[Qemu-devel] [PATCH v4 0/3] disable the decrementer interrupt when a CPU

From: Cédric Le Goater
Subject: [Qemu-devel] [PATCH v4 0/3] disable the decrementer interrupt when a CPU is unplugged
Date: Fri, 24 Nov 2017 08:05:47 +0100


When a CPU is stopped with the 'stop-self' RTAS call, its state
'halted' is switched to 1 and, in this case, the MSR is not taken into
account anymore in the cpu_has_work() routine. Only the pending
hardware interrupts are checked with their LPCR:PECE* enablement bit.

If the DECR timer fires after 'stop-self' is called and before the CPU
'stop' state is reached, the nearly-dead CPU will have some work to do
and the guest will crash. This case happens very frequently with the
not yet upstream P9 XIVE exploitation mode. In XICS mode, the DECR is
occasionally fired but after 'stop' state, so no work is to be done
and the guest survives.

I suspect there is a race between the QEMU mainloop triggering the
timers and the TCG CPU thread but I could not quite identify the root
cause. To be safe, let's disable the decrementer interrupt in the LPCR
when the CPU is halted and reenable it when the CPU is restarted.
Reseting the MSR is now pointless, so remove this dubious workaround.



Changes in v4:

 - used the 'lpcr_pm' field of PowerPCCPUClass

Changes in v3:

 - removed the ppc_cpu_pvr_match() routine testing the CPU family.
 - introduced a cpu_ppc_papr_pece_bits() helper to gather the PECE
   bits depending on the CPU family.   
 - enabled Power-saving mode Exit Cause exceptions only on the boot CPU.
Changes in v2:

 - used a new routine ppc_cpu_pvr_match() to discriminate CPU versions
 - removed the LPCR:PECE* enablement bit when the CPU is initialized
   if it is a secondary
 - included Nikunj's fix to reboot SMP TCG guests
Cédric Le Goater (3):
  spapr/rtas: disable the decrementer interrupt when a CPU is unplugged
  spapr/rtas: fix reboot of a a SMP TCG guest
  spapr/rtas: do not reset the MSR in stop-self command

 hw/ppc/spapr_cpu_core.c     |  8 ++++++++
 hw/ppc/spapr_rtas.c         | 21 +++++++++++----------
 target/ppc/translate_init.c |  9 ++++++---
 3 files changed, 25 insertions(+), 13 deletions(-)


