From: Simon Scherer <[email protected]>

Per the SDM, FXCH unconditionally clears the FPU status word's C1
flag. QEMU's helper_fxchg_ST0_STN swaps ST(0) and ST(i) but never
touches fpus, so C1 is left untouched from whatever prior instruction
set it.

This patch clears C1 after the exchange matching the SDM.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4399
Signed-off-by: Simon Scherer <[email protected]>
Link: 
https://lore.kernel.org/r/[email protected]
Signed-off-by: Paolo Bonzini <[email protected]>
(cherry picked from commit c7cc09c85b89f8dbabff548a441d8f2c3a5ca50a)
Signed-off-by: Michael Tokarev <[email protected]>

diff --git a/target/i386/tcg/fpu_helper.c b/target/i386/tcg/fpu_helper.c
index 128f16dc951..235a9adcc15 100644
--- a/target/i386/tcg/fpu_helper.c
+++ b/target/i386/tcg/fpu_helper.c
@@ -519,6 +519,9 @@ void helper_fxchg_ST0_STN(CPUX86State *env, int st_index)
     tmp = ST(st_index);
     ST(st_index) = ST0;
     ST0 = tmp;
+
+    /* C1 is unconditionally cleared to 0 */
+    env->fpus &= ~0x0200;
 }
 
 /* FPU operations */
-- 
2.47.3


Reply via email to