@samitouri / QOSamiQemu / commits / e8743ca0ac

target/hexagon: fix J2_jumptnew/pt predicate check to use LSB

J2_jumptnew and J2_jumptnewpt passed the raw predicate value to gen_cond_jump(), checking if the full 8-bit value was non-zero. Refer to PRM Section 6.1.2 "predicate-consuming instructions examine only the least-significant bit". This inconsistency caused if (p0.new) jumps and if (p0.new) loads within the same packet to disagree when the predicate had values other than the ones generated by predicate-generating instructions (e.g. 0x80 or 0xAA where bit 0 is clear but the value is non-zero): the jump would be taken while the loads were skipped. Fix by routing both macros through fGEN_TCG_cond_jumpt(fLSBNEW(PuN)), matching the pattern used by every other predicated jump. Discovered-by: Alexey Karyakin <akaryaki@qti.qualcomm.com> Reviewed-by: Taylor Simpson <ltaylorsimpson@gmail.com> Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>

Brian Cain committed Mar 2, 2026 at 21:28 UTC e8743ca0acc5118a934ab974974aa147f40875eb
1 file changed +2 -2
target/hexagon/gen_tcg.h
+2 -2
@@ -951,9 +951,9 @@
951 #define fGEN_TCG_J2_jumpfpt(SHORTCODE) \
952 fGEN_TCG_cond_jumpf(fLSBOLD(PuV))
953 #define fGEN_TCG_J2_jumptnew(SHORTCODE) \
954 - gen_cond_jump(ctx, TCG_COND_EQ, PuN, riV)
954 + fGEN_TCG_cond_jumpt(fLSBNEW(PuN))
955 #define fGEN_TCG_J2_jumptnewpt(SHORTCODE) \
956 - gen_cond_jump(ctx, TCG_COND_EQ, PuN, riV)
956 + fGEN_TCG_cond_jumpt(fLSBNEW(PuN))
957 #define fGEN_TCG_J2_jumpfnewpt(SHORTCODE) \
958 fGEN_TCG_cond_jumpf(fLSBNEW(PuN))
959 #define fGEN_TCG_J2_jumpfnew(SHORTCODE) \