diff options
| author | Mikulas Patocka <mpatocka@redhat.com> | 2026-08-03 21:38:32 +0200 |
|---|---|---|
| committer | Helge Deller <deller@gmx.de> | 2026-08-07 15:13:36 +0200 |
| commit | f7ad7b1f8c8148f39bc1f2c984bfc7b7c9c59041 (patch) | |
| tree | f6c79a3974ae12f222346dd98c868084544f69ea /linux-user | |
| parent | 668d571bf0c2ee4851be2187798f413025647fc3 (diff) | |
| download | qemu-f7ad7b1f8c8148f39bc1f2c984bfc7b7c9c59041.tar.gz qemu-f7ad7b1f8c8148f39bc1f2c984bfc7b7c9c59041.zip | |
linux-user/sh4: Fix crashes on signal delivery in conditional delay slot
If we get a signal in the delay slot, we must roll-back the PC to the
jump instruction. This was already fixed by the commit 3b894b699c9a
("linux-user/sh4: Fix crashes on signal delivery"), however this fix
omits a test for TB_FLAG_DELAY_SLOT_COND. TB_FLAG_DELAY_SLOT_COND is set
by the conditional delayed branches bf/s and bt/s. Qemu did not roll-back
the PC in this case, resulting in incorrect program execution.
This patch fixes it.
Cc: qemu-stable@nongnu.org
Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
Reviewed-by: Yoshinori Sato <yoshinori.sato@nifty.com>
Signed-off-by: Helge Deller <deller@gmx.de>
Diffstat (limited to 'linux-user')
| -rw-r--r-- | linux-user/sh4/signal.c | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/linux-user/sh4/signal.c b/linux-user/sh4/signal.c index 7f246e750d..047174ac8f 100644 --- a/linux-user/sh4/signal.c +++ b/linux-user/sh4/signal.c @@ -109,7 +109,7 @@ static void unwind_gusa(CPUSH4State *regs) the SP, otherwise we would be pushing the signal context to invalid memory. */ regs->gregs[15] = regs->gregs[1]; - } else if (regs->flags & TB_FLAG_DELAY_SLOT) { + } else if (regs->flags & (TB_FLAG_DELAY_SLOT | TB_FLAG_DELAY_SLOT_COND)) { /* If we are in a delay slot, push the previous instruction. */ regs->pc -= 2; } |
