mirror of
https://github.com/hrydgard/ppsspp.git
synced 2026-10-01 14:58:14 +00:00
RiscVRegCache::FlushBeforeCall claimed the caller-saved X and F registers "match between X0 and F0". They don't: X0-X4 are zero/ra/sp/gp/tp and are never allocated, but F0-F4 (ft0-ft4) are caller-saved and are in the FPR allocation order. A block that spilled into them and then called out (for vsin or vcos, say) had the callee destroy registers the cache still thought were live and dirty. LoongArch and arm64 get this right. The LoongArch signed div-by-zero sequence applied its ADDI_D(-1) after the jump target, so it ran on both paths: a negative numerator ended up with a quotient of 0 instead of 1, and a non-negative one borrowed into the remainder in the high half, giving hi = num - 1. Insert the -1 into the low word rather than subtracting, and branch around the other case. FCvtScaledWS loaded 0x7FFFFFFF into SCRATCHF1 and then immediately overwrote it with the multiplier, while the FSELs picked SCRATCHF2 - a register the function never writes. A NAN input produced whatever was left there. Also: - RISC-V had no SyscallUnresolved case, falling through to INVALIDOP, which is a live assert in release builds. Added it, matching arm64. - applyRoundingMode_ fed fcr31 straight to FSRM, which only takes three bits - the flags at 2-6 could turn a mode of 0 into 4. Mask with 3 first, as MIPS.cpp and LoongArch64Asm.cpp do. - OverwriteExit lacked arm64's assert that the exit fits the 8-byte hole, which matters more here since QuickJ is 4, 8 or 12 bytes. - Both backends allocated the FMin/FMax temp GPR inside the conditional NAN path, where a spill store would only run on one side while the regcache assumed it always ran. Hoisted above the branch. Both backends build now, and pspautotests and the unit tests pass under qemu on each - but nothing in the suite reaches the paths above, so the two worth checking were checked by running the emitted sequences directly. The div-by-zero one is wrong for all eight numerators tried and right for all eight after. The rounding one turns a guest mode of 0 into RMM whenever fcr31 has its inexact flag set, so 0.5 converts to 1 rather than 0. The rest are still by inspection: they need register pressure, an unresolved import, or a debug build to reach. Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>