target/s390x/tcg: Set STCK/STCKF condition code after the store
STORE CLOCK [FAST] to an inaccessible address aborts QEMU: $ qemu-s390x ./stckf ERROR:cc_helper.c:128:cc_calc_addu: assertion failed: (carry_out <= 1) op_stck() sets the condition code with gen_op_movi_cc() before the output operand store, which is deferred to wout_m1_64(). Assigning a constant condition code discards the lazy CC values, so the optimizer drops the writes that produced them. When the store then raises an exception, the instruction is suppressed and s390x_restore_state_to_opc() reinstates the cc_op recorded at the start of STCK[F], but cc_src/cc_dst now hold stale values, so the next condition code evaluation reads garbage. Fix by performing the store manually. The alternative of not discarding in gen_op_movi_cc() keeps the inputs live, but results in less optimal code. Reported-by: Ido Plat <Ido.Plat1@ibm.com> Fixes: 434c91a5f4ed ("target-s390: Convert STCK") Cc: qemu-stable@nongnu.org Signed-off-by: Ilya Leoshkevich <iii@linux.ibm.com> Reviewed-by: Eric Farman <farman@linux.ibm.com> Link: https://lore.kernel.org/qemu-devel/20260714203206.363028-2-iii@linux.ibm.com Signed-off-by: Eric Farman <farman@linux.ibm.com>