PuWRXjtXStI0sDT29DCV63AdvIvWf3YcgeJvOiQ0vW3cLH DEEWJMQ+ISh5V7AH8KhtCRvJcWZzJlA1jH0BoIeb/Gzt2vAGRWpKTOPlWnbWS4OIWyY1 OznQ== X-Gm-Message-State: AFuF++mbeg7XwsIVjFdd+cbNE1g489IosgYGyMeekdus+mlrCbUuymN3 JvHsNvCOrHrJV2Dh+De5SV6KKb6JuT/+b8yuw3j8BQ0lkOObKrFkuMeO+P3bj3gfEFO2oRitMNH xADDaLAI= X-Gm-Gg: AYBFou3sxKicLwDUYk0W7+SmPwYNKVw4aHlWy40FocZhYIXrEDE6X/ZH7b6LWJemzP4 Z7iKn/ixamqCtOOk5EuHqLaNtliDHr3FR7wbNz5d3ZzDCDE/kNBqlRKv+pTdYG4oYWtTCVu4Ids 7gG1orJSx7ULOipq/QaOpd11o2QeI/fW380CBI0MA9mBAlmnbVTM1LamisJxcGqNVfcdDq+ocA3 /aPghoNPfTQYcljWe7agx1v5kFmBjI2pfB44DoDMgDXLjk+0q0ZKIh0g9Eq5IH5RWsRMFVxg5c7 7TZo63DaCCR2p1cITmBOoQaVwbI4SaRGPcmNVFidKEKQCsKUH/6112UWL9JYXB6d3NKewcNPp9U EDaH6TtfmfbIFKtSek56xG1PRgF5KQtxZykeVRbwWbN8JpZYn+F6UsuXHw3uVRg0m/R6c6sI+YO uojNmawnfZcXIq2F5rw8OSCvO7C7edc4yPW0w2QsrUJglx52Faxv5G0V/okNxWOQRtnrwPuM1/+ FvgBpE= X-Received: by 2002:a17:90a:a8f:b0:39e:234a:f071 with SMTP id 98e67ed59e1d1-39e234af2a6mr8934514a91.19.1789602722314; Wed, 16 Sep 2026 16:52:02 -0700 (PDT) From: Richard Henderson To: qemu-devel@nongnu.org Cc: cui.tao@linux.dev Subject: [PATCH v2 1/2] accel/tcg: Allow some address space wraparound during translation Date: Wed, 16 Sep 2026 13:51:57 -1000 Message-ID: <20260916235158.294901-2-richard.henderson@linaro.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260916235158.294901-1-richard.henderson@linaro.org> References: <20260916235158.294901-1-richard.henderson@linaro.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2607:f8b0:4864:39::10; envelope-from=richard.henderson@linaro.org; helo=mail-pj2-x10.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linaro.org) X-ZM-MESSAGEID: 1789602770408158500 Content-Type: text/plain; charset="utf-8" Allow the two pages of translation to be non-contiguous. As long as the target translator wraps pc properly, this allows address space wraparound to function correctly. This avoids an assert on a valid i386 system-mode test case. Reported-by: Tao Cui Signed-off-by: Richard Henderson Reviewed-by: Jim MacArthur --- include/exec/translator.h | 3 +++ accel/tcg/translator.c | 45 ++++++++++++++++++++++++--------------- 2 files changed, 31 insertions(+), 17 deletions(-) diff --git a/include/exec/translator.h b/include/exec/translator.h index 978dee25add..104e6d4f361 100644 --- a/include/exec/translator.h +++ b/include/exec/translator.h @@ -55,6 +55,8 @@ typedef enum DisasJumpType { * @pc_first: Address of first guest instruction in this TB. * @pc_next: Address of next guest instruction in this TB (current during * disassembly). + * @pc_second_page: Address of the beginning of the second page of this TB, + * or -1 if the TB does not yet extend to a second page. * @is_jmp: What instruction to disassemble next. * @num_insns: Number of translated instructions (including current). * @max_insns: Maximum number of instructions to be translated in this TB. @@ -69,6 +71,7 @@ struct DisasContextBase { TranslationBlock *tb; vaddr pc_first; vaddr pc_next; + vaddr pc_second_page; DisasJumpType is_jmp; int num_insns; int max_insns; diff --git a/accel/tcg/translator.c b/accel/tcg/translator.c index 57daded60ff..52e605708f3 100644 --- a/accel/tcg/translator.c +++ b/accel/tcg/translator.c @@ -134,6 +134,7 @@ void translator_loop(CPUState *cpu, TranslationBlock *t= b, int *max_insns, db->tb =3D tb; db->pc_first =3D pc; db->pc_next =3D pc; + db->pc_second_page =3D -1; db->is_jmp =3D DISAS_NEXT; db->num_insns =3D 0; db->max_insns =3D *max_insns; @@ -285,16 +286,18 @@ static bool translator_ld(CPUArchState *env, DisasCon= textBase *db, /* * The read must conclude on the second page and not extend to a third. * - * TODO: We could allow the two pages to be virtually discontiguous, - * since we already allow the two pages to be physically discontiguous. - * The only reasonable use case would be executing an insn at the end - * of the address space wrapping around to the beginning. For that, - * we would need to know the current width of the address space. - * In the meantime, assert. + * TODO: This doesn't handle address space wraparound properly for + * multi-byte reads, as we don't know the size of the address space he= re. + * But if the target translator wraps pc to 0 itself, and issues align= ed + * reads, then this can work. */ - base =3D (base & TARGET_PAGE_MASK) + TARGET_PAGE_SIZE; - assert(((base ^ pc) & TARGET_PAGE_MASK) =3D=3D 0); - assert(((base ^ last) & TARGET_PAGE_MASK) =3D=3D 0); + if (db->pc_second_page =3D=3D -1) { + db->pc_second_page =3D pc & TARGET_PAGE_MASK; + } else { + assert((pc & TARGET_PAGE_MASK) =3D=3D db->pc_second_page); + } + assert((last & TARGET_PAGE_MASK) =3D=3D db->pc_second_page); + base =3D db->pc_second_page; host =3D db->host_addr[1]; =20 if (host =3D=3D NULL) { @@ -372,16 +375,24 @@ static void record_save(DisasContextBase *db, vaddr p= c, { int offset; =20 - /* Do not record probes before the start of TB. */ - if (pc < db->pc_first) { - return; - } - /* - * In translator_access, we verified that pc is within 2 pages - * of pc_first, thus this will never overflow. + * In translator_ld, we verified that we touched no more than 2 pages, + * but we did not verify that they were virtually contiguous. + * Here, reimagine the two pages as virtually contiguous. */ - offset =3D pc - db->pc_first; + if (likely(((db->pc_first ^ pc) & TARGET_PAGE_MASK) =3D=3D 0)) { + /* first page */ + /* Do not record probes before the start of TB. */ + if (pc < db->pc_first) { + return; + } + offset =3D pc - db->pc_first; + } else { + int first_page_end_offset =3D -(db->pc_first | TARGET_PAGE_MASK); + assert(db->pc_second_page !=3D -1); + assert((pc & TARGET_PAGE_MASK) =3D=3D db->pc_second_page); + offset =3D pc - db->pc_second_page + first_page_end_offset; + } =20 /* * Either the first or second page may be I/O. If it is the second, --=20 2.53.0 From nobody Sat Sep 26 20:52:28 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linaro.org ARC-Seal: i=1; a=rsa-sha256; t=1789602766; cv=none; d=zohomail.com; s=zohoarc; b=dZsfhqYGgwZ/EZRr2uGOksCzQ3+KGULEDlU4nHstWxskYHTeVfQyGEbXA0tvbkNeQw1qD0/41NJHrqLliwG+ZDsgAuOA/MSPRk/Y3ufkS8UdosX5hY586WTRZpeqZal81FQOAfYlsfgtT6HeabnIyCC8pKE8RFYvWl0kWfWKNWw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789602766; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=m8E/wyVeNfRdDfLa7dYg+pi94E3VOm5je38wI3uaR/I=; b=jQaeq6Jebey/BxQOnQoQXJSmYSTxBkHOHUFZiZX+K4tNLXl+8BfPsN6TIwNkGYzrVX2wXcDj6A0y0BcYzqr0x4/uTE9Rs17woCpBxfFG9AiH/7FVnyzBMqVaar9LliGOzKcJd6wTsR/3qmYt6BithkrbXeJBoZ1XmM559uur6hA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789602766466754.853735955173; Wed, 16 Sep 2026 16:52:46 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x6zQR-00063p-Oj; Wed, 16 Sep 2026 19:52:27 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x6zQJ-00062m-SP for qemu-devel@nongnu.org; Wed, 16 Sep 2026 19:52:21 -0400 Received: from mail-pj2-x0f.google.com ([2607:f8b0:4864:39::f]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1x6zQ4-0006bL-Ue for qemu-devel@nongnu.org; Wed, 16 Sep 2026 19:52:06 -0400 Received: by mail-pj2-x0f.google.com with SMTP id 98e67ed59e1d1-39dbdfaef3cso233589a91.1 for ; Wed, 16 Sep 2026 16:52:04 -0700 (PDT) Received: from stoup ([2603:800c:7900:ed00:325f:1938:d075:8c13]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-33bfb05e604sm9240454eec.12.2026.09.16.16.52.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 16 Sep 2026 16:52:03 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1789602723; x=1790207523; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=m8E/wyVeNfRdDfLa7dYg+pi94E3VOm5je38wI3uaR/I=; b=beHdINKuH49283AD2wzgA8L8R5a0ZtcSoB9ySQIsG9GsVqicoS8G2eKFMbVvhsdVYn 3f5qlTknzFKVWKqjRmxeYREqMVJxszZkEztQXy5Qmp6AKwNnWpDkSboD2aWHbk8P5U1l phPgRlT7ZowdN6rKgk0aqXTOgo4V5mNbB+o8IYF9UKJnjCuJlRBLkuoLNliklqH1xHb/ lfdEpodVrLHs8yBm4ZNJd+xzS3nQoLNPIU9fgp/rQN1vH5zA/xDkhT1uTToaBxUHYeiM 8wXtTsjYGw72P6S1S7vmGHSEUUJkwY69FQRUd3q2pRLnbCwmiP+wDk/6mqreMmcXQV9B YiyQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789602723; x=1790207523; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=m8E/wyVeNfRdDfLa7dYg+pi94E3VOm5je38wI3uaR/I=; b=yGaiA2Fq2+M7nXtfOTYvOlrWoD2IkF41oGWk61L57FY7z3SGxTDtWG23ZB3sLbziTa cSgb+S+NdlaRNFHoumCt7SFexPk31VS29ADR3r73tV3zV/VtTy73wotk374iQPgTDQoY Her5zyh2nEcwCFwCMrTzlhoC6TdlZyqzlg+goEQGKwoDUIDaEQoI5pTHJqd5anmoF9im whVceQzDAGKwexDo59VRw1B2l8ViFK3d+Z9Zxy0yXKt8cV2Fxaj5iGX1VQa21e1WAhPI cn0g3DLECkNVFB675rJaA2KeBjlYwNogKPhoLbwZUqORFXu0/VM9XrkqLzcmQhJIWoym Rjjw== X-Gm-Message-State: AFuF++nahryD0aKlo73IW+pJ8F/FYGxZR4vQOP5di41QLvRhqwziqw8Z gaotyJxWlWBCU13X+I8Kn+AWmYbXjwXoy+N066G6dsSKupqvIFlRG+VlkGFkhBeL9ovvFZxeJsO vG/b7ilQ= X-Gm-Gg: AYBFou3Hzex5A4cRAFPdBQD+XLkRdqN5G2L5/nKwqDpcoD+f0uWpvv91IwCixrUnraS rSOe20QRmQ1++2RX+u5NjewPHmpFcVfbjayzZwZ3t/pRf2LTODYKsCFkVvK38oM2h7YJS8XO+s1 O66mZ00kLbbFOl2igZOkKzJHZidGbMK/6HY7oOiz7bth3c72fShn7vBXPyQcFbA76+wpQqDGN3f 4GHHewfyAv0bC6i03X4TxKbNUS2o9yZ5YX6IxZ/XqZeXv2Epbu2GSdGk2nswT5U3IlO66MA7bmP 5R+qcluQhLjgG+3bw2bONXxrDeAI8b+dXWUA2rG42r62LcyBTTBnXDb7hbVjqo2oN9N2shuMnEl XLIo5TCuOdMIWzYj85mZdTRnFsFtODlXejS7U03LaHMeQhl8KFlwhJATApu+2h6Y1JI5u/bAjxT zNdp7spWJUtYQxLZ+YBbhXAEEehsb+REFffXvT9bOHVlV67TIlNYSagiWtWy/7eVR7e8bq6vSiJ 0wZGsgRd8EhOyjELQ== X-Received: by 2002:a17:90a:d646:b0:39e:3554:4d0c with SMTP id 98e67ed59e1d1-39e35545ae5mr6624370a91.2.1789602723405; Wed, 16 Sep 2026 16:52:03 -0700 (PDT) From: Richard Henderson To: qemu-devel@nongnu.org Cc: cui.tao@linux.dev, Tao Cui Subject: [PATCH v2 2/2] tests/tcg/i386/system: Add regression test for translator_ld wraparound Date: Wed, 16 Sep 2026 13:51:58 -1000 Message-ID: <20260916235158.294901-3-richard.henderson@linaro.org> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260916235158.294901-1-richard.henderson@linaro.org> References: <20260916235158.294901-1-richard.henderson@linaro.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2607:f8b0:4864:39::f; envelope-from=richard.henderson@linaro.org; helo=mail-pj2-x0f.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linaro.org) X-ZM-MESSAGEID: 1789602768940158500 Content-Type: text/plain; charset="utf-8" From: Tao Cui Add a test case that reaches an instruction straddling the end of the 32-bit address space (0xfffffffe). The top page (0xfffff000) is SeaBIOS ROM, so the cross-boundary byte is the ROM's own 0x00 (add r/m8, r8) at 0xffffffff, whose modrm is fetched from [0x0]. A short exit stub is placed there. The case runs on qemu-system-i386 since the bug is 32-bit only. Signed-off-by: Tao Cui Message-ID: <20260709020529.126652-3-cui.tao@linux.dev> [rth: Simplify and convert to meson test harness] Signed-off-by: Richard Henderson Reviewed-by: Jim MacArthur --- tests/tcg/i386/system/meson.build | 4 ++++ tests/tcg/i386/system/wraparound.S | 35 ++++++++++++++++++++++++++++++ 2 files changed, 39 insertions(+) create mode 100644 tests/tcg/i386/system/wraparound.S diff --git a/tests/tcg/i386/system/meson.build b/tests/tcg/i386/system/meso= n.build index d3f73997c7f..c08563d0ab5 100644 --- a/tests/tcg/i386/system/meson.build +++ b/tests/tcg/i386/system/meson.build @@ -34,6 +34,10 @@ foreach t: tcg_tests['multiarch-softmmu']['tests'] endforeach endforeach =20 +tests +=3D { + 'wraparound.S': { 'cflags': cflags, 'qemu_args': ['-m', '4G'] + qemu_def= _args } +} + if 'qemu-system-i386' in emulators tcg_tests +=3D { 'i386-softmmu': { diff --git a/tests/tcg/i386/system/wraparound.S b/tests/tcg/i386/system/wra= paround.S new file mode 100644 index 00000000000..9c77b3a8468 --- /dev/null +++ b/tests/tcg/i386/system/wraparound.S @@ -0,0 +1,35 @@ +/* SPDX-License-Identifier: GPL-2.0-or-later */ +/* + * Regression test for the translator_ld crash when an instruction + * straddles the end of the 32-bit address space (i386). + */ + + .code32 + .section .text + +main: + /* + * The top page (0xfffff000) is SeaBIOS ROM and cannot be written. + * Its byte at 0xffffffff (0x00 =3D "add r/m8, r8") already crosse= s the + * page boundary into page1 at 0x0, which is exactly the case + * translator_ld must handle without aborting. Reaching 0xfffffffe + * runs the ROM's cld, then that add; the add's modrm is fetched f= rom + * [0x0], which is RAM, so build a short exit stub there: + * + * [0x0] c0 modrm -> "add al, al" (reg; EIP -> 1) + * [0x1] c3 ret + * + * Note: this relies on the SeaBIOS byte at 0xffffffff being 0x00 + * (add r/m8, r8); if that ever changes, the stub below must move. + * + * Note that eax =3D 0 before and after the stub, so this becomes + * the exit code of the test. + */ + xor %eax, %eax + movw $0xc3c0, (%eax) + movl $0xfffffffe, %ecx + jmp *%ecx + + .globl main + .type main, @function + .size main, . - main --=20 2.53.0