From nobody Sun Jul 26 10:59:31 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=gmail.com ARC-Seal: i=1; a=rsa-sha256; t=1783257543; cv=none; d=zohomail.com; s=zohoarc; b=EPFGWX2gagTKnrH0RT9zHoKAn7A1sqiGX0CneK9TlHFCZ/OPsR+mh2ccDXs8fu6/A8Vvm5+08U8fOpS3WslY5TC9FiFrzc+F8pz9SJioHY5hYztPmAs1Wd4OSP6QRAMN/FGPui0DZMa+l2P7srJef0mnWCmlfzDbDC5j57HNk4c= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783257543; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=3iQ6foKp7BWXNI7l7JdIldcj04hpvpDIkEePupB9eIQ=; b=PNLTAzBfMd3VE0TVFR8a1ef20v5Msd2+ukzw2uyFYvGWKm1T8m5AvjMMKF59SmqMyNf6TFMgxo1lj1quAP6UaSj0aWMmp5S8w/qV6XMjo14/QT/vVJc7/WiUec4ul9oq76C7gdygcLwVJEqXCSBQihSpvwGCXjx5FjO4617yIA4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783257543324835.4599563216859; Sun, 5 Jul 2026 06:19:03 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wgMja-0002KA-83; Sun, 05 Jul 2026 09:18:10 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgMjX-0002Jd-Vm for qemu-devel@nongnu.org; Sun, 05 Jul 2026 09:18:07 -0400 Received: from mail-wm1-x329.google.com ([2a00:1450:4864:20::329]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wgMjV-0003pp-RP for qemu-devel@nongnu.org; Sun, 05 Jul 2026 09:18:07 -0400 Received: by mail-wm1-x329.google.com with SMTP id 5b1f17b1804b1-493ba701891so16298615e9.3 for ; Sun, 05 Jul 2026 06:18:04 -0700 (PDT) Received: from user-Legion-Pro-5-16ARX8.. (cable-94-189-254-58.dynamic.sbb.rs. [94.189.254.58]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-493ccd9d607sm259916135e9.2.2026.07.05.06.18.00 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 05 Jul 2026 06:18:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1783257483; x=1783862283; darn=nongnu.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=3iQ6foKp7BWXNI7l7JdIldcj04hpvpDIkEePupB9eIQ=; b=poaQrKri+3Fu+zOE//3MG5qV8kAkwGsqKRDOWI0YPxQXR1gZ+9SfnYxHjRhQx296/2 jrpPNJponyqhVczUTLpQEUaxRvO5ZhcMVT9Qo4x7B0lvgi/3kYbGJ+T9SRk3vTjC5QYO gFgiuAcSSyr54luC7ELLa37tPUf6RFviU6skqEl9frWV86x4KopIDoPKLlSvGc2etCf+ RXj1Wmo1YwzwL9Ycv1uKKbcWG22ZLZi2n336jf9RpbIn02yJcpPv30QAo42SQuvZfNB+ rfncCTR90YVJw8j/YvBHVTTbG1/hXxlXmMKcC0rELkx5KuLkWDZSAhP7ZQ6kRvsPLroa NKmw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783257483; x=1783862283; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=3iQ6foKp7BWXNI7l7JdIldcj04hpvpDIkEePupB9eIQ=; b=WDCX0301t3t0RVsL2PbErqnR8z8k011wJNWQ02pucqS9LoPpMf1e//FoQI/yPpo3u4 andtJZCe4CpNBE3YVj97IaR43V/T9TCsBzQCz9fcLxQDFPuMTdcKdqAYYgR4ftp7OByQ Vs1QjESyyadAvjG2iFfmks8f97z/1122ixL1CcOt4INtCgpqgupbD497mEqGFCWPgTna G17kZFF4pJ72whnMX6N5jW/D1JaYgR8wfZSMfIjGPDIEYZkfYudZ2g0R1DFlkQoEtu8X 09ticKrtlihTx+2QBZg5GHbH4BRzUocfFi5pd/nNsyGvwmqtNed6v3H6gu29Eb3a+y2j JeZg== X-Forwarded-Encrypted: i=1; AFNElJ8pODMcM4Dqf7vNvG/kJcajyibVQsblIx/jm3ms7dXR1a+vCVwVcHrn7AxKc4KE+nsSvUhn+3EuErIY@nongnu.org X-Gm-Message-State: AOJu0Yx0LwC1NXZL90JbJT2IOxrQM6mGTx4tLUMtA49DGjLC6SrH6WIZ lpsBDBCZzTw6BYNXcwxuJNstsiKE3LS947hioTw5p+QHQizOCgqG5Ysj X-Gm-Gg: AfdE7ckmMQ2xaJ5NaInj6fr+VnYkMRCNc7/YZSuz+IZTghYR2xeMpU6fSEDFXbxGx3K Py0pke2GhktlmjFAVEdxJPxGwnFQirUmCFaMHH1qCOqAucw9QpLd672OsnBMx4UooaeRgv5DrL2 JQTtfQ9C7N6eGJk3z1TRfMWHLHNPZLd0a+V83L/i8duTACEHg+V7Jwkc7lSLvaYVeGqkoviDwjE jgYMs3SjbuKYxnEa1kYPAa2bZG6dkszjtX/+3g7m15wurRzEzNcnYcU9OACO42TuPK7MBSEGOks fuZUJXC4FFKfsZTsnj6SjmxN3wlE17t3cRs1ABiCj3BksxmINa8l+UeG8mt78LPtZTuQAWGriVo 9rMYMGxgBvbE4AG8P1hFbXb9fI7i6nwoUrdXBA6GGRlxvY6yWFkw/0KR1mboCaXOSz4DoZt+bB4 uzfoZ4J1Ua63qp1VPpyYBXuBKGJoYKY6+aq7aJDFP0CWoCpOGCLQaInKGfsMH36uvzg3O0 X-Received: by 2002:a05:600c:529a:b0:493:b7cb:c5f with SMTP id 5b1f17b1804b1-493d11d7f58mr79902045e9.11.1783257482717; Sun, 05 Jul 2026 06:18:02 -0700 (PDT) From: imaginos To: Palmer Dabbelt , Alistair Francis Cc: Weiwei Li , Daniel Henrique Barboza , Liu Zhiwei , Chao Liu , qemu-riscv@nongnu.org, qemu-devel@nongnu.org, imaginos Subject: [PATCH] target/riscv: check G-stage write permission for VS-stage A/D updates Date: Sun, 5 Jul 2026 15:16:40 +0200 Message-ID: <20260705131734.13792-1-imaginos32@gmail.com> X-Mailer: git-send-email 2.43.0 MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::329; envelope-from=imaginos32@gmail.com; helo=mail-wm1-x329.google.com X-Spam_score_int: -17 X-Spam_score: -1.8 X-Spam_bar: - X-Spam_report: (-1.8 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @gmail.com) X-ZM-MESSAGEID: 1783257544262158500 Content-Type: text/plain; charset="utf-8" During a two-stage (VS-stage + G-stage) page-table walk with hardware A/D updating enabled (Svadu / menvcfg.ADUE), a store that reaches a VS-stage leaf PTE whose accessed or dirty bit is clear triggers a hardware write-back of those bits into the PTE. That write-back is an implicit store to the PTE's guest-physical address, so it must be permitted by G-stage. Fix this by re-running the G-stage translation of the guest PTE's address with store semantics. get_physical_address() then also checks that G-stage permits the guest PTE to be written, and raises a guest-page store fault when it does not. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3426 Signed-off-by: imaginos --- target/riscv/cpu_helper.c | 28 ++++++++++++++++++++++++++++ 1 file changed, 28 insertions(+) Verified against Spike, with this patch QEMU's reported values match Spike. Spike (reference): QEMU, before this patch: mcause 0x17 mcause 0x17 mtval 0x80000000 mtval 0x80000000 mtval2 0x20001004 mtval2 0x20000000 mtinst 0x3020 mtinst 0x6a704073 If I've misread any of the A/D-update semantics here, I'd appreciate the correction. diff --git a/target/riscv/cpu_helper.c b/target/riscv/cpu_helper.c index 2db07f5dfb..3b4d2aea96 100644 --- a/target/riscv/cpu_helper.c +++ b/target/riscv/cpu_helper.c @@ -1370,6 +1370,7 @@ static int get_physical_address(CPURISCVState *env, h= waddr *physical, int ptshift; target_ulong pte; hwaddr pte_addr; + hwaddr pte_gpa =3D 0; const hwaddr base_root =3D base; const bool be =3D mo_endian_env(env) =3D=3D MO_BE; int i; @@ -1407,6 +1408,7 @@ static int get_physical_address(CPURISCVState *env, h= waddr *physical, } =20 pte_addr =3D vbase + idx * ptesize; + pte_gpa =3D base + idx * ptesize; } else { pte_addr =3D base + idx * ptesize; } @@ -1661,6 +1663,28 @@ static int get_physical_address(CPURISCVState *env, = hwaddr *physical, return TRANSLATE_FAIL; } =20 + /* + * The implicit store that writes updated A/D bits back to a VS-st= age + * (first-stage) PTE must itself be permitted by G-stage. Re-run t= he + * second-stage translation of the PTE's guest-physical address wi= th + * store semantics; if G-stage denies write, G-stage store fault + * against the PTE address. + */ + if (two_stage && first_stage) { + int gpa_prot; + hwaddr gpa_paddr; + int gpa_ret =3D get_physical_address(env, &gpa_paddr, &gpa_pro= t, + pte_gpa, NULL, MMU_DATA_STO= RE, + MMUIdx_U, false, true, + is_debug, false); + if (gpa_ret !=3D TRANSLATE_SUCCESS) { + if (fault_pte_addr) { + *fault_pte_addr =3D pte_gpa >> 2; + } + return TRANSLATE_G_STAGE_FAIL; + } + } + pmp_ret =3D get_physical_address_pmp(env, &pmp_prot, pte_addr, sxlen_bytes, MMU_DATA_STORE, PR= V_S); if (pmp_ret !=3D TRANSLATE_SUCCESS) { @@ -2345,6 +2369,10 @@ void riscv_cpu_do_interrupt(CPUState *cs) * doing VS-stage page table walk. */ tinst =3D (riscv_cpu_xlen(env) =3D=3D 32) ? 0x00002000 : 0= x00003000; + + if (cause =3D=3D RISCV_EXCP_STORE_GUEST_AMO_ACCESS_FAULT) { + tinst |=3D 0x20; + } } else { /* * The "Addr. Offset" field in transformed instruction is --=20 2.43.0