Commit 653b0c06c8 for qemu.org

commit 653b0c06c83d761667474b29ebfb8a312f317c3a
Author: Jean-Francois Bortolotti <jeff@borto.fr>
Date:   Sat Sep 26 01:41:36 2026 +0200

    target/arm: Fix PMSAv8 shareability decode for R-profile MPU regions

    In Armv8-R AArch32 the shareability field of an MPU region lives in
    PRBAR, not PRLAR:

      PRBAR: [31:6] BASE  [5] RES0  [4:3] SH  [2:1] AP  [0] XN
      PRLAR: [31:6] LIMIT [5:4] RES0  [3:1] AttrIndx  [0] EN

    (Arm Cortex-R52 TRM 100026_0103_00_en: Tables 3-80 and 3-83 for
    HPRBAR/HPRLAR, Tables 3-124 and 3-127 for PRBAR/PRLAR.)

    Without this fix, address translation instructions like ATS1HR
    will return wrong value for PAR.SH.

    Cc: qemu-stable@nongnu.org
    Fixes: fca45e3467f7 ("target/arm: Add PMSAv8r functionality")
    Signed-off-by: Jean-Francois Bortolotti <jeff@borto.fr>
    Message-id: 20260925234136.1182108-1-jeff@borto.fr
    Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
    Signed-off-by: Peter Maydell <peter.maydell@linaro.org>

diff --git a/target/arm/ptw.c b/target/arm/ptw.c
index f537502d3b..de0435a58b 100644
--- a/target/arm/ptw.c
+++ b/target/arm/ptw.c
@@ -3092,7 +3092,7 @@ bool pmsav8_mpu_lookup(CPUARMState *env, uint32_t address,
         if (!arm_feature(env, ARM_FEATURE_M)) {
             uint8_t attrindx = extract32(matched_rlar, 1, 3);
             uint64_t mair = env->cp15.mair_el[regime_el(mmu_idx)];
-            uint8_t sh = extract32(matched_rlar, 3, 2);
+            uint8_t sh = extract32(matched_rbar, 3, 2);

             if (regime_sctlr(env, mmu_idx) & SCTLR_WXN &&
                 result->f.prot & PAGE_WRITE && mmu_idx != ARMMMUIdx_Stage2) {