target/riscv: Update $ra with current $pc in trans_cm_jalt()

The original implementation sets $pc to the address read from the jump
vector table first and links $ra with the address of the next instruction
after the updated $pc. After jumping to the updated $pc and executing the
next ret instruction, the program jumps to $ra, which is in the same
function currently executing, which results in an infinite loop.
This commit stores the jump address in a temporary, updates $ra with the
current $pc, and copies the temporary to $pc.

Signed-off-by: Jason Chien <jason.chien@sifive.com>
Reviewed-by: Frank Chang <frank.chang@sifive.com>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Message-ID: <20240207081820.28559-1-jason.chien@sifive.com>
Signed-off-by: Alistair Francis <alistair.francis@wdc.com>
This commit is contained in:
Jason Chien 2024-02-07 16:18:08 +08:00 committed by Alistair Francis
parent 8f6330a807
commit 3011c1dd9c

View File

@ -293,12 +293,14 @@ static bool trans_cm_jalt(DisasContext *ctx, arg_cm_jalt *a)
{ {
REQUIRE_ZCMT(ctx); REQUIRE_ZCMT(ctx);
TCGv addr = tcg_temp_new();
/* /*
* Update pc to current for the non-unwinding exception * Update pc to current for the non-unwinding exception
* that might come from cpu_ld*_code() in the helper. * that might come from cpu_ld*_code() in the helper.
*/ */
gen_update_pc(ctx, 0); gen_update_pc(ctx, 0);
gen_helper_cm_jalt(cpu_pc, tcg_env, tcg_constant_i32(a->index)); gen_helper_cm_jalt(addr, tcg_env, tcg_constant_i32(a->index));
/* c.jt vs c.jalt depends on the index. */ /* c.jt vs c.jalt depends on the index. */
if (a->index >= 32) { if (a->index >= 32) {
@ -307,6 +309,8 @@ static bool trans_cm_jalt(DisasContext *ctx, arg_cm_jalt *a)
gen_set_gpr(ctx, xRA, succ_pc); gen_set_gpr(ctx, xRA, succ_pc);
} }
tcg_gen_mov_tl(cpu_pc, addr);
tcg_gen_lookup_and_goto_ptr(); tcg_gen_lookup_and_goto_ptr();
ctx->base.is_jmp = DISAS_NORETURN; ctx->base.is_jmp = DISAS_NORETURN;
return true; return true;