mirror of
https://github.com/dolphin-emu/dolphin.git
synced 2025-01-12 00:59:11 +01:00
989bdb8d6d
Fixes https://bugs.dolphin-emu.org/issues/12827. A description of what was going wrong: JitArm64::Init first calls CodeBlock::AllocCodeSpace, after which CodeBlock and Arm64Emitter consider us to have 96 MB of code space available. JitArm64::Init then calls AddChildCodeSpace, which is supposed to take 64 MiB of that space and give it to m_far_code. CodeBlock's view of how much space there is gets updated from 96 MiB to 32 MiB, but due to the missing call, Arm64Emitter keeps thinking that it has 96 MiB of space available. The last thing JitArm64::Init does is to call ResetFreeMemoryRanges. This function asks Arm64Emitter how much code space is available and stores a range of that size in m_free_ranges_near, meaning that m_free_ranges_near ends up being backed by both nearcode and farcode! This is a ticking time bomb; as soon as we grab memory from m_free_ranges_near which is backed by farcode, we're in trouble. The crash I ran into in my testing was caused by fastmem code being allocated in farcode (our backpatch handler only handles accesses made from nearcode), but you may as well get errors caused by code intended for nearcode overwriting code intended for farcode or vice versa. So why did NBA Live 2005 crash when most games had no problems, and why was the bug bisected to the commit that increased the size of far code from 16 MiB to 64 MiB? Well, as long as we're only using the first 32 MiB of the big 96 MiB range, everything works. What happens with NBA Live 2005 (I have not investigated exactly through what mechanism this happens) is that at some point the range in m_free_ranges_near gets split into two ranges, one which is backed by nearcode and one which is backed by farcode. Dolphin prefers to select the biggest range available (we don't want to pick a tiny 1 KiB range that may not be able to fit the whole block we're about to emit, after all), and after increasing the size of farcode to 64 MiB, farcode is bigger than nearcode.
122 lines
3.6 KiB
C++
122 lines
3.6 KiB
C++
// Copyright 2014 Dolphin Emulator Project
|
|
// SPDX-License-Identifier: GPL-2.0-or-later
|
|
|
|
#pragma once
|
|
|
|
#include <cstddef>
|
|
#include <vector>
|
|
|
|
#include "Common/Assert.h"
|
|
#include "Common/CommonTypes.h"
|
|
#include "Common/MemoryUtil.h"
|
|
|
|
namespace Common
|
|
{
|
|
// Everything that needs to generate code should inherit from this.
|
|
// You get memory management for free, plus, you can use all emitter functions without
|
|
// having to prefix them with gen-> or something similar.
|
|
// Example implementation:
|
|
// class JIT : public CodeBlock<ARMXEmitter> {}
|
|
template <class T>
|
|
class CodeBlock : public T
|
|
{
|
|
private:
|
|
// A privately used function to set the executable RAM space to something invalid.
|
|
// For debugging usefulness it should be used to set the RAM to a host specific breakpoint
|
|
// instruction
|
|
virtual void PoisonMemory() = 0;
|
|
|
|
protected:
|
|
u8* region = nullptr;
|
|
// Size of region we can use.
|
|
size_t region_size = 0;
|
|
// Original size of the region we allocated.
|
|
size_t total_region_size = 0;
|
|
|
|
bool m_is_child = false;
|
|
std::vector<CodeBlock*> m_children;
|
|
|
|
public:
|
|
CodeBlock() = default;
|
|
virtual ~CodeBlock()
|
|
{
|
|
if (region)
|
|
FreeCodeSpace();
|
|
}
|
|
CodeBlock(const CodeBlock&) = delete;
|
|
CodeBlock& operator=(const CodeBlock&) = delete;
|
|
CodeBlock(CodeBlock&&) = delete;
|
|
CodeBlock& operator=(CodeBlock&&) = delete;
|
|
|
|
// Call this before you generate any code.
|
|
void AllocCodeSpace(size_t size)
|
|
{
|
|
region_size = size;
|
|
total_region_size = size;
|
|
region = static_cast<u8*>(Common::AllocateExecutableMemory(total_region_size));
|
|
T::SetCodePtr(region, region + size);
|
|
}
|
|
|
|
// Always clear code space with breakpoints, so that if someone accidentally executes
|
|
// uninitialized, it just breaks into the debugger.
|
|
void ClearCodeSpace()
|
|
{
|
|
PoisonMemory();
|
|
ResetCodePtr();
|
|
}
|
|
|
|
// Call this when shutting down. Don't rely on the destructor, even though it'll do the job.
|
|
void FreeCodeSpace()
|
|
{
|
|
ASSERT(!m_is_child);
|
|
Common::FreeMemoryPages(region, total_region_size);
|
|
region = nullptr;
|
|
region_size = 0;
|
|
total_region_size = 0;
|
|
for (CodeBlock* child : m_children)
|
|
{
|
|
child->region = nullptr;
|
|
child->region_size = 0;
|
|
child->total_region_size = 0;
|
|
}
|
|
}
|
|
|
|
bool IsInSpace(const u8* ptr) const { return ptr >= region && ptr < (region + region_size); }
|
|
// Cannot currently be undone. Will write protect the entire code region.
|
|
// Start over if you need to change the code (call FreeCodeSpace(), AllocCodeSpace()).
|
|
void WriteProtect() { Common::WriteProtectMemory(region, region_size, true); }
|
|
void ResetCodePtr() { T::SetCodePtr(region, region + region_size); }
|
|
size_t GetSpaceLeft() const
|
|
{
|
|
ASSERT(static_cast<size_t>(T::GetCodePtr() - region) < region_size);
|
|
return region_size - (T::GetCodePtr() - region);
|
|
}
|
|
|
|
bool IsAlmostFull() const
|
|
{
|
|
// This should be bigger than the biggest block ever.
|
|
return GetSpaceLeft() < 0x10000;
|
|
}
|
|
|
|
bool HasChildren() const { return region_size != total_region_size; }
|
|
u8* AllocChildCodeSpace(size_t child_size)
|
|
{
|
|
ASSERT_MSG(DYNA_REC, child_size < GetSpaceLeft(), "Insufficient space for child allocation.");
|
|
u8* child_region = region + region_size - child_size;
|
|
region_size -= child_size;
|
|
ResetCodePtr();
|
|
return child_region;
|
|
}
|
|
void AddChildCodeSpace(CodeBlock* child, size_t child_size)
|
|
{
|
|
u8* child_region = AllocChildCodeSpace(child_size);
|
|
child->m_is_child = true;
|
|
child->region = child_region;
|
|
child->region_size = child_size;
|
|
child->total_region_size = child_size;
|
|
child->ResetCodePtr();
|
|
m_children.emplace_back(child);
|
|
}
|
|
};
|
|
} // namespace Common
|