@samitouri / QOSamiQemu / commits / 3835a61341

hw/hppa: Fix crash of 64-bit HP-UX 11 while flushing caches

HP-UX 11 64-bit reads at bootup a word from address CPU_HPA + 0x500 while flushing the the cache of a T600. Add a memory handler to avoid crashing while reading this word. Signed-off-by: Helge Deller <deller@gmx.de> Reviewed-by: Anton Johansson <anjo@rev.ng>

Helge Deller committed Mar 15, 2026 at 19:16 UTC 3835a6134131f2557ef891bcbd5ee751c83d8cc2
1 file changed +20
hw/hppa/machine.c
+20
@@ -306,6 +306,8 @@ static TranslateFn *machine_HP_common_init_cpus(MachineState *machine)
306
307 for (unsigned int i = 0; i < smp_cpus; i++) {
308 g_autofree char *name = g_strdup_printf("cpu%u-io-eir", i);
309 + g_autofree char *cflush_name = NULL;
310 + MemoryRegion *cflush;
311
312 cpu_region = g_new(MemoryRegion, 1);
313 memory_region_init_io(cpu_region, OBJECT(cpu[i]), &hppa_io_eir_ops,
@@ -313,6 +315,24 @@ static TranslateFn *machine_HP_common_init_cpus(MachineState *machine)
315 memory_region_add_subregion(addr_space,
316 translate(NULL, CPU_HPA + i * 0x1000),
317 cpu_region);
318 +
319 + if (!hppa_is_pa20(&cpu[0]->env)) {
320 + continue;
321 + }
322 +
323 + /*
324 + * HP-UX 11 64-bit reads a word from address CPU_HPA + 0x500
325 + * while flushing the cache of a T600, which was the first
326 + * server with a 64-bit PA-RISC 2.0 CPU.
327 + * We return 0, since the value isn't used anyway.
328 + */
329 + cflush_name = g_strdup_printf("cpu%u-T600-cacheflush", i);
330 + cflush = g_new(MemoryRegion, 1);
331 + memory_region_init_io(cflush, NULL, &hppa_pci_ignore_ops,
332 + NULL, cflush_name, 4);
333 + memory_region_add_subregion(addr_space,
334 + translate(NULL, CPU_HPA + i * 0x1000 + 0x500),
335 + cflush);
336 }
337
338 /* RTC and DebugOutputPort on CPU #0 */