fix(verify): fix non-amd64 JIT trampolines and validate under qemu
This commit is contained in:
@@ -369,11 +369,12 @@ every architecture too: `enterJITChecked` plants sentinels in the registers
|
||||
the Go ABI fixes across calls (amd64 `BP`/`R14`, arm64 `R29`/`R28`, riscv64
|
||||
`X27`, loong64 `R22`; the latter two keep no hardware frame pointer) and the
|
||||
raw return trampoline `leaveJITCheckedRaw` verifies them, restoring the
|
||||
saved registers before Go code resumes. At present only the amd64 JIT path
|
||||
is runtime-proven: the non-amd64 trampolines compile and their kernels are
|
||||
correct, but the return into Go code still fails under emulation, so `gasm
|
||||
verify` gates JIT execution to amd64 kernels on amd64 hosts and runs only
|
||||
the toolchain comparisons elsewhere (see docs/DECISIONS.md).
|
||||
saved registers before Go code resumes. riscv64 is validated end to
|
||||
end under qemu-user emulation; arm64 shares the same stack convention and
|
||||
fix; loong64 stays ground-truth-only until hardware validation (see
|
||||
docs/DECISIONS.md). `gasm verify` runs the JIT checks when the host
|
||||
matches the kernel's architecture and the toolchain comparisons
|
||||
elsewhere.
|
||||
|
||||
`Load` / `LoadSource` / `LoadAST` parse, assemble and map a `.s` file in one
|
||||
step, returning a `Kernel` whose `CallFunc` method marshals the argument block
|
||||
|
||||
+18
-2
@@ -35,8 +35,24 @@ for the lifetime of the GOOBJ emission.
|
||||
|
||||
## 2026-08-30 non-amd64 JIT execution trampolines
|
||||
|
||||
**Status:** open (blocks runtime verification on arm64, riscv64 and
|
||||
loong64 hosts).
|
||||
**Status:** resolved for riscv64 (validated end to end under qemu-user)
|
||||
and arm64 (fix in place, consistent with the observed frame convention);
|
||||
open for loong64 until hardware validation.
|
||||
|
||||
**Root cause (found 2026-08-31).** The trampolines advanced SP past the
|
||||
leave-address slot after loading it, while the assembled kernels read
|
||||
their first argument at SP+8 per the frame convention (the amd64 path
|
||||
already kept SP on that slot). Removing the advance fixed riscv64
|
||||
immediately (plain and checked ABI tests pass under qemu-user); the
|
||||
arm64 kernel's pre-fix trace showed exactly the same SP+8 reading. The
|
||||
apparent arm64/loong64 "crashes in the JIT" turned out to be dominated
|
||||
by an unrelated instability: the Go 1.26 and 1.27 runtimes crash under
|
||||
qemu-user arm64 emulation (GC worker start, identical signature with the
|
||||
JIT tests skipped, both qemu 7.2 and 10.2), and the Go loong64 runtime
|
||||
does not start at all. `gasm verify` therefore keeps loong64 kernels on
|
||||
the ground-truth path until hardware validation; the GOARCH-guarded
|
||||
tests (`verify/jit_arch_test.go`, `verify/abi_arch_test.go`) are the
|
||||
hardware validation entry point.
|
||||
|
||||
**State.** The per-architecture trampolines compile for all targets, the
|
||||
kernels they execute are byte-for-byte correct against `go tool asm`, and
|
||||
|
||||
Reference in New Issue
Block a user