summary refs log tree commit diff stats
path: root/results/classifier/semantic-bugs/1790
blob: 2a0a409bfdfa818a04022de92259438780ba2198 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
instruction: 0.969
graphic: 0.821
boot: 0.809
semantic: 0.738
device: 0.730
mistranslation: 0.585
assembly: 0.543
network: 0.505
vnc: 0.500
other: 0.437
socket: 0.425
KVM: 0.068

[AARCH64] STGP instruction is not writing the value of the second register to memory
Description of problem:
My application is built with Clang 16 and the option -fsanitize=memtag-stack.
It means the the MTE protection is activated for the stack.
The local variables are tagged and the compiler is often using the STGP instruction "Store Allocation Tag and Pair of registers" in order to transfer the value of two 64-bit registers to memory.
The following instruction was not working as expected:
   18004: 69000895     	stgp	x21, x2, [x4]
The value of the second register x2 is not transferred to the memory.
Only x21 is written.

I think that the issue is in trans_STGP().
We don't call finalize_memop_pair() like we do for in the general trans_STP().

```
diff --git a/target/arm/tcg/translate-a64.c b/target/arm/tcg/translate-a64.c
index 7d0c8f79a7..f599f3e136 100644
--- a/target/arm/tcg/translate-a64.c
+++ b/target/arm/tcg/translate-a64.c
@@ -3034,6 +3034,8 @@ static bool trans_STGP(DisasContext *s, arg_ldstpair *a)
 
     tcg_rt = cpu_reg(s, a->rt);
     tcg_rt2 = cpu_reg(s, a->rt2);
+    mop = a->sz + 1;
+    mop = finalize_memop_pair(s, mop);
 
     assert(a->sz == 3);
```

With this fix, my OS (Kinibi) is now able to boot.