On Tue, 22 Sep 2026, Mikulas Patocka wrote:
> > Logging guest state at the point your revert hook fires could be
> > informative...
>
> Yes, I will look into it.
So, I tried, and got a hit right away:
superh_cpu_revert_uninterruptible
pc: 45be9e
r0: 45bea4
r1: 55d55e40
r15: fffffffa
flags: 1fa0
45be94: 10 89 bt 45beb8 <afree+0x84>
45be96: 03 c7 mova 45bea4 <afree+0x70>,r0
45be98: f3 61 mov r15,r1
45be9a: 09 00 nop
45be9c: fa ef mov #-6,r15
45be9e: 21 57 mov.l @(4,r2),r7
45bea0: 3b 27 or r3,r7
45bea2: 71 12 mov.l r7,@(4,r2)
45bea4: 13 6f mov r1,r15
45bea6: 0b 00 rts
Then, I tried to log only cases where pc points deeper into the gUSA
region and got nothing.
So, if superh_cpu_revert_uninterruptible reverts the PC from 45be9e back
to 45be9c, the deadlock doesn't happen.
Could it be, that on the exit path from cpu_exec_step_atomic, Qemu somehow
forgets that it is in the middle of the gUSA region and continues
execution in parallel?
Mikulas