Issue created by Sebastian Huber: 
https://gitlab.rtems.org/rtems/rtos/rtems/-/work_items/5769



The exception path of `_ISR_Handler` reads the control and status
register of coprocessor 1 with `mfc1` and writes it back with `mtc1`.
Those instructions address a floating point data register. `cfc1` and
`ctc1` address a control register.

So the save puts the bits of `$f31` into the frame at `R_FCSR`, over the
value which the prologue stores there. The restore puts the slot into
`$f31` and destroys that register. The same pair uses `C1_REVISION`,
which is `$f0` and which holds the identity of the unit rather than
state of a context.

The prologue stores the register through the two-read idiom of the port
and `_ISR_Handler_exit` restores it with `ctc1`, so the exception path
needs neither access. Nothing needs to fill `R_FEIR`, because no MIPS32
processor carries that register.

Found by the specification driven validation of the exception frame.
This description was created with Claude Code assistance.

-- 
View it on GitLab: https://gitlab.rtems.org/rtems/rtos/rtems/-/work_items/5769
You're receiving this email because of your account on gitlab.rtems.org. 
Unsubscribe from this thread: 
https://gitlab.rtems.org/-/namespace/49/sent_notifications/5-05exbpj2420xid4p8z49uagf8-1d/unsubscribe
 | Manage all notifications: https://gitlab.rtems.org/-/profile/notifications | 
Help: https://gitlab.rtems.org/help


_______________________________________________
bugs mailing list
[email protected]
http://lists.rtems.org/mailman/listinfo/bugs

Reply via email to