{"id":2232508,"url":"http://patchwork.ozlabs.org/api/1.1/patches/2232508/?format=json","web_url":"http://patchwork.ozlabs.org/project/qemu-devel/patch/20260504-feat-mte4-v5-12-232a648e63c6@gmail.com/","project":{"id":14,"url":"http://patchwork.ozlabs.org/api/1.1/projects/14/?format=json","name":"QEMU Development","link_name":"qemu-devel","list_id":"qemu-devel.nongnu.org","list_email":"qemu-devel@nongnu.org","web_url":"","scm_url":"","webscm_url":""},"msgid":"<20260504-feat-mte4-v5-12-232a648e63c6@gmail.com>","date":"2026-05-04T15:50:45","name":"[v5,12/15] target/arm: tag is not a part of PAuth with MTX","commit_ref":null,"pull_url":null,"state":"new","archived":false,"hash":"b00f11511c5998201aa4a1d0e2de83d25dc5a836","submitter":{"id":91863,"url":"http://patchwork.ozlabs.org/api/1.1/people/91863/?format=json","name":"Gabriel Brookman","email":"brookmangabriel@gmail.com"},"delegate":null,"mbox":"http://patchwork.ozlabs.org/project/qemu-devel/patch/20260504-feat-mte4-v5-12-232a648e63c6@gmail.com/mbox/","series":[{"id":502688,"url":"http://patchwork.ozlabs.org/api/1.1/series/502688/?format=json","web_url":"http://patchwork.ozlabs.org/project/qemu-devel/list/?series=502688","date":"2026-05-04T15:50:33","name":"target/arm: add support for MTE4","version":5,"mbox":"http://patchwork.ozlabs.org/series/502688/mbox/"}],"comments":"http://patchwork.ozlabs.org/api/patches/2232508/comments/","check":"pending","checks":"http://patchwork.ozlabs.org/api/patches/2232508/checks/","tags":{},"headers":{"Return-Path":"<qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org>","X-Original-To":"incoming@patchwork.ozlabs.org","Delivered-To":"patchwork-incoming@legolas.ozlabs.org","Authentication-Results":["legolas.ozlabs.org;\n\tdkim=pass (2048-bit key;\n unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256\n header.s=20251104 header.b=ZzuGG8ZD;\n\tdkim-atps=neutral","legolas.ozlabs.org;\n spf=pass (sender SPF authorized) smtp.mailfrom=nongnu.org\n (client-ip=209.51.188.17; helo=lists1p.gnu.org;\n envelope-from=qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org;\n receiver=patchwork.ozlabs.org)"],"Received":["from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17])\n\t(using TLSv1.2 with cipher ECDHE-ECDSA-AES256-GCM-SHA384 (256/256 bits))\n\t(No client certificate requested)\n\tby legolas.ozlabs.org (Postfix) with ESMTPS id 4g8R4K13dQz1yJ0\n\tfor <incoming@patchwork.ozlabs.org>; Tue, 05 May 2026 01:52:49 +1000 (AEST)","from localhost ([::1] helo=lists1p.gnu.org)\n\tby lists1p.gnu.org with esmtp (Exim 4.90_1)\n\t(envelope-from <qemu-devel-bounces@nongnu.org>)\n\tid 1wJva2-00013Q-H8; Mon, 04 May 2026 11:51:34 -0400","from eggs.gnu.org ([2001:470:142:3::10])\n by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256)\n (Exim 4.90_1) (envelope-from <brookmangabriel@gmail.com>)\n id 1wJvZx-00010w-TL\n for qemu-devel@nongnu.org; Mon, 04 May 2026 11:51:30 -0400","from mail-qt1-x82f.google.com ([2607:f8b0:4864:20::82f])\n by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128)\n (Exim 4.90_1) (envelope-from <brookmangabriel@gmail.com>)\n id 1wJvZv-0006FR-HA\n for qemu-devel@nongnu.org; Mon, 04 May 2026 11:51:28 -0400","by mail-qt1-x82f.google.com with SMTP id\n d75a77b69052e-50d6b9bca48so61862291cf.2\n for <qemu-devel@nongnu.org>; Mon, 04 May 2026 08:51:27 -0700 (PDT)","from [192.168.1.164] ([2600:1009:a021:c665:5296:905f:3e4a:eb90])\n by smtp.gmail.com with ESMTPSA id\n d75a77b69052e-51040931552sm99599011cf.12.2026.05.04.08.51.24\n (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);\n Mon, 04 May 2026 08:51:25 -0700 (PDT)"],"DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed;\n d=gmail.com; s=20251104; t=1777909886; x=1778514686; darn=nongnu.org;\n h=cc:to:in-reply-to:references:message-id:content-transfer-encoding\n :mime-version:subject:date:from:from:to:cc:subject:date:message-id\n :reply-to; bh=KsGoT0ZY/Rv32gk7xNMn1j9Shl8qcLertbKSdgPbnPQ=;\n b=ZzuGG8ZDueG/nOzu4oiFxMeOz/814xHu/advCcwzfGjN7n6wexJW3RbA5O1AvIJGUn\n e4gcHZis2eB3qUV+wSUasFCVtIfcxiVktD9q2Ld7GVLdE1xPX2ahywL6ccThoOgEhBMr\n KeFMvCp7Pz0R9LvA68CJheqhT2kkbm+Wz3dCf6HAR2HmNDKTFnNsAK+JeG3CjzTz5VsG\n u1SmSK32oWinJpGikYcVQ0oS1JOw/f3W4M6xGAzsYTdf0kWgbcyEYtFUO5jH+q6Jf/IN\n WAbJCsOiKzHft2CmVJ92SvEdovM9Eb2bdvQDB6B52G98T7WA3dkOI0g7c2/Jx8qKSYgw\n 0DHw==","X-Google-DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed;\n d=1e100.net; s=20251104; t=1777909886; x=1778514686;\n h=cc:to:in-reply-to:references:message-id:content-transfer-encoding\n :mime-version:subject:date:from:x-gm-gg:x-gm-message-state:from:to\n :cc:subject:date:message-id:reply-to;\n bh=KsGoT0ZY/Rv32gk7xNMn1j9Shl8qcLertbKSdgPbnPQ=;\n b=q2TnlioiIcuvM0lhXhwcAXITsf0tOI53E48N9gixsx+PCCtyfXXg2qCerUPezTHmj2\n STV5xc0G0kpxuVxgnDQAHpBQdQ01PmksqxaY8lbyNCyoZx1sozoLdY0TvLBjGLkgQemG\n PGO4bk58TcziEsMMiBsDtGksO/H2VkT6uFzEmSKkV+GC8NUBD7YMGYPbubJ476W9A1f6\n 48PESigvW+EesP6YdqWvqWJGH8K4oIQkU9wDuEjhpuJ/DyB0iiZzo6g+pwd98n6IC3Fs\n JG5eNAn1FSnj4KzFuBP2Ll+LkbvVwBaS58EQMs27/Mpe6ytqt7ZFHRhud7hiq8nnYZ6r\n a3nQ==","X-Gm-Message-State":"AOJu0Yy5T77p8N7H5F0drE/i14cUdIA3QOjDbJLyrJPAt4qScEnm0LxK\n S7vq2iCfF6KHL9OWZycWELgsB0pLCWJ7W5P324EHMvU4CWb78/yWxfCy","X-Gm-Gg":"AeBDiesfHm6iqULptuwqZkwV10JINZmktg2YKxXaGkAGxHZkdJ9XK4GVEEweT26kOAB\n VxO74PK/7vji65Ue56EX5P8WRXyRXS/z1uimS3Bmjo/hdH0YdCNOgFgLPn1NKi7+pxLJPKn0efa\n dCz2dS4hpNSS9IyrNwSkVMXNXv75+E1Eq/EXW4e/Zw0roJ7tgJ53RQDMTa4A9VrDrduTDnpL8Fq\n IessP1tLr+VrdRiJErtZPodMPtLyfdW4F+NYCRzF0VwPp0o7goSM+hpJMk47dBbrRZ1mQprHaNr\n /GzRUj89RPq8FhxVArIgss5aXkPfe7eJNkzRU9gY7vYZqXq9iI7vwVBz7UlUiePvUyO+oUmHzfq\n NQPiNUUJUUmwiQ4BqLAMryP2sb50h4STAy2t6cLQo2tj7BCr0OTUiB/6l82IUmFkZAP5i+owuxD\n Rb1GjHSc8x4qALju1L88Z9cAStLj7AYh2SbJ9UMIaqs235PIL7TZE=","X-Received":"by 2002:ac8:7dce:0:b0:50b:1adf:89ba with SMTP id\n d75a77b69052e-5104bf74fd1mr150008201cf.40.1777909886538;\n Mon, 04 May 2026 08:51:26 -0700 (PDT)","From":"Gabriel Brookman <brookmangabriel@gmail.com>","Date":"Mon, 04 May 2026 11:50:45 -0400","Subject":"[PATCH v5 12/15] target/arm: tag is not a part of PAuth with MTX","MIME-Version":"1.0","Content-Type":"text/plain; charset=\"utf-8\"","Content-Transfer-Encoding":"7bit","Message-Id":"<20260504-feat-mte4-v5-12-232a648e63c6@gmail.com>","References":"<20260504-feat-mte4-v5-0-232a648e63c6@gmail.com>","In-Reply-To":"<20260504-feat-mte4-v5-0-232a648e63c6@gmail.com>","To":"qemu-devel@nongnu.org","Cc":"Peter Maydell <peter.maydell@linaro.org>,\n Gustavo Romero <gustavo.romero@linaro.org>,\n Richard Henderson <richard.henderson@linaro.org>, qemu-arm@nongnu.org,\n Laurent Vivier <laurent@vivier.eu>,\n Gabriel Brookman <brookmangabriel@gmail.com>, Helge Deller <deller@gmx.de>,\n Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>,\n Pierrick Bouvier <pierrick.bouvier@oss.qualcomm.com>","X-Mailer":"b4 0.15.2","X-Developer-Signature":"v=1; a=ed25519-sha256; t=1777909867; l=3109;\n i=brookmangabriel@gmail.com; s=20251009; h=from:subject:message-id;\n bh=i7naSFKtsdz7oJ/mLAV3eXUKurGnggfA0UJX9vwXyVE=;\n b=beRiuMoGUh2trILB0UOertQUMc/zy6fknjcq7gSUZHgKun0WCnuuWwBVfNhaJW7+EirEeH2lY\n 1/4idKjmpHAD3FtHMGyqprB+YkcsbXSUDzwf8gwybtQgDXPwEG13OfQ","X-Developer-Key":"i=brookmangabriel@gmail.com; a=ed25519;\n pk=m9TtPDal6WzoHNnQiHHKf8dTrv3DUCPUUTujuo8vNrw=","Received-SPF":"pass client-ip=2607:f8b0:4864:20::82f;\n envelope-from=brookmangabriel@gmail.com; helo=mail-qt1-x82f.google.com","X-Spam_score_int":"-10","X-Spam_score":"-1.1","X-Spam_bar":"-","X-Spam_report":"(-1.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1,\n DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FORGED_GMAIL_RCVD=1,\n FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001,\n SPF_PASS=-0.001 autolearn=no autolearn_force=no","X-Spam_action":"no action","X-BeenThere":"qemu-devel@nongnu.org","X-Mailman-Version":"2.1.29","Precedence":"list","List-Id":"qemu development <qemu-devel.nongnu.org>","List-Unsubscribe":"<https://lists.nongnu.org/mailman/options/qemu-devel>,\n <mailto:qemu-devel-request@nongnu.org?subject=unsubscribe>","List-Archive":"<https://lists.nongnu.org/archive/html/qemu-devel>","List-Post":"<mailto:qemu-devel@nongnu.org>","List-Help":"<mailto:qemu-devel-request@nongnu.org?subject=help>","List-Subscribe":"<https://lists.nongnu.org/mailman/listinfo/qemu-devel>,\n <mailto:qemu-devel-request@nongnu.org?subject=subscribe>","Errors-To":"qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org","Sender":"qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org"},"content":"As described in the section on MTX, tag bits should not be used to store\nor compute the PAC when MTX is set. See also Authenticate(),\nInsertPAC(), and Strip().\n\nSigned-off-by: Gabriel Brookman <brookmangabriel@gmail.com>\n---\n target/arm/internals.h        | 12 +++++++++++-\n target/arm/tcg/pauth_helper.c | 18 +++++++++++++++++-\n 2 files changed, 28 insertions(+), 2 deletions(-)","diff":"diff --git a/target/arm/internals.h b/target/arm/internals.h\nindex d313d36603..31b7e1c85e 100644\n--- a/target/arm/internals.h\n+++ b/target/arm/internals.h\n@@ -1809,7 +1809,17 @@ static inline uint64_t pauth_ptr_mask(ARMVAParameters param)\n     int bot_pac_bit = 64 - param.tsz;\n     int top_pac_bit = 64 - 8 * param.tbi;\n \n-    return MAKE_64BIT_MASK(bot_pac_bit, top_pac_bit - bot_pac_bit);\n+    uint64_t mask = MAKE_64BIT_MASK(bot_pac_bit, top_pac_bit - bot_pac_bit);\n+\n+    /*\n+     * If mtx is enabled, second nibble is not part of PAC. See\n+     * InsertPAC().\n+     */\n+    if (param.mtx) {\n+        mask &= ~MAKE_64BIT_MASK(56, 4);\n+    }\n+\n+    return mask;\n }\n \n /* Add the cpreg definitions for debug related system registers */\ndiff --git a/target/arm/tcg/pauth_helper.c b/target/arm/tcg/pauth_helper.c\nindex 67c0d59d9e..3d83ca4c3c 100644\n--- a/target/arm/tcg/pauth_helper.c\n+++ b/target/arm/tcg/pauth_helper.c\n@@ -342,9 +342,16 @@ static uint64_t pauth_addpac(CPUARMState *env, uint64_t ptr, uint64_t modifier,\n     }\n \n     /* Build a pointer with known good extension bits.  */\n-    top_bit = 64 - 8 * param.tbi;\n+    top_bit = 64 - 8 * (param.tbi || param.mtx);\n     bot_bit = 64 - param.tsz;\n     ext_ptr = deposit64(ptr, bot_bit, top_bit - bot_bit, ext);\n+    /*\n+     * If mtx is active but not tbi, then the top 4 bits are replaced with the\n+     * ext bit, while leaving bits 56-59 alone. See InsertPAC().\n+     */\n+    if (param.mtx && !param.tbi) {\n+        ext_ptr = deposit64(ext_ptr, 60, 4, ext);\n+    }\n \n     pac = pauth_computepac(env, ext_ptr, modifier, *key);\n \n@@ -377,6 +384,11 @@ static uint64_t pauth_addpac(CPUARMState *env, uint64_t ptr, uint64_t modifier,\n     if (param.tbi) {\n         ptr &= ~MAKE_64BIT_MASK(bot_bit, 55 - bot_bit + 1);\n         pac &= MAKE_64BIT_MASK(bot_bit, 54 - bot_bit + 1);\n+    } else if (param.mtx) {\n+        ptr &= ~(MAKE_64BIT_MASK(60, 4) |\n+                 MAKE_64BIT_MASK(bot_bit, 55 - bot_bit + 1));\n+        pac &= MAKE_64BIT_MASK(60, 4) |\n+               MAKE_64BIT_MASK(bot_bit, 54 - bot_bit + 1);\n     } else {\n         ptr &= MAKE_64BIT_MASK(0, bot_bit);\n         pac &= ~(MAKE_64BIT_MASK(55, 1) | MAKE_64BIT_MASK(0, bot_bit));\n@@ -424,6 +436,10 @@ static uint64_t pauth_auth(CPUARMState *env, uint64_t ptr, uint64_t modifier,\n     cmp_mask = MAKE_64BIT_MASK(bot_bit, top_bit - bot_bit);\n     cmp_mask &= ~MAKE_64BIT_MASK(55, 1);\n \n+    if (param.mtx) {\n+        cmp_mask &= ~MAKE_64BIT_MASK(56, 4);\n+    }\n+\n     if (pauth_feature >= PauthFeat_2) {\n         ARMPauthFeature fault_feature =\n             is_combined ? PauthFeat_FPACCOMBINED : PauthFeat_FPAC;\n","prefixes":["v5","12/15"]}