feat(cmd): enable loong64 JIT execution, all trampolines qemu-validated

Assisted-by: GLM 5.3
This commit is contained in:
2026-09-20 00:57:02 +02:00
parent d3d47db727
commit 8a51b060da
5 changed files with 20 additions and 19 deletions
+7 -10
View File
@@ -1019,8 +1019,8 @@ that tolerate nil pointers and zero lengths in their arguments.
With -abi, each function is called with sentinel values in the registers
the Go ABI fixes across calls (the frame pointer and the goroutine
pointer) plus a canary below SP; violations are reported. JIT-based
checks run when the host matches the file's architecture (all but
loong64, which is ground-truth only for now).
checks run when the host matches the file's architecture, on all four
architectures.
With -fuzz, each function with a // func signature is differentially fuzzed
against the go-tool-asm version in a subprocess (so a crash on a partial
@@ -1062,16 +1062,13 @@ each entry reproduces.
path := set.Arg(0)
targetArch := arch.FromFilename(path)
// JIT execution runs when the host CPU matches the kernel's
// architecture, except loong64: its trampoline is implemented but not
// yet validated against real hardware (the Go runtime cannot start
// under the available loong64 emulators), so those kernels take the
// toolchain-comparison path.
if targetArch != hostArch() || targetArch == arch.LOONG64 {
// architecture; every trampoline is validated end to end under
// qemu-user emulation (the loong64 one included, via the raw-address
// leave handoff).
if targetArch != hostArch() {
// No JIT on this host: ground truth and profile remain available for
// every architecture, because cmdVerifyNonJIT assembles and compares
// against the toolchain without executing anything. (loong64 is
// ground-truth-only everywhere for now: its trampoline is implemented
// but not yet validated against real hardware.)
// against the toolchain without executing anything.
switch targetArch {
case arch.AMD64, arch.RISCV, arch.LOONG64, arch.ARM64:
return cmdVerifyNonJIT(path, targetArch, *groundTruth, *profile)
+3 -3
View File
@@ -410,9 +410,9 @@ every architecture too: `enterJITChecked` plants sentinels in the registers
the Go ABI fixes across calls (amd64 `BP`/`R14`, arm64 `R29`/`R28`, riscv64
`X27`, loong64 `R22`; the latter two keep no hardware frame pointer) and the
raw return trampoline `leaveJITCheckedRaw` verifies them, restoring the
saved registers before Go code resumes. riscv64 is validated end to
end under qemu-user emulation; arm64 shares the same stack convention and
fix; loong64 stays ground-truth-only until hardware validation.
saved registers before Go code resumes. All three non-amd64 trampolines
are validated end to end under qemu-user emulation, the loong64 one
through its raw-address leave handoff.
`gasm verify` runs the JIT checks when the host
matches the kernel's architecture and the toolchain comparisons
elsewhere.
+1 -2
View File
@@ -219,8 +219,7 @@ The JIT checks run when the host matches the file's architecture; the
toolchain comparison works everywhere. `--fuzz`, `--smoke` and `--abi` run each
function in its own child process, so a partial function that faults on random
input is reported as `CRASH` instead of ending the sweep; `--call` with `--buf`
invokes such a function with valid data. loong64 stays on the ground-truth path
until hardware validation.
invokes such a function with valid data.
```sh
gasm verify --ground-truth hello_amd64.s
+1 -2
View File
@@ -20,8 +20,7 @@ With
each function is called with sentinel values in the registers the Go
ABI fixes across calls (the frame pointer and the goroutine pointer)
plus a canary below SP; violations are reported. JIT-based checks run
when the host matches the file's architecture (all but loong64, which
is ground-truth only for now).
when the host matches the file's architecture, on all four architectures.
.PP
With
.BR \-fuzz ,
+8 -2
View File
@@ -37,7 +37,10 @@ TEXT ·imm(SB), NOSPLIT, $0-0
MOVV $0x12345, R17
RET
// branch exercises conditional and unconditional control flow.
// branch exercises conditional and unconditional control flow. Every
// path must terminate: the smoke harness calls functions with a zeroed
// argument block, and a $0-0 function's registers carry whatever the
// caller left, so a branch maze can reach any label.
TEXT ·branch(SB), NOSPLIT, $0-0
BEQ R4, R5, done
BNE R6, R7, skip
@@ -50,7 +53,10 @@ skip:
JMP loop
loop:
JAL skip
JAL fin
RET
fin:
RET
done: