Re: [PATCH] arm64/boot: Don't set PMUv3p9 FGT2 bits without PMUv3

From: Catalin Marinas

Date: Fri Oct 02 2026 - 10:53:10 EST


On Fri, Oct 02, 2026 at 03:00:42PM +0100, Will Deacon wrote:
> On Fri, Oct 02, 2026 at 02:54:47PM +0100, Fuad Tabba wrote:
> > On Fri, Oct 02, 2026 at 02:29:26PM +0100, Will Deacon wrote:
> > > Are you sure #8 is the correct immediate for the ccmp? My reading of the
> > > pseudocode is that it should be #9, but this instruction has always confused
> > > me and I hate the fact that it doesn't take another condition code mnemonic
> > > instead of a raw immediate value.
> >
> > My read is that #8 is right. From the CCMP (immediate) pseudocode in the
> > Arm ARM (DDI 0487 M.d, C6.2.81), flags start out as the nzcv immediate
> > and are only overwritten by the compare when the condition holds:
> >
> > var flags : bits(4) = nzcv;
> > ...
> > if ConditionHolds(condition) then
> > ...
> > (-, flags) = AddWithCarry{datasize}(operand1, NOT operand2, '1');
> > end;
> > PSTATE.[N,Z,C,V] = flags;
> >
> > So when PMUVer == IMP_DEF the ne fails and NZCV = 0b1000, i.e. N=1, V=0.
> > LT is N != V (Table C1-1), so b.lt is taken and we skip. #9 would give
> > N=1, V=1, so we'd fall through and set the bits on an IMP_DEF PMU.
>
> Aha, that table is pretty helpful, thanks.
>
> I think you're right -- I missed the inversion at the end of
> ConditionHolds().
>
> I'll pick this up next week.

I couldn't figure out the #8 either. I wonder whether it's more readable
as (untested):

sub x1, x1, #ID_AA64DFR0_EL1_PMUVer_V3P9
cmp x1, #(ID_AA64DFR0_EL1_PMUVer_IMP_DEF - ID_AA64DFR0_EL1_PMUVer_V3P9)
b.hs .Lskip_pmuv3p9_\@ // Skip unless V3P9 <= PMUVer < IMP_DEF

The first sub either gives us a large number (negative but we do the
unsigned comparison with b.hs) or something between 0 and (15-9). The
cmp and the 'same' part of b.hs skip the (15-9) case.

--
Catalin