Merge commit 'a4673e276248ada38f40d39191a197e7e35d3f8b' into upstream-merge
[qemu-kvm/amd-iommu.git] / cpu-exec.c
blob240bc287d5ef0951822605adcac7105b5a8965dd
1 /*
2 * i386 emulator main execution loop
4 * Copyright (c) 2003-2005 Fabrice Bellard
6 * This library is free software; you can redistribute it and/or
7 * modify it under the terms of the GNU Lesser General Public
8 * License as published by the Free Software Foundation; either
9 * version 2 of the License, or (at your option) any later version.
11 * This library is distributed in the hope that it will be useful,
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
14 * Lesser General Public License for more details.
16 * You should have received a copy of the GNU Lesser General Public
17 * License along with this library; if not, see <http://www.gnu.org/licenses/>.
19 #include "config.h"
20 #include "exec.h"
21 #include "disas.h"
22 #if !defined(TARGET_IA64)
23 #include "tcg.h"
24 #endif
25 #include "kvm.h"
27 #if !defined(CONFIG_SOFTMMU)
28 #undef EAX
29 #undef ECX
30 #undef EDX
31 #undef EBX
32 #undef ESP
33 #undef EBP
34 #undef ESI
35 #undef EDI
36 #undef EIP
37 #include <signal.h>
38 #ifdef __linux__
39 #include <sys/ucontext.h>
40 #endif
41 #endif
43 #include "qemu-kvm.h"
45 #if defined(__sparc__) && !defined(CONFIG_SOLARIS)
46 // Work around ugly bugs in glibc that mangle global register contents
47 #undef env
48 #define env cpu_single_env
49 #endif
51 int tb_invalidated_flag;
53 //#define CONFIG_DEBUG_EXEC
54 //#define DEBUG_SIGNAL
56 int qemu_cpu_has_work(CPUState *env)
58 return cpu_has_work(env);
61 void cpu_loop_exit(void)
63 env->current_tb = NULL;
64 longjmp(env->jmp_env, 1);
67 /* exit the current TB from a signal handler. The host registers are
68 restored in a state compatible with the CPU emulator
70 void cpu_resume_from_signal(CPUState *env1, void *puc)
72 #if !defined(CONFIG_SOFTMMU)
73 #ifdef __linux__
74 struct ucontext *uc = puc;
75 #elif defined(__OpenBSD__)
76 struct sigcontext *uc = puc;
77 #endif
78 #endif
80 env = env1;
82 /* XXX: restore cpu registers saved in host registers */
84 #if !defined(CONFIG_SOFTMMU)
85 if (puc) {
86 /* XXX: use siglongjmp ? */
87 #ifdef __linux__
88 #ifdef __ia64
89 sigprocmask(SIG_SETMASK, (sigset_t *)&uc->uc_sigmask, NULL);
90 #else
91 sigprocmask(SIG_SETMASK, &uc->uc_sigmask, NULL);
92 #endif
93 #elif defined(__OpenBSD__)
94 sigprocmask(SIG_SETMASK, &uc->sc_mask, NULL);
95 #endif
97 #endif
98 env->exception_index = -1;
99 longjmp(env->jmp_env, 1);
102 /* Execute the code without caching the generated code. An interpreter
103 could be used if available. */
104 static void cpu_exec_nocache(int max_cycles, TranslationBlock *orig_tb)
106 unsigned long next_tb;
107 TranslationBlock *tb;
109 /* Should never happen.
110 We only end up here when an existing TB is too long. */
111 if (max_cycles > CF_COUNT_MASK)
112 max_cycles = CF_COUNT_MASK;
114 tb = tb_gen_code(env, orig_tb->pc, orig_tb->cs_base, orig_tb->flags,
115 max_cycles);
116 env->current_tb = tb;
117 /* execute the generated code */
118 next_tb = tcg_qemu_tb_exec(tb->tc_ptr);
119 env->current_tb = NULL;
121 if ((next_tb & 3) == 2) {
122 /* Restore PC. This may happen if async event occurs before
123 the TB starts executing. */
124 cpu_pc_from_tb(env, tb);
126 tb_phys_invalidate(tb, -1);
127 tb_free(tb);
130 static TranslationBlock *tb_find_slow(target_ulong pc,
131 target_ulong cs_base,
132 uint64_t flags)
134 TranslationBlock *tb, **ptb1;
135 unsigned int h;
136 tb_page_addr_t phys_pc, phys_page1, phys_page2;
137 target_ulong virt_page2;
139 tb_invalidated_flag = 0;
141 /* find translated block using physical mappings */
142 phys_pc = get_page_addr_code(env, pc);
143 phys_page1 = phys_pc & TARGET_PAGE_MASK;
144 phys_page2 = -1;
145 h = tb_phys_hash_func(phys_pc);
146 ptb1 = &tb_phys_hash[h];
147 for(;;) {
148 tb = *ptb1;
149 if (!tb)
150 goto not_found;
151 if (tb->pc == pc &&
152 tb->page_addr[0] == phys_page1 &&
153 tb->cs_base == cs_base &&
154 tb->flags == flags) {
155 /* check next page if needed */
156 if (tb->page_addr[1] != -1) {
157 virt_page2 = (pc & TARGET_PAGE_MASK) +
158 TARGET_PAGE_SIZE;
159 phys_page2 = get_page_addr_code(env, virt_page2);
160 if (tb->page_addr[1] == phys_page2)
161 goto found;
162 } else {
163 goto found;
166 ptb1 = &tb->phys_hash_next;
168 not_found:
169 /* if no translated code available, then translate it now */
170 tb = tb_gen_code(env, pc, cs_base, flags, 0);
172 found:
173 /* we add the TB in the virtual pc hash table */
174 env->tb_jmp_cache[tb_jmp_cache_hash_func(pc)] = tb;
175 return tb;
178 static inline TranslationBlock *tb_find_fast(void)
180 TranslationBlock *tb;
181 target_ulong cs_base, pc;
182 int flags;
184 /* we record a subset of the CPU state. It will
185 always be the same before a given translated block
186 is executed. */
187 cpu_get_tb_cpu_state(env, &pc, &cs_base, &flags);
188 tb = env->tb_jmp_cache[tb_jmp_cache_hash_func(pc)];
189 if (unlikely(!tb || tb->pc != pc || tb->cs_base != cs_base ||
190 tb->flags != flags)) {
191 tb = tb_find_slow(pc, cs_base, flags);
193 return tb;
196 static CPUDebugExcpHandler *debug_excp_handler;
198 CPUDebugExcpHandler *cpu_set_debug_excp_handler(CPUDebugExcpHandler *handler)
200 CPUDebugExcpHandler *old_handler = debug_excp_handler;
202 debug_excp_handler = handler;
203 return old_handler;
206 static void cpu_handle_debug_exception(CPUState *env)
208 CPUWatchpoint *wp;
210 if (!env->watchpoint_hit)
211 QTAILQ_FOREACH(wp, &env->watchpoints, entry)
212 wp->flags &= ~BP_WATCHPOINT_HIT;
214 if (debug_excp_handler)
215 debug_excp_handler(env);
218 /* main execution loop */
220 volatile sig_atomic_t exit_request;
222 int cpu_exec(CPUState *env1)
224 volatile host_reg_t saved_env_reg;
225 int ret, interrupt_request;
226 TranslationBlock *tb;
227 uint8_t *tc_ptr;
228 unsigned long next_tb;
230 if (cpu_halted(env1) == EXCP_HALTED)
231 return EXCP_HALTED;
233 cpu_single_env = env1;
235 /* the access to env below is actually saving the global register's
236 value, so that files not including target-xyz/exec.h are free to
237 use it. */
238 QEMU_BUILD_BUG_ON (sizeof (saved_env_reg) != sizeof (env));
239 saved_env_reg = (host_reg_t) env;
240 asm("");
241 env = env1;
243 if (exit_request) {
244 env->exit_request = 1;
245 exit_request = 0;
248 #if defined(TARGET_I386)
249 if (!kvm_enabled()) {
250 /* put eflags in CPU temporary format */
251 CC_SRC = env->eflags & (CC_O | CC_S | CC_Z | CC_A | CC_P | CC_C);
252 DF = 1 - (2 * ((env->eflags >> 10) & 1));
253 CC_OP = CC_OP_EFLAGS;
254 env->eflags &= ~(DF_MASK | CC_O | CC_S | CC_Z | CC_A | CC_P | CC_C);
256 #elif defined(TARGET_SPARC)
257 #elif defined(TARGET_M68K)
258 env->cc_op = CC_OP_FLAGS;
259 env->cc_dest = env->sr & 0xf;
260 env->cc_x = (env->sr >> 4) & 1;
261 #elif defined(TARGET_ALPHA)
262 #elif defined(TARGET_ARM)
263 #elif defined(TARGET_PPC)
264 #elif defined(TARGET_MICROBLAZE)
265 #elif defined(TARGET_MIPS)
266 #elif defined(TARGET_SH4)
267 #elif defined(TARGET_CRIS)
268 #elif defined(TARGET_S390X)
269 #elif defined(TARGET_IA64)
270 /* XXXXX */
271 #else
272 #error unsupported target CPU
273 #endif
274 env->exception_index = -1;
276 /* prepare setjmp context for exception handling */
277 for(;;) {
278 if (setjmp(env->jmp_env) == 0) {
279 #if defined(__sparc__) && !defined(CONFIG_SOLARIS)
280 #undef env
281 env = cpu_single_env;
282 #define env cpu_single_env
283 #endif
284 /* if an exception is pending, we execute it here */
285 if (env->exception_index >= 0) {
286 if (env->exception_index >= EXCP_INTERRUPT) {
287 /* exit request from the cpu execution loop */
288 ret = env->exception_index;
289 if (ret == EXCP_DEBUG)
290 cpu_handle_debug_exception(env);
291 break;
292 } else {
293 #if defined(CONFIG_USER_ONLY)
294 /* if user mode only, we simulate a fake exception
295 which will be handled outside the cpu execution
296 loop */
297 #if defined(TARGET_I386)
298 do_interrupt_user(env->exception_index,
299 env->exception_is_int,
300 env->error_code,
301 env->exception_next_eip);
302 /* successfully delivered */
303 env->old_exception = -1;
304 #endif
305 ret = env->exception_index;
306 break;
307 #else
308 #if defined(TARGET_I386)
309 /* simulate a real cpu exception. On i386, it can
310 trigger new exceptions, but we do not handle
311 double or triple faults yet. */
312 do_interrupt(env->exception_index,
313 env->exception_is_int,
314 env->error_code,
315 env->exception_next_eip, 0);
316 /* successfully delivered */
317 env->old_exception = -1;
318 #elif defined(TARGET_PPC)
319 do_interrupt(env);
320 #elif defined(TARGET_MICROBLAZE)
321 do_interrupt(env);
322 #elif defined(TARGET_MIPS)
323 do_interrupt(env);
324 #elif defined(TARGET_SPARC)
325 do_interrupt(env);
326 #elif defined(TARGET_ARM)
327 do_interrupt(env);
328 #elif defined(TARGET_SH4)
329 do_interrupt(env);
330 #elif defined(TARGET_ALPHA)
331 do_interrupt(env);
332 #elif defined(TARGET_CRIS)
333 do_interrupt(env);
334 #elif defined(TARGET_M68K)
335 do_interrupt(0);
336 #elif defined(TARGET_IA64)
337 do_interrupt(env);
338 #endif
339 env->exception_index = -1;
340 #endif
344 if (kvm_enabled()) {
345 kvm_cpu_exec(env);
346 longjmp(env->jmp_env, 1);
349 next_tb = 0; /* force lookup of first TB */
350 for(;;) {
351 interrupt_request = env->interrupt_request;
352 if (unlikely(interrupt_request)) {
353 if (unlikely(env->singlestep_enabled & SSTEP_NOIRQ)) {
354 /* Mask out external interrupts for this step. */
355 interrupt_request &= ~(CPU_INTERRUPT_HARD |
356 CPU_INTERRUPT_FIQ |
357 CPU_INTERRUPT_SMI |
358 CPU_INTERRUPT_NMI);
360 if (interrupt_request & CPU_INTERRUPT_DEBUG) {
361 env->interrupt_request &= ~CPU_INTERRUPT_DEBUG;
362 env->exception_index = EXCP_DEBUG;
363 cpu_loop_exit();
365 #if defined(TARGET_ARM) || defined(TARGET_SPARC) || defined(TARGET_MIPS) || \
366 defined(TARGET_PPC) || defined(TARGET_ALPHA) || defined(TARGET_CRIS) || \
367 defined(TARGET_MICROBLAZE)
368 if (interrupt_request & CPU_INTERRUPT_HALT) {
369 env->interrupt_request &= ~CPU_INTERRUPT_HALT;
370 env->halted = 1;
371 env->exception_index = EXCP_HLT;
372 cpu_loop_exit();
374 #endif
375 #if defined(TARGET_I386)
376 if (interrupt_request & CPU_INTERRUPT_INIT) {
377 svm_check_intercept(SVM_EXIT_INIT);
378 do_cpu_init(env);
379 env->exception_index = EXCP_HALTED;
380 cpu_loop_exit();
381 } else if (interrupt_request & CPU_INTERRUPT_SIPI) {
382 do_cpu_sipi(env);
383 } else if (env->hflags2 & HF2_GIF_MASK) {
384 if ((interrupt_request & CPU_INTERRUPT_SMI) &&
385 !(env->hflags & HF_SMM_MASK)) {
386 svm_check_intercept(SVM_EXIT_SMI);
387 env->interrupt_request &= ~CPU_INTERRUPT_SMI;
388 do_smm_enter();
389 next_tb = 0;
390 } else if ((interrupt_request & CPU_INTERRUPT_NMI) &&
391 !(env->hflags2 & HF2_NMI_MASK)) {
392 env->interrupt_request &= ~CPU_INTERRUPT_NMI;
393 env->hflags2 |= HF2_NMI_MASK;
394 do_interrupt(EXCP02_NMI, 0, 0, 0, 1);
395 next_tb = 0;
396 } else if (interrupt_request & CPU_INTERRUPT_MCE) {
397 env->interrupt_request &= ~CPU_INTERRUPT_MCE;
398 do_interrupt(EXCP12_MCHK, 0, 0, 0, 0);
399 next_tb = 0;
400 } else if ((interrupt_request & CPU_INTERRUPT_HARD) &&
401 (((env->hflags2 & HF2_VINTR_MASK) &&
402 (env->hflags2 & HF2_HIF_MASK)) ||
403 (!(env->hflags2 & HF2_VINTR_MASK) &&
404 (env->eflags & IF_MASK &&
405 !(env->hflags & HF_INHIBIT_IRQ_MASK))))) {
406 int intno;
407 svm_check_intercept(SVM_EXIT_INTR);
408 env->interrupt_request &= ~(CPU_INTERRUPT_HARD | CPU_INTERRUPT_VIRQ);
409 intno = cpu_get_pic_interrupt(env);
410 qemu_log_mask(CPU_LOG_TB_IN_ASM, "Servicing hardware INT=0x%02x\n", intno);
411 #if defined(__sparc__) && !defined(CONFIG_SOLARIS)
412 #undef env
413 env = cpu_single_env;
414 #define env cpu_single_env
415 #endif
416 do_interrupt(intno, 0, 0, 0, 1);
417 /* ensure that no TB jump will be modified as
418 the program flow was changed */
419 next_tb = 0;
420 #if !defined(CONFIG_USER_ONLY)
421 } else if ((interrupt_request & CPU_INTERRUPT_VIRQ) &&
422 (env->eflags & IF_MASK) &&
423 !(env->hflags & HF_INHIBIT_IRQ_MASK)) {
424 int intno;
425 /* FIXME: this should respect TPR */
426 svm_check_intercept(SVM_EXIT_VINTR);
427 intno = ldl_phys(env->vm_vmcb + offsetof(struct vmcb, control.int_vector));
428 qemu_log_mask(CPU_LOG_TB_IN_ASM, "Servicing virtual hardware INT=0x%02x\n", intno);
429 do_interrupt(intno, 0, 0, 0, 1);
430 env->interrupt_request &= ~CPU_INTERRUPT_VIRQ;
431 next_tb = 0;
432 #endif
435 #elif defined(TARGET_PPC)
436 #if 0
437 if ((interrupt_request & CPU_INTERRUPT_RESET)) {
438 cpu_reset(env);
440 #endif
441 if (interrupt_request & CPU_INTERRUPT_HARD) {
442 ppc_hw_interrupt(env);
443 if (env->pending_interrupts == 0)
444 env->interrupt_request &= ~CPU_INTERRUPT_HARD;
445 next_tb = 0;
447 #elif defined(TARGET_MICROBLAZE)
448 if ((interrupt_request & CPU_INTERRUPT_HARD)
449 && (env->sregs[SR_MSR] & MSR_IE)
450 && !(env->sregs[SR_MSR] & (MSR_EIP | MSR_BIP))
451 && !(env->iflags & (D_FLAG | IMM_FLAG))) {
452 env->exception_index = EXCP_IRQ;
453 do_interrupt(env);
454 next_tb = 0;
456 #elif defined(TARGET_MIPS)
457 if ((interrupt_request & CPU_INTERRUPT_HARD) &&
458 (env->CP0_Status & env->CP0_Cause & CP0Ca_IP_mask) &&
459 (env->CP0_Status & (1 << CP0St_IE)) &&
460 !(env->CP0_Status & (1 << CP0St_EXL)) &&
461 !(env->CP0_Status & (1 << CP0St_ERL)) &&
462 !(env->hflags & MIPS_HFLAG_DM)) {
463 /* Raise it */
464 env->exception_index = EXCP_EXT_INTERRUPT;
465 env->error_code = 0;
466 do_interrupt(env);
467 next_tb = 0;
469 #elif defined(TARGET_SPARC)
470 if (interrupt_request & CPU_INTERRUPT_HARD) {
471 if (cpu_interrupts_enabled(env) &&
472 env->interrupt_index > 0) {
473 int pil = env->interrupt_index & 0xf;
474 int type = env->interrupt_index & 0xf0;
476 if (((type == TT_EXTINT) &&
477 cpu_pil_allowed(env, pil)) ||
478 type != TT_EXTINT) {
479 env->exception_index = env->interrupt_index;
480 do_interrupt(env);
481 next_tb = 0;
484 } else if (interrupt_request & CPU_INTERRUPT_TIMER) {
485 //do_interrupt(0, 0, 0, 0, 0);
486 env->interrupt_request &= ~CPU_INTERRUPT_TIMER;
488 #elif defined(TARGET_ARM)
489 if (interrupt_request & CPU_INTERRUPT_FIQ
490 && !(env->uncached_cpsr & CPSR_F)) {
491 env->exception_index = EXCP_FIQ;
492 do_interrupt(env);
493 next_tb = 0;
495 /* ARMv7-M interrupt return works by loading a magic value
496 into the PC. On real hardware the load causes the
497 return to occur. The qemu implementation performs the
498 jump normally, then does the exception return when the
499 CPU tries to execute code at the magic address.
500 This will cause the magic PC value to be pushed to
501 the stack if an interrupt occured at the wrong time.
502 We avoid this by disabling interrupts when
503 pc contains a magic address. */
504 if (interrupt_request & CPU_INTERRUPT_HARD
505 && ((IS_M(env) && env->regs[15] < 0xfffffff0)
506 || !(env->uncached_cpsr & CPSR_I))) {
507 env->exception_index = EXCP_IRQ;
508 do_interrupt(env);
509 next_tb = 0;
511 #elif defined(TARGET_SH4)
512 if (interrupt_request & CPU_INTERRUPT_HARD) {
513 do_interrupt(env);
514 next_tb = 0;
516 #elif defined(TARGET_ALPHA)
517 if (interrupt_request & CPU_INTERRUPT_HARD) {
518 do_interrupt(env);
519 next_tb = 0;
521 #elif defined(TARGET_CRIS)
522 if (interrupt_request & CPU_INTERRUPT_HARD
523 && (env->pregs[PR_CCS] & I_FLAG)
524 && !env->locked_irq) {
525 env->exception_index = EXCP_IRQ;
526 do_interrupt(env);
527 next_tb = 0;
529 if (interrupt_request & CPU_INTERRUPT_NMI
530 && (env->pregs[PR_CCS] & M_FLAG)) {
531 env->exception_index = EXCP_NMI;
532 do_interrupt(env);
533 next_tb = 0;
535 #elif defined(TARGET_M68K)
536 if (interrupt_request & CPU_INTERRUPT_HARD
537 && ((env->sr & SR_I) >> SR_I_SHIFT)
538 < env->pending_level) {
539 /* Real hardware gets the interrupt vector via an
540 IACK cycle at this point. Current emulated
541 hardware doesn't rely on this, so we
542 provide/save the vector when the interrupt is
543 first signalled. */
544 env->exception_index = env->pending_vector;
545 do_interrupt(1);
546 next_tb = 0;
548 #endif
549 /* Don't use the cached interupt_request value,
550 do_interrupt may have updated the EXITTB flag. */
551 if (env->interrupt_request & CPU_INTERRUPT_EXITTB) {
552 env->interrupt_request &= ~CPU_INTERRUPT_EXITTB;
553 /* ensure that no TB jump will be modified as
554 the program flow was changed */
555 next_tb = 0;
558 if (unlikely(env->exit_request)) {
559 env->exit_request = 0;
560 env->exception_index = EXCP_INTERRUPT;
561 cpu_loop_exit();
563 #if defined(DEBUG_DISAS) || defined(CONFIG_DEBUG_EXEC)
564 if (qemu_loglevel_mask(CPU_LOG_TB_CPU)) {
565 /* restore flags in standard format */
566 #if defined(TARGET_I386)
567 env->eflags = env->eflags | helper_cc_compute_all(CC_OP) | (DF & DF_MASK);
568 log_cpu_state(env, X86_DUMP_CCOP);
569 env->eflags &= ~(DF_MASK | CC_O | CC_S | CC_Z | CC_A | CC_P | CC_C);
570 #elif defined(TARGET_M68K)
571 cpu_m68k_flush_flags(env, env->cc_op);
572 env->cc_op = CC_OP_FLAGS;
573 env->sr = (env->sr & 0xffe0)
574 | env->cc_dest | (env->cc_x << 4);
575 log_cpu_state(env, 0);
576 #else
577 log_cpu_state(env, 0);
578 #endif
580 #endif /* DEBUG_DISAS || CONFIG_DEBUG_EXEC */
581 spin_lock(&tb_lock);
582 tb = tb_find_fast();
583 /* Note: we do it here to avoid a gcc bug on Mac OS X when
584 doing it in tb_find_slow */
585 if (tb_invalidated_flag) {
586 /* as some TB could have been invalidated because
587 of memory exceptions while generating the code, we
588 must recompute the hash index here */
589 next_tb = 0;
590 tb_invalidated_flag = 0;
592 #ifdef CONFIG_DEBUG_EXEC
593 qemu_log_mask(CPU_LOG_EXEC, "Trace 0x%08lx [" TARGET_FMT_lx "] %s\n",
594 (long)tb->tc_ptr, tb->pc,
595 lookup_symbol(tb->pc));
596 #endif
597 /* see if we can patch the calling TB. When the TB
598 spans two pages, we cannot safely do a direct
599 jump. */
600 if (next_tb != 0 && tb->page_addr[1] == -1) {
601 tb_add_jump((TranslationBlock *)(next_tb & ~3), next_tb & 3, tb);
603 spin_unlock(&tb_lock);
605 /* cpu_interrupt might be called while translating the
606 TB, but before it is linked into a potentially
607 infinite loop and becomes env->current_tb. Avoid
608 starting execution if there is a pending interrupt. */
609 if (!unlikely (env->exit_request)) {
610 env->current_tb = tb;
611 tc_ptr = tb->tc_ptr;
612 /* execute the generated code */
613 #if defined(__sparc__) && !defined(CONFIG_SOLARIS)
614 #undef env
615 env = cpu_single_env;
616 #define env cpu_single_env
617 #endif
618 next_tb = tcg_qemu_tb_exec(tc_ptr);
619 env->current_tb = NULL;
620 if ((next_tb & 3) == 2) {
621 /* Instruction counter expired. */
622 int insns_left;
623 tb = (TranslationBlock *)(long)(next_tb & ~3);
624 /* Restore PC. */
625 cpu_pc_from_tb(env, tb);
626 insns_left = env->icount_decr.u32;
627 if (env->icount_extra && insns_left >= 0) {
628 /* Refill decrementer and continue execution. */
629 env->icount_extra += insns_left;
630 if (env->icount_extra > 0xffff) {
631 insns_left = 0xffff;
632 } else {
633 insns_left = env->icount_extra;
635 env->icount_extra -= insns_left;
636 env->icount_decr.u16.low = insns_left;
637 } else {
638 if (insns_left > 0) {
639 /* Execute remaining instructions. */
640 cpu_exec_nocache(insns_left, tb);
642 env->exception_index = EXCP_INTERRUPT;
643 next_tb = 0;
644 cpu_loop_exit();
648 /* reset soft MMU for next block (it can currently
649 only be set by a memory fault) */
650 } /* for(;;) */
652 } /* for(;;) */
655 #if defined(TARGET_I386)
656 /* restore flags in standard format */
657 env->eflags = env->eflags | helper_cc_compute_all(CC_OP) | (DF & DF_MASK);
658 #elif defined(TARGET_ARM)
659 /* XXX: Save/restore host fpu exception state?. */
660 #elif defined(TARGET_SPARC)
661 #elif defined(TARGET_PPC)
662 #elif defined(TARGET_M68K)
663 cpu_m68k_flush_flags(env, env->cc_op);
664 env->cc_op = CC_OP_FLAGS;
665 env->sr = (env->sr & 0xffe0)
666 | env->cc_dest | (env->cc_x << 4);
667 #elif defined(TARGET_MICROBLAZE)
668 #elif defined(TARGET_MIPS)
669 #elif defined(TARGET_SH4)
670 #elif defined(TARGET_IA64)
671 #elif defined(TARGET_ALPHA)
672 #elif defined(TARGET_CRIS)
673 #elif defined(TARGET_S390X)
674 /* XXXXX */
675 #else
676 #error unsupported target CPU
677 #endif
679 /* restore global registers */
680 asm("");
681 env = (void *) saved_env_reg;
683 /* fail safe : never use cpu_single_env outside cpu_exec() */
684 cpu_single_env = NULL;
685 return ret;
688 /* must only be called from the generated code as an exception can be
689 generated */
690 void tb_invalidate_page_range(target_ulong start, target_ulong end)
692 /* XXX: cannot enable it yet because it yields to MMU exception
693 where NIP != read address on PowerPC */
694 #if 0
695 target_ulong phys_addr;
696 phys_addr = get_phys_addr_code(env, start);
697 tb_invalidate_phys_page_range(phys_addr, phys_addr + end - start, 0);
698 #endif
701 #if defined(TARGET_I386) && defined(CONFIG_USER_ONLY)
703 void cpu_x86_load_seg(CPUX86State *s, int seg_reg, int selector)
705 CPUX86State *saved_env;
707 saved_env = env;
708 env = s;
709 if (!(env->cr[0] & CR0_PE_MASK) || (env->eflags & VM_MASK)) {
710 selector &= 0xffff;
711 cpu_x86_load_seg_cache(env, seg_reg, selector,
712 (selector << 4), 0xffff, 0);
713 } else {
714 helper_load_seg(seg_reg, selector);
716 env = saved_env;
719 void cpu_x86_fsave(CPUX86State *s, target_ulong ptr, int data32)
721 CPUX86State *saved_env;
723 saved_env = env;
724 env = s;
726 helper_fsave(ptr, data32);
728 env = saved_env;
731 void cpu_x86_frstor(CPUX86State *s, target_ulong ptr, int data32)
733 CPUX86State *saved_env;
735 saved_env = env;
736 env = s;
738 helper_frstor(ptr, data32);
740 env = saved_env;
743 #endif /* TARGET_I386 */
745 #if !defined(CONFIG_SOFTMMU)
747 #if defined(TARGET_I386)
748 #define EXCEPTION_ACTION raise_exception_err(env->exception_index, env->error_code)
749 #else
750 #define EXCEPTION_ACTION cpu_loop_exit()
751 #endif
753 /* 'pc' is the host PC at which the exception was raised. 'address' is
754 the effective address of the memory exception. 'is_write' is 1 if a
755 write caused the exception and otherwise 0'. 'old_set' is the
756 signal set which should be restored */
757 static inline int handle_cpu_signal(unsigned long pc, unsigned long address,
758 int is_write, sigset_t *old_set,
759 void *puc)
761 TranslationBlock *tb;
762 int ret;
764 if (cpu_single_env)
765 env = cpu_single_env; /* XXX: find a correct solution for multithread */
766 #if defined(DEBUG_SIGNAL)
767 qemu_printf("qemu: SIGSEGV pc=0x%08lx address=%08lx w=%d oldset=0x%08lx\n",
768 pc, address, is_write, *(unsigned long *)old_set);
769 #endif
770 /* XXX: locking issue */
771 if (is_write && page_unprotect(h2g(address), pc, puc)) {
772 return 1;
775 /* see if it is an MMU fault */
776 ret = cpu_handle_mmu_fault(env, address, is_write, MMU_USER_IDX, 0);
777 if (ret < 0)
778 return 0; /* not an MMU fault */
779 if (ret == 0)
780 return 1; /* the MMU fault was handled without causing real CPU fault */
781 /* now we have a real cpu fault */
782 tb = tb_find_pc(pc);
783 if (tb) {
784 /* the PC is inside the translated code. It means that we have
785 a virtual CPU fault */
786 cpu_restore_state(tb, env, pc, puc);
789 /* we restore the process signal mask as the sigreturn should
790 do it (XXX: use sigsetjmp) */
791 sigprocmask(SIG_SETMASK, old_set, NULL);
792 EXCEPTION_ACTION;
794 /* never comes here */
795 return 1;
798 #if defined(__i386__)
800 #if defined(__APPLE__)
801 # include <sys/ucontext.h>
803 # define EIP_sig(context) (*((unsigned long*)&(context)->uc_mcontext->ss.eip))
804 # define TRAP_sig(context) ((context)->uc_mcontext->es.trapno)
805 # define ERROR_sig(context) ((context)->uc_mcontext->es.err)
806 # define MASK_sig(context) ((context)->uc_sigmask)
807 #elif defined (__NetBSD__)
808 # include <ucontext.h>
810 # define EIP_sig(context) ((context)->uc_mcontext.__gregs[_REG_EIP])
811 # define TRAP_sig(context) ((context)->uc_mcontext.__gregs[_REG_TRAPNO])
812 # define ERROR_sig(context) ((context)->uc_mcontext.__gregs[_REG_ERR])
813 # define MASK_sig(context) ((context)->uc_sigmask)
814 #elif defined (__FreeBSD__) || defined(__DragonFly__)
815 # include <ucontext.h>
817 # define EIP_sig(context) (*((unsigned long*)&(context)->uc_mcontext.mc_eip))
818 # define TRAP_sig(context) ((context)->uc_mcontext.mc_trapno)
819 # define ERROR_sig(context) ((context)->uc_mcontext.mc_err)
820 # define MASK_sig(context) ((context)->uc_sigmask)
821 #elif defined(__OpenBSD__)
822 # define EIP_sig(context) ((context)->sc_eip)
823 # define TRAP_sig(context) ((context)->sc_trapno)
824 # define ERROR_sig(context) ((context)->sc_err)
825 # define MASK_sig(context) ((context)->sc_mask)
826 #else
827 # define EIP_sig(context) ((context)->uc_mcontext.gregs[REG_EIP])
828 # define TRAP_sig(context) ((context)->uc_mcontext.gregs[REG_TRAPNO])
829 # define ERROR_sig(context) ((context)->uc_mcontext.gregs[REG_ERR])
830 # define MASK_sig(context) ((context)->uc_sigmask)
831 #endif
833 int cpu_signal_handler(int host_signum, void *pinfo,
834 void *puc)
836 siginfo_t *info = pinfo;
837 #if defined(__NetBSD__) || defined (__FreeBSD__) || defined(__DragonFly__)
838 ucontext_t *uc = puc;
839 #elif defined(__OpenBSD__)
840 struct sigcontext *uc = puc;
841 #else
842 struct ucontext *uc = puc;
843 #endif
844 unsigned long pc;
845 int trapno;
847 #ifndef REG_EIP
848 /* for glibc 2.1 */
849 #define REG_EIP EIP
850 #define REG_ERR ERR
851 #define REG_TRAPNO TRAPNO
852 #endif
853 pc = EIP_sig(uc);
854 trapno = TRAP_sig(uc);
855 return handle_cpu_signal(pc, (unsigned long)info->si_addr,
856 trapno == 0xe ?
857 (ERROR_sig(uc) >> 1) & 1 : 0,
858 &MASK_sig(uc), puc);
861 #elif defined(__x86_64__)
863 #ifdef __NetBSD__
864 #define PC_sig(context) _UC_MACHINE_PC(context)
865 #define TRAP_sig(context) ((context)->uc_mcontext.__gregs[_REG_TRAPNO])
866 #define ERROR_sig(context) ((context)->uc_mcontext.__gregs[_REG_ERR])
867 #define MASK_sig(context) ((context)->uc_sigmask)
868 #elif defined(__OpenBSD__)
869 #define PC_sig(context) ((context)->sc_rip)
870 #define TRAP_sig(context) ((context)->sc_trapno)
871 #define ERROR_sig(context) ((context)->sc_err)
872 #define MASK_sig(context) ((context)->sc_mask)
873 #elif defined (__FreeBSD__) || defined(__DragonFly__)
874 #include <ucontext.h>
876 #define PC_sig(context) (*((unsigned long*)&(context)->uc_mcontext.mc_rip))
877 #define TRAP_sig(context) ((context)->uc_mcontext.mc_trapno)
878 #define ERROR_sig(context) ((context)->uc_mcontext.mc_err)
879 #define MASK_sig(context) ((context)->uc_sigmask)
880 #else
881 #define PC_sig(context) ((context)->uc_mcontext.gregs[REG_RIP])
882 #define TRAP_sig(context) ((context)->uc_mcontext.gregs[REG_TRAPNO])
883 #define ERROR_sig(context) ((context)->uc_mcontext.gregs[REG_ERR])
884 #define MASK_sig(context) ((context)->uc_sigmask)
885 #endif
887 int cpu_signal_handler(int host_signum, void *pinfo,
888 void *puc)
890 siginfo_t *info = pinfo;
891 unsigned long pc;
892 #if defined(__NetBSD__) || defined (__FreeBSD__) || defined(__DragonFly__)
893 ucontext_t *uc = puc;
894 #elif defined(__OpenBSD__)
895 struct sigcontext *uc = puc;
896 #else
897 struct ucontext *uc = puc;
898 #endif
900 pc = PC_sig(uc);
901 return handle_cpu_signal(pc, (unsigned long)info->si_addr,
902 TRAP_sig(uc) == 0xe ?
903 (ERROR_sig(uc) >> 1) & 1 : 0,
904 &MASK_sig(uc), puc);
907 #elif defined(_ARCH_PPC)
909 /***********************************************************************
910 * signal context platform-specific definitions
911 * From Wine
913 #ifdef linux
914 /* All Registers access - only for local access */
915 # define REG_sig(reg_name, context) ((context)->uc_mcontext.regs->reg_name)
916 /* Gpr Registers access */
917 # define GPR_sig(reg_num, context) REG_sig(gpr[reg_num], context)
918 # define IAR_sig(context) REG_sig(nip, context) /* Program counter */
919 # define MSR_sig(context) REG_sig(msr, context) /* Machine State Register (Supervisor) */
920 # define CTR_sig(context) REG_sig(ctr, context) /* Count register */
921 # define XER_sig(context) REG_sig(xer, context) /* User's integer exception register */
922 # define LR_sig(context) REG_sig(link, context) /* Link register */
923 # define CR_sig(context) REG_sig(ccr, context) /* Condition register */
924 /* Float Registers access */
925 # define FLOAT_sig(reg_num, context) (((double*)((char*)((context)->uc_mcontext.regs+48*4)))[reg_num])
926 # define FPSCR_sig(context) (*(int*)((char*)((context)->uc_mcontext.regs+(48+32*2)*4)))
927 /* Exception Registers access */
928 # define DAR_sig(context) REG_sig(dar, context)
929 # define DSISR_sig(context) REG_sig(dsisr, context)
930 # define TRAP_sig(context) REG_sig(trap, context)
931 #endif /* linux */
933 #if defined(__FreeBSD__) || defined(__FreeBSD_kernel__)
934 #include <ucontext.h>
935 # define IAR_sig(context) ((context)->uc_mcontext.mc_srr0)
936 # define MSR_sig(context) ((context)->uc_mcontext.mc_srr1)
937 # define CTR_sig(context) ((context)->uc_mcontext.mc_ctr)
938 # define XER_sig(context) ((context)->uc_mcontext.mc_xer)
939 # define LR_sig(context) ((context)->uc_mcontext.mc_lr)
940 # define CR_sig(context) ((context)->uc_mcontext.mc_cr)
941 /* Exception Registers access */
942 # define DAR_sig(context) ((context)->uc_mcontext.mc_dar)
943 # define DSISR_sig(context) ((context)->uc_mcontext.mc_dsisr)
944 # define TRAP_sig(context) ((context)->uc_mcontext.mc_exc)
945 #endif /* __FreeBSD__|| __FreeBSD_kernel__ */
947 #ifdef __APPLE__
948 # include <sys/ucontext.h>
949 typedef struct ucontext SIGCONTEXT;
950 /* All Registers access - only for local access */
951 # define REG_sig(reg_name, context) ((context)->uc_mcontext->ss.reg_name)
952 # define FLOATREG_sig(reg_name, context) ((context)->uc_mcontext->fs.reg_name)
953 # define EXCEPREG_sig(reg_name, context) ((context)->uc_mcontext->es.reg_name)
954 # define VECREG_sig(reg_name, context) ((context)->uc_mcontext->vs.reg_name)
955 /* Gpr Registers access */
956 # define GPR_sig(reg_num, context) REG_sig(r##reg_num, context)
957 # define IAR_sig(context) REG_sig(srr0, context) /* Program counter */
958 # define MSR_sig(context) REG_sig(srr1, context) /* Machine State Register (Supervisor) */
959 # define CTR_sig(context) REG_sig(ctr, context)
960 # define XER_sig(context) REG_sig(xer, context) /* Link register */
961 # define LR_sig(context) REG_sig(lr, context) /* User's integer exception register */
962 # define CR_sig(context) REG_sig(cr, context) /* Condition register */
963 /* Float Registers access */
964 # define FLOAT_sig(reg_num, context) FLOATREG_sig(fpregs[reg_num], context)
965 # define FPSCR_sig(context) ((double)FLOATREG_sig(fpscr, context))
966 /* Exception Registers access */
967 # define DAR_sig(context) EXCEPREG_sig(dar, context) /* Fault registers for coredump */
968 # define DSISR_sig(context) EXCEPREG_sig(dsisr, context)
969 # define TRAP_sig(context) EXCEPREG_sig(exception, context) /* number of powerpc exception taken */
970 #endif /* __APPLE__ */
972 int cpu_signal_handler(int host_signum, void *pinfo,
973 void *puc)
975 siginfo_t *info = pinfo;
976 #if defined(__FreeBSD__) || defined(__FreeBSD_kernel__)
977 ucontext_t *uc = puc;
978 #else
979 struct ucontext *uc = puc;
980 #endif
981 unsigned long pc;
982 int is_write;
984 pc = IAR_sig(uc);
985 is_write = 0;
986 #if 0
987 /* ppc 4xx case */
988 if (DSISR_sig(uc) & 0x00800000)
989 is_write = 1;
990 #else
991 if (TRAP_sig(uc) != 0x400 && (DSISR_sig(uc) & 0x02000000))
992 is_write = 1;
993 #endif
994 return handle_cpu_signal(pc, (unsigned long)info->si_addr,
995 is_write, &uc->uc_sigmask, puc);
998 #elif defined(__alpha__)
1000 int cpu_signal_handler(int host_signum, void *pinfo,
1001 void *puc)
1003 siginfo_t *info = pinfo;
1004 struct ucontext *uc = puc;
1005 uint32_t *pc = uc->uc_mcontext.sc_pc;
1006 uint32_t insn = *pc;
1007 int is_write = 0;
1009 /* XXX: need kernel patch to get write flag faster */
1010 switch (insn >> 26) {
1011 case 0x0d: // stw
1012 case 0x0e: // stb
1013 case 0x0f: // stq_u
1014 case 0x24: // stf
1015 case 0x25: // stg
1016 case 0x26: // sts
1017 case 0x27: // stt
1018 case 0x2c: // stl
1019 case 0x2d: // stq
1020 case 0x2e: // stl_c
1021 case 0x2f: // stq_c
1022 is_write = 1;
1025 return handle_cpu_signal(pc, (unsigned long)info->si_addr,
1026 is_write, &uc->uc_sigmask, puc);
1028 #elif defined(__sparc__)
1030 int cpu_signal_handler(int host_signum, void *pinfo,
1031 void *puc)
1033 siginfo_t *info = pinfo;
1034 int is_write;
1035 uint32_t insn;
1036 #if !defined(__arch64__) || defined(CONFIG_SOLARIS)
1037 uint32_t *regs = (uint32_t *)(info + 1);
1038 void *sigmask = (regs + 20);
1039 /* XXX: is there a standard glibc define ? */
1040 unsigned long pc = regs[1];
1041 #else
1042 #ifdef __linux__
1043 struct sigcontext *sc = puc;
1044 unsigned long pc = sc->sigc_regs.tpc;
1045 void *sigmask = (void *)sc->sigc_mask;
1046 #elif defined(__OpenBSD__)
1047 struct sigcontext *uc = puc;
1048 unsigned long pc = uc->sc_pc;
1049 void *sigmask = (void *)(long)uc->sc_mask;
1050 #endif
1051 #endif
1053 /* XXX: need kernel patch to get write flag faster */
1054 is_write = 0;
1055 insn = *(uint32_t *)pc;
1056 if ((insn >> 30) == 3) {
1057 switch((insn >> 19) & 0x3f) {
1058 case 0x05: // stb
1059 case 0x15: // stba
1060 case 0x06: // sth
1061 case 0x16: // stha
1062 case 0x04: // st
1063 case 0x14: // sta
1064 case 0x07: // std
1065 case 0x17: // stda
1066 case 0x0e: // stx
1067 case 0x1e: // stxa
1068 case 0x24: // stf
1069 case 0x34: // stfa
1070 case 0x27: // stdf
1071 case 0x37: // stdfa
1072 case 0x26: // stqf
1073 case 0x36: // stqfa
1074 case 0x25: // stfsr
1075 case 0x3c: // casa
1076 case 0x3e: // casxa
1077 is_write = 1;
1078 break;
1081 return handle_cpu_signal(pc, (unsigned long)info->si_addr,
1082 is_write, sigmask, NULL);
1085 #elif defined(__arm__)
1087 int cpu_signal_handler(int host_signum, void *pinfo,
1088 void *puc)
1090 siginfo_t *info = pinfo;
1091 struct ucontext *uc = puc;
1092 unsigned long pc;
1093 int is_write;
1095 #if (__GLIBC__ < 2 || (__GLIBC__ == 2 && __GLIBC_MINOR__ <= 3))
1096 pc = uc->uc_mcontext.gregs[R15];
1097 #else
1098 pc = uc->uc_mcontext.arm_pc;
1099 #endif
1100 /* XXX: compute is_write */
1101 is_write = 0;
1102 return handle_cpu_signal(pc, (unsigned long)info->si_addr,
1103 is_write,
1104 &uc->uc_sigmask, puc);
1107 #elif defined(__mc68000)
1109 int cpu_signal_handler(int host_signum, void *pinfo,
1110 void *puc)
1112 siginfo_t *info = pinfo;
1113 struct ucontext *uc = puc;
1114 unsigned long pc;
1115 int is_write;
1117 pc = uc->uc_mcontext.gregs[16];
1118 /* XXX: compute is_write */
1119 is_write = 0;
1120 return handle_cpu_signal(pc, (unsigned long)info->si_addr,
1121 is_write,
1122 &uc->uc_sigmask, puc);
1125 #elif defined(__ia64)
1127 #ifndef __ISR_VALID
1128 /* This ought to be in <bits/siginfo.h>... */
1129 # define __ISR_VALID 1
1130 #endif
1132 int cpu_signal_handler(int host_signum, void *pinfo, void *puc)
1134 siginfo_t *info = pinfo;
1135 struct ucontext *uc = puc;
1136 unsigned long ip;
1137 int is_write = 0;
1139 ip = uc->uc_mcontext.sc_ip;
1140 switch (host_signum) {
1141 case SIGILL:
1142 case SIGFPE:
1143 case SIGSEGV:
1144 case SIGBUS:
1145 case SIGTRAP:
1146 if (info->si_code && (info->si_segvflags & __ISR_VALID))
1147 /* ISR.W (write-access) is bit 33: */
1148 is_write = (info->si_isr >> 33) & 1;
1149 break;
1151 default:
1152 break;
1154 return handle_cpu_signal(ip, (unsigned long)info->si_addr,
1155 is_write,
1156 (sigset_t *)&uc->uc_sigmask, puc);
1159 #elif defined(__s390__)
1161 int cpu_signal_handler(int host_signum, void *pinfo,
1162 void *puc)
1164 siginfo_t *info = pinfo;
1165 struct ucontext *uc = puc;
1166 unsigned long pc;
1167 uint16_t *pinsn;
1168 int is_write = 0;
1170 pc = uc->uc_mcontext.psw.addr;
1172 /* ??? On linux, the non-rt signal handler has 4 (!) arguments instead
1173 of the normal 2 arguments. The 3rd argument contains the "int_code"
1174 from the hardware which does in fact contain the is_write value.
1175 The rt signal handler, as far as I can tell, does not give this value
1176 at all. Not that we could get to it from here even if it were. */
1177 /* ??? This is not even close to complete, since it ignores all
1178 of the read-modify-write instructions. */
1179 pinsn = (uint16_t *)pc;
1180 switch (pinsn[0] >> 8) {
1181 case 0x50: /* ST */
1182 case 0x42: /* STC */
1183 case 0x40: /* STH */
1184 is_write = 1;
1185 break;
1186 case 0xc4: /* RIL format insns */
1187 switch (pinsn[0] & 0xf) {
1188 case 0xf: /* STRL */
1189 case 0xb: /* STGRL */
1190 case 0x7: /* STHRL */
1191 is_write = 1;
1193 break;
1194 case 0xe3: /* RXY format insns */
1195 switch (pinsn[2] & 0xff) {
1196 case 0x50: /* STY */
1197 case 0x24: /* STG */
1198 case 0x72: /* STCY */
1199 case 0x70: /* STHY */
1200 case 0x8e: /* STPQ */
1201 case 0x3f: /* STRVH */
1202 case 0x3e: /* STRV */
1203 case 0x2f: /* STRVG */
1204 is_write = 1;
1206 break;
1208 return handle_cpu_signal(pc, (unsigned long)info->si_addr,
1209 is_write, &uc->uc_sigmask, puc);
1212 #elif defined(__mips__)
1214 int cpu_signal_handler(int host_signum, void *pinfo,
1215 void *puc)
1217 siginfo_t *info = pinfo;
1218 struct ucontext *uc = puc;
1219 greg_t pc = uc->uc_mcontext.pc;
1220 int is_write;
1222 /* XXX: compute is_write */
1223 is_write = 0;
1224 return handle_cpu_signal(pc, (unsigned long)info->si_addr,
1225 is_write, &uc->uc_sigmask, puc);
1228 #elif defined(__hppa__)
1230 int cpu_signal_handler(int host_signum, void *pinfo,
1231 void *puc)
1233 struct siginfo *info = pinfo;
1234 struct ucontext *uc = puc;
1235 unsigned long pc = uc->uc_mcontext.sc_iaoq[0];
1236 uint32_t insn = *(uint32_t *)pc;
1237 int is_write = 0;
1239 /* XXX: need kernel patch to get write flag faster. */
1240 switch (insn >> 26) {
1241 case 0x1a: /* STW */
1242 case 0x19: /* STH */
1243 case 0x18: /* STB */
1244 case 0x1b: /* STWM */
1245 is_write = 1;
1246 break;
1248 case 0x09: /* CSTWX, FSTWX, FSTWS */
1249 case 0x0b: /* CSTDX, FSTDX, FSTDS */
1250 /* Distinguish from coprocessor load ... */
1251 is_write = (insn >> 9) & 1;
1252 break;
1254 case 0x03:
1255 switch ((insn >> 6) & 15) {
1256 case 0xa: /* STWS */
1257 case 0x9: /* STHS */
1258 case 0x8: /* STBS */
1259 case 0xe: /* STWAS */
1260 case 0xc: /* STBYS */
1261 is_write = 1;
1263 break;
1266 return handle_cpu_signal(pc, (unsigned long)info->si_addr,
1267 is_write, &uc->uc_sigmask, puc);
1270 #else
1272 #error host CPU specific signal handler needed
1274 #endif
1276 #endif /* !defined(CONFIG_SOFTMMU) */