tcg/wasm32: narrow store-TCI fallback to 32-bit stores
The compiled-store corruption requires 8-bit and 32-bit store TB populations compiled together. Interpreting either width breaks the interaction; keep only 32-bit qemu store TBs on TCI and allow the rest to compile. ?nostoretci remains the all-compiled repro path.
This commit is contained in:
@@ -3378,17 +3378,12 @@ static void tcg_out_qemu_st(TCGContext *s, TCGOpcode opc, const TCGArg *args, bo
|
||||
wasm_tb_had_store = true;
|
||||
tcg_tci_out_qemu_ldst(s, opc, args);
|
||||
tcg_wasm_out_qemu_st(s, args, is_64);
|
||||
/* ponytail: Store-Containing TBs Run on TCI - Upstream qemu-wasm sets this for every guest store.
|
||||
* Investigation (docs/wasm-inflate-panic.md E1-E8) proved the corruption is emergent, not
|
||||
* localizable: it is deterministic and needs both 8-bit and 32-bit store TBs compiled, yet no
|
||||
* single PC region of either width reproduces it, and it survives disabling TB chaining, pinning
|
||||
* instances, routing stores through the helper, and skipping replayed helpers. Whole-TB gating
|
||||
* (the backend's only knob) cannot dissect it further; the fix needs generated-wasm inspection or
|
||||
* per-op TCI. Ceiling: store-TBs interpreted (perf cost, ~30s book open). */
|
||||
/* Mode 2 (E11) needs the real buggy compiled-store path live, so leave stores compiled there.
|
||||
* E12 probe: wasm_store_tci_disabled lets a normal-speed build run compiled stores to test
|
||||
* whether the corruption workaround is still needed after later fixes. */
|
||||
if (wasm_diff_mode != 2 && !wasm_store_tci_disabled) {
|
||||
/* ponytail: 32-bit Store TBs Stay TCI - The corruption needs compiled 8-bit and 32-bit store
|
||||
* populations together; interpreting either width breaks the bad interaction. Keep the smaller
|
||||
* 32-bit subset on TCI and compile the rest. ?nostoretci remains the all-compiled repro path. */
|
||||
MemOp store_memop = get_memop(args[2]);
|
||||
bool store_tci = !wasm_store_tci_disabled && ((store_memop & MO_SIZE) == MO_32);
|
||||
if (wasm_diff_mode != 2 && store_tci) {
|
||||
wasm_tci_only_tb = true;
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user