)]}'
{
  "commit": "e9418396e050a5cccf64de180d403f7839ec4eb0",
  "tree": "402d9c639fe20c8bae374bd7d0eb8cf22346f4e8",
  "parents": [
    "b267cdd260cfc24aa35a80fafa5f68e38c6304b2"
  ],
  "author": {
    "name": "Richard Henderson",
    "email": "richard.henderson@linaro.org",
    "time": "Wed Sep 23 15:06:53 2026 -0700"
  },
  "committer": {
    "name": "Michael Tokarev",
    "email": "mjt@tls.msk.ru",
    "time": "Mon Sep 28 10:06:45 2026 +0300"
  },
  "message": "target/sh4: Replace TB_FLAG_GUSA_EXCLUSIVE with CF_STEP_ATOMIC\n\nThere was a complex bug with gUSA wherein:\n\n  * decode_gusa calls gen_restart_exclusive\n  * gen_restart_exclusive generates code that sets TB_FLAG_GUSA_EXCLUSIVE\n    and generates a call to helper_exclusive\n\n  * when the code is executed, TB_FLAG_GUSA_EXCLUSIVE is set\n  * helper_exclusive calls cpu_loop_exit_atomic, this makes cpu_exec exit\n    with EXCP_ATOMIC\n  * we go to cpu_loop, we execute cpu_exec_step_atomic\n  * suppose that exit request is set, cpu_exec_step_atomic does nothing, it\n    leaves the CPU in the same state as it was before\n  * we go back to cpu_loop\n  * suppose that no signal is delivered, so the gUSA is not rewound\n  * cpu_loop goes to cpu_exec\n  * there is one difference - now, TB_FLAG_GUSA_EXCLUSIVE is set and it was\n    clear before - so cpu_exec will not use the TB that calls\n    helper_exclusive, it will instead use the TB that performs the atomic\n    operation (both of these TBs have the same PC, they only differ in flags)\n  * the TB that performs the atomic operation is executed inside cpu_exec\n    \u003d\u003e race condition\n\nFix the bug by managing the \"are we in cpu_exec_step_atomic\" flag\nfrom cpu_exec_step_atomic itself, rather from the translator.\n\nCc: qemu-stable@nongnu.org\nFixes: 4bfa602bc22 (\"target/sh4: Handle user-space atomics\")\nReported-by: Mikulas Patocka \u003cmpatocka@redhat.com\u003e\nSigned-off-by: Richard Henderson \u003crichard.henderson@linaro.org\u003e\nTested-by: Mikulas Patocka \u003cmpatocka@redhat.com\u003e\nSigned-off-by: Helge Deller \u003cdeller@gmx.de\u003e\n(cherry picked from commit 62728f8c932f9572eeea22f91e3ee223978b1c7f)\nSigned-off-by: Michael Tokarev \u003cmjt@tls.msk.ru\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "527102f783fa27dafd8f53eb146aca9e84057a8f",
      "old_mode": 33188,
      "old_path": "accel/tcg/cpu-exec.c",
      "new_id": "b2f4c80b55f2f3960456a3c2cad7f90adfbd5d3e",
      "new_mode": 33188,
      "new_path": "accel/tcg/cpu-exec.c"
    },
    {
      "type": "modify",
      "old_id": "40cc6990318ca41b748b68cb6280f74e66d69705",
      "old_mode": 33188,
      "old_path": "include/exec/translation-block.h",
      "new_id": "7c42c57cca6f349118c794e307d7132b3e3646a1",
      "new_mode": 33188,
      "new_path": "include/exec/translation-block.h"
    },
    {
      "type": "modify",
      "old_id": "3302702376378c487f4f54c008e7a57b3e1de191",
      "old_mode": 33188,
      "old_path": "target/sh4/cpu.h",
      "new_id": "6984bb462fb596cbb7a2f0e7902a45f4ebf547fc",
      "new_mode": 33188,
      "new_path": "target/sh4/cpu.h"
    },
    {
      "type": "modify",
      "old_id": "373950fd6625455ef89e242c2e91dd8cda7b2e2c",
      "old_mode": 33188,
      "old_path": "target/sh4/translate.c",
      "new_id": "c15c0802f7834d81a12f1fe71e96a1e4f09dd000",
      "new_mode": 33188,
      "new_path": "target/sh4/translate.c"
    }
  ]
}
