From nobody Sun Sep 27 21:12:12 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=galbraiths.ca ARC-Seal: i=1; a=rsa-sha256; t=1790393075; cv=none; d=zohomail.com; s=zohoarc; b=Ffjv/X9ep+7Pn1S5CF3swMFluqqw487hzZu5DqaUEAFc0BHqXj535VFoy5kCM9oGulfJYCZDbBOBEf8Yo4d5m41hDav05wrq8L9jgwGp+F9QqjprI4H79TJSm6WzOiy6mivQQSTivI4X9jqueSx6OxGRNZ8i2LnmkfwiknqyTRs= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1790393075; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=8S3opI7vrdEG/nPSyIv/cACVp2yZhGAylytqy0JQ/xA=; b=RaHbWK4I5lF5MYO9o7QxPQ5UAq2ILimn19rw4Y7S/GDXvrnpcKwThl3oBDtxSV8Bo6yLoRI0subaFL69nrK47GE/w8vFRRgwmskssWWZrwOUUGIeoUPAhAh0sA8My7M7Ws08MDFr+2quaUz2M34n3p/SNwQdRbIYLFnmTNI2Li8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1790393075238569.8533362354514; Fri, 25 Sep 2026 20:24:35 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1xAJ13-00081o-2d; Fri, 25 Sep 2026 23:23:57 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1xAJ12-00081f-0B for qemu-devel@nongnu.org; Fri, 25 Sep 2026 23:23:56 -0400 Received: from fout-b6-smtp.messagingengine.com ([202.12.124.149]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1xAJ10-00009v-9m for qemu-devel@nongnu.org; Fri, 25 Sep 2026 23:23:55 -0400 Received: from phl-compute-02.internal (phl-compute-02.internal [10.202.2.42]) by mailfout.stl.internal (Postfix) with ESMTP id 42C811D0006B; Fri, 25 Sep 2026 23:23:53 -0400 (EDT) Received: from phl-frontend-03 ([10.202.2.162]) by phl-compute-02.internal (MEProxy); Fri, 25 Sep 2026 23:23:53 -0400 Received: by mail.messagingengine.com (Postfix) with ESMTPA; Fri, 25 Sep 2026 23:23:52 -0400 (EDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=galbraiths.ca; h=cc:cc:content-transfer-encoding:content-type:date:date:from :from:in-reply-to:in-reply-to:message-id:mime-version:references :reply-to:subject:subject:to:to; s=fm2; t=1790393033; x= 1790479433; bh=8S3opI7vrdEG/nPSyIv/cACVp2yZhGAylytqy0JQ/xA=; b=r Jah5Rd4WLCweMc1oFWsDpkvepfq6KN12vvBc+gLOcT6GP75GJsvu2tpfISjkPmhP T321ypYLIca5GMO3Okquw1h9Mo033htu+GTqky0Lro7o/oWx3mivXSiyHrWvfzvI 3a1xQX2elU6w4SxcGj+5cdX3odkmBEGw8MnHLHTJsucYWZ6cM1a6Bh5swwFGmNt7 jpyUIlxQs/F7ZgKIMe6DsfXgdJvt/XcvNYzPqx2rHAvqONv4gUtSCDK8CfNTjpvU +SW7aNqQ53xaG0pBL8KXfWWRkmRXW6IZR8WUlT6XhVNrUN60CA0KNPIrxd0IDQVL oISofGsEr/v4AJyyIngjQ== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-transfer-encoding :content-type:date:date:feedback-id:feedback-id:from:from :in-reply-to:in-reply-to:message-id:mime-version:references :reply-to:subject:subject:to:to:x-me-proxy:x-me-sender :x-me-sender:x-sasl-enc; s=fm1; t=1790393033; x=1790479433; bh=8 S3opI7vrdEG/nPSyIv/cACVp2yZhGAylytqy0JQ/xA=; b=VQXPkHgsj9zl0ZwqU 9ozDDqf+V0gm5wBr5m6huR5sJ+cB+pq4aP3tk0B5RTVM7LGZmjHPFACSJkVqi3wi OqWTBdTaH4p26O0JY4wxtzrbTSZXIZGrhTujEl5Vr8VwZuigQvNzHCLAG2c9FhNu myEi8CKTvCMKeUeuqWYN9/L/dxcdFkKvk01oIsG2XpsD72pX6shwbJ5SJ6XENmBO oJ+b00z39c95HZMADChBm8MghfFgJGMCfp8FSkhTSGsoPBuwqLFWyvylU/81CQrN YeNKudjzglwELoHlT41hZj6NNnkznSxNzOieKOHkG0uxc3fAec1BXO1hF6jTF9u2 T2UPQ== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: dmFkZTEdcYkaQJ+iTkEjT16KNjbMj/htJ3DV+pGdLzXjvnJy9fGhY1qphRJciGsxrBuXCC bb+cl4WKhrxJp8Goxc19okexAaTOj4CDMqZqizpnJ0ubVqM8KNY/hSvvh1buLqPKyS2fpO +LjHGB7+2cYSSXelwG+xd050NaAPXU4lAn3pJGFgEn85LfB2nBXv1OLLK/jhVRexc6VGR9 RNwZh+5ooCWfAd1jt972K7Ebiic6+xTZOa5lym4OBU+x+5MCW5y/GqxHwD35zOus83Hw59 oIEJ7zVVqvXpCNoGr0bd/cPstn1MUEBzPppeoLL6RQB9HvvtfDg8QRP/Pd3RgSonjFRZOK RYfCDwcJAZz6dgveZTkP5V18K4aNw9Qq5c9gOh/IQTqF/8Ln0FwNm9o7e+oLEDKBiTM93A 3EEpGzW7CNKBXGuK182Ja6Xp5Sa+iH6XUfX02WbIumG+s/msx2ke99QJdJhPEZf/lpIzQ4 cDTEqdxIL2LQ/cYAlp43aEBeSSeJWMg7fGQdR1jb5aYpcvZj85sqGQeUWhAwIV8aOGk0W9 JyY20GSMvIMxzFLMrEU7s52mJKsSY3TuieeGghOgm6qAI7tFuBx5fsH8RSPv7xOv174rY3 rnHSuGWihx+TEyO9Xj4+VvZbEm/dnoE+0HMZYT9wlVTSIPOfHqd9+AcbUt5Q X-ME-Proxy: Feedback-ID: i00314697:Fastmail From: Paul Galbraith To: qemu-devel@nongnu.org Cc: pbonzini@redhat.com, richard.henderson@linaro.org, Paul Galbraith Subject: [PATCH v3 1/2] target/i386/tcg: fix EIP truncation for wrapping 16-bit near branches Date: Fri, 25 Sep 2026 23:23:35 -0400 Message-ID: <20260926032336.933-2-paul@galbraiths.ca> X-Mailer: git-send-email 2.55.0.windows.3 In-Reply-To: <20260926032336.933-1-paul@galbraiths.ca> References: <20260926032336.933-1-paul@galbraiths.ca> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=202.12.124.149; envelope-from=paul@galbraiths.ca; helo=fout-b6-smtp.messagingengine.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @galbraiths.ca) X-ZM-MESSAGEID: 1790393078366158500 Content-Type: text/plain; charset="utf-8" A 16-bit near branch that wraps through 0xFFFF must truncate EIP. TCG skipped this when the target was on the same page, which can happen when the CS base is not page aligned. Signed-off-by: Paul Galbraith --- target/i386/tcg/translate.c | 20 ++++++++++++++++---- 1 file changed, 16 insertions(+), 4 deletions(-) diff --git a/target/i386/tcg/translate.c b/target/i386/tcg/translate.c index d8de290acb..6d3c929eee 100644 --- a/target/i386/tcg/translate.c +++ b/target/i386/tcg/translate.c @@ -2025,12 +2025,24 @@ static void gen_jmp_rel(DisasContext *s, MemOp ot, = int diff, int tb_num) =20 if (tb_cflags(s->base.tb) & CF_PCREL) { tcg_gen_addi_tl(cpu_eip, cpu_eip, new_pc - s->pc_save); + + /* + * True if a wrap cannot be ruled out: the source and destination = EIP + * are in different EIP pages. If they share one, the addition ca= nnot + * leave [0, mask] on any rerun of this TB, which only ever shifts= EIP + * by whole pages. + */ + bool eip_may_wrap =3D !CODE64(s) && + (((s->pc_save - s->cs_base) ^ (new_pc - s->cs_base)) + & TARGET_PAGE_MASK) !=3D 0; + /* - * If we can prove the branch does not leave the page and we have - * no extra masking to apply (data16 branch in code32, see above), - * then we have also proven that the addition does not wrap. + * If we can prove the branch does not leave the page, does not le= ave + * its EIP page, and we have no extra masking to apply (data16 bra= nch + * in code32, see above), then the addition does not wrap. */ - if (!use_goto_tb || !translator_is_same_page(&s->base, new_pc)) { + if (!use_goto_tb || !translator_is_same_page(&s->base, new_pc) + || eip_may_wrap) { tcg_gen_andi_tl(cpu_eip, cpu_eip, mask); use_goto_tb =3D false; } --=20 2.55.0.windows.3 From nobody Sun Sep 27 21:12:12 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=galbraiths.ca ARC-Seal: i=1; a=rsa-sha256; t=1790393073; cv=none; d=zohomail.com; s=zohoarc; b=C+930NLX0EKucJIPV25kdlxiGqC1MiwH//WVnn5KFonCClhlpb1Rvyb9unrgR0DoYhrfO3juaBmTZ6gFY01inG0u96M6tcweb0gPMFZZQtrEAoxoFZN0+Cel2TWdLZDviv5uNLps6nK4sK88s43E3RKc4GVRIy7PB2TlFnkMJhM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1790393073; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=UiROjTviiSwdRAUeTrROxyenRNPGultVEh2ZzybIzPs=; b=grXAD1gAE/enhacImG9tdVXW4wN/JPT+ie7VKLykK3h7LksNXZc8p5s0JlajF+ySHA9x2ieYPhMPHv0Ftey2+eR3EHYp6WZOyxGD6YvIJEOeqEVVlb3DkSyP/WxTmcAJresRqCRglvLNLNtg8UejA0KlHpe1x/NgkHGBn2tzdv0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1790393072298322.3551088601869; Fri, 25 Sep 2026 20:24:32 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1xAJ1E-00082t-28; Fri, 25 Sep 2026 23:24:08 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1xAJ1C-00082W-8v for qemu-devel@nongnu.org; Fri, 25 Sep 2026 23:24:06 -0400 Received: from fout-b6-smtp.messagingengine.com ([202.12.124.149]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1xAJ1A-0000AN-G7 for qemu-devel@nongnu.org; Fri, 25 Sep 2026 23:24:06 -0400 Received: from phl-compute-06.internal (phl-compute-06.internal [10.202.2.46]) by mailfout.stl.internal (Postfix) with ESMTP id 8CDEE1D00071; Fri, 25 Sep 2026 23:24:03 -0400 (EDT) Received: from phl-frontend-03 ([10.202.2.162]) by phl-compute-06.internal (MEProxy); Fri, 25 Sep 2026 23:24:03 -0400 Received: by mail.messagingengine.com (Postfix) with ESMTPA; Fri, 25 Sep 2026 23:24:02 -0400 (EDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=galbraiths.ca; h=cc:cc:content-transfer-encoding:content-type:date:date:from :from:in-reply-to:in-reply-to:message-id:mime-version:references :reply-to:subject:subject:to:to; s=fm2; t=1790393043; x= 1790479443; bh=UiROjTviiSwdRAUeTrROxyenRNPGultVEh2ZzybIzPs=; b=S zJma5QlN1sStYOEHcBIgMl7Wrqb4ixy7GZib2zBP1k4tqloZzhBqUJ+z2v5heq+I DD9XodSvnnjAp7lYOU4at/DNG/jg3SYH/IL/YIMZfioXO8iFMRbpLXh4VmjLzGAv sVE0AsHhu7ZIev9P1yTebfESdSIP1TmopGfhVYGetDjguOmtN65zzZhqDoLysXBr owMM22YjTbyiyGocP6TrhYWZnYih1U9jNQS/SXLiibBuTYITNcn78WMvZ2cD/pQo /LmhOgqQmxLyKXhjhJ1RV2KKtjGqQp0Sbdg36+TgufWEx2tRWW//uuTLMDmONody Egl0AajYBstcylR0k4dpQ== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-transfer-encoding :content-type:date:date:feedback-id:feedback-id:from:from :in-reply-to:in-reply-to:message-id:mime-version:references :reply-to:subject:subject:to:to:x-me-proxy:x-me-sender :x-me-sender:x-sasl-enc; s=fm1; t=1790393043; x=1790479443; bh=U iROjTviiSwdRAUeTrROxyenRNPGultVEh2ZzybIzPs=; b=P+olfjwG5RxOG4nUq rxa2vMXr0Po1PU4AoLUZXcdcLMMdhkVtIf2z0VZ29PKyeyxD7J9nHK/k2M71D/Nr hzHpyLIIJvFg74q2z9fS83oQ2Q4ygpYbpDlGN+PqMfekr9aGlUSTN4F/p1HudGYG cpm0rNtLbm5ERbSeCBK+4Lf+yVPo4rwskd1yTznJ6vrm4CTFanWs3jpQIt/ZJVH0 5/K6pvGERVsJlH2slICH6RtYkoEi0S//GizZKaVAnA94wzJLv4uBHtGFS4UH3ZmK ftr3GaQaOc9t5O0YpCyvG4awQBNp/z/4SOemyKT2BQ/KGr1OXKMQ34teHEd0iXOb CrKuA== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: dmFkZTEgfWq44un7oqbbc2cSBXVU9dUWrYd6s7OzGzXYSaviivPuhgIsDL6v/GSXMMoPj0 506Z7ollbyjn15YT0z4R+mLfmdARf21h5/3FOiSHbXu3uMS7KRTgun9Xl7yq01PdX4Aoml NIuSIJF0CpvA6B/Znp3hvZ1uDkNhz3WOn54yjNig/Oxj5duuxPaYcfk+kAvStGrQJ3L1jS Ra6wUB9RqvNdqESUZ8O1ZPstDYOeXtwH/dHhn9qvIBTncyq3ETqEgkwOpk8VQl0YX0+vjL crw5ppkmSAFpsHyYe95iFJSz0KIMfhWNUfLVAKO5h4yPhcbFOl+B0kvn5ryXzDB5Ru+zQq KKK05MmjxuXaZqK8A+LeflQ7/02ZWJl96yAv8yJNbz4CL6gU1d34dozAv4vE58QbRTppKd +967EMXmojo4gZr/9ilkmyeIMr6WLcQ2/kRzvTdiCLybZI4GIwg/zT+WFCace7RmoarcKI ciN92yvhyiG1VczRcNuTss87zNnXPCXvFeOkEoZIY58Kmnw0mNQOj2NZCm6qiW2XGNNanZ Ujq9dQl3cjyS2X1mUqKmYoM0GqSOD48qG7S4lX+wjwOrTV2HPVOYxIdrRYpWBE3OQ0jk4I v2ti8PlL79uTJXZDwql6U5/G+hh4F8wlVmIShrkWiDeS7uoIq7WZV0LgNxeQ X-ME-Proxy: Feedback-ID: i00314697:Fastmail From: Paul Galbraith To: qemu-devel@nongnu.org Cc: pbonzini@redhat.com, richard.henderson@linaro.org, Paul Galbraith Subject: [PATCH v3 2/2] tests/tcg/i386: add regression test for wrapping 16-bit near branches Date: Fri, 25 Sep 2026 23:23:36 -0400 Message-ID: <20260926032336.933-3-paul@galbraiths.ca> X-Mailer: git-send-email 2.55.0.windows.3 In-Reply-To: <20260926032336.933-1-paul@galbraiths.ca> References: <20260926032336.933-1-paul@galbraiths.ca> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=202.12.124.149; envelope-from=paul@galbraiths.ca; helo=fout-b6-smtp.messagingengine.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @galbraiths.ca) X-ZM-MESSAGEID: 1790393074385158500 Content-Type: text/plain; charset="utf-8" Jump from IP 0xFFF0 to IP 0x0020 with a CS base that is not page aligned, and check that EIP wraps. Signed-off-by: Paul Galbraith --- tests/tcg/i386/system/meson.build | 7 ++ tests/tcg/i386/system/test-branch-wrap16.S | 118 +++++++++++++++++++++ 2 files changed, 125 insertions(+) create mode 100644 tests/tcg/i386/system/test-branch-wrap16.S diff --git a/tests/tcg/i386/system/meson.build b/tests/tcg/i386/system/meso= n.build index d3f73997c7..d831f7e9c1 100644 --- a/tests/tcg/i386/system/meson.build +++ b/tests/tcg/i386/system/meson.build @@ -34,6 +34,13 @@ foreach t: tcg_tests['multiarch-softmmu']['tests'] endforeach endforeach =20 +tests +=3D { + 'test-branch-wrap16.S': { + 'cflags': cflags, + 'qemu_args': qemu_def_args, + } +} + if 'qemu-system-i386' in emulators tcg_tests +=3D { 'i386-softmmu': { diff --git a/tests/tcg/i386/system/test-branch-wrap16.S b/tests/tcg/i386/sy= stem/test-branch-wrap16.S new file mode 100644 index 0000000000..2520891ba7 --- /dev/null +++ b/tests/tcg/i386/system/test-branch-wrap16.S @@ -0,0 +1,118 @@ +/* + * SPDX-License-Identifier: GPL-2.0-or-later + * + * A 16-bit near branch must truncate EIP to 16 bits. + * + * The test jumps from IP 0xFFF0 to IP 0x0020 in 16-bit code. The jump + * crosses 0xFFFF. For correct 16-bit behaviour the CPU should wrap the + * target to 0x0020, rather than branching to 0x10020. + * + * TCG used to skip the wrap when the untruncated target (CS base + + * 0x10020) was on the same guest page as the jump. That only happens + * when the CS base is not page aligned, so the code segment starts at + * a page boundary plus 0x10. + */ + +#define SEL_CODE32 0x08 +#define SEL_CODE16 0x18 + +#define RESULT_NONE 0 +#define RESULT_PASS 1 +#define RESULT_FAIL 2 + +/* + * 16-bit relative 'jmp target', hand-assembled because clang rejects a + * rel16 displacement outside [-0x8000, 0x7FFF]. But, in 16-bit code, any + * 16-bit displacement is valid. GAS correctly accepts any 16-bit offset. + */ +.macro jmp_rel16 target + .byte 0xE9 /* jmp rel16 opcode */ + .word ((\target) - (. + 2)) & 0xFFFF /* cw: 16-bit offset */ +.endm + + .data + +g_result: + .long RESULT_NONE + +/* 0x08 and 0x10 must match boot.S, which loaded the data selectors */ +gdt16: + .quad 0 + .word 0xFFFF, 0 + .byte 0, 0x9b, 0xCF, 0 + .word 0xFFFF, 0 + .byte 0, 0x93, 0xCF, 0 +gdt16_code16: + /* 16-bit code, 64 KiB limit; main fills in the base */ + .word 0xFFFF, 0 + .byte 0, 0x9b, 0x00, 0 +gdt16_end: + +gdtr16: + .word gdt16_end - gdt16 - 1 + .long gdt16 + +fail_msg: + .asciz "FAIL: branch left EIP untruncated (result=3D%d)\n" +pass_msg: + .asciz "PASS\n" + + /* + * Page aligned plus 0x10. A larger alignment breaks the + * multiboot load in boot.S. + */ + .balign 0x1000 + .skip 0x10 +wrap16_cs_base: + .code16 + + /* jmp lands here when EIP wraps to 0x0020 */ + .org wrap16_cs_base + 0x0020 +wrap16_target: + movl $g_result, %eax + movb $RESULT_PASS, (%eax) + ljmpl $SEL_CODE32, $wrap16_back + + .org wrap16_cs_base + 0xFFF0 + /* the problematic branch, which should wrap EIP */ + jmp_rel16 wrap16_target + + /* jmp lands here when EIP does not wrap (0x10020) */ + .org wrap16_cs_base + 0x10020 + movl $g_result, %eax + movb $RESULT_FAIL, (%eax) + ljmpl $SEL_CODE32, $wrap16_back + + .code32 + + .text + +wrap16_run: + ljmp $SEL_CODE16, $0xFFF0 +wrap16_back: + ret + + .globl main +main: + movl $wrap16_cs_base, %eax + movw %ax, gdt16_code16 + 2 + shrl $16, %eax + movb %al, gdt16_code16 + 4 + movb %ah, gdt16_code16 + 7 + lgdt gdtr16 + + call wrap16_run + cmpl $RESULT_PASS, g_result + jne test_failed + pushl $pass_msg /* test passed */ + call ml_printf + addl $4, %esp + xorl %eax, %eax + ret +test_failed: + pushl g_result + pushl $fail_msg + call ml_printf + addl $8, %esp + movl $1, %eax + ret --=20 2.55.0.windows.3