From nobody Fri Jul 24 04:55:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1784837087; cv=none; d=zohomail.com; s=zohoarc; b=Leoou0zCvZM4NYo5j/HbIJ9vRHR36fnLWY93z3FCxiKEPbaia3215bp+PQNl1rPxjjq5W+S2aYrJif2NbTYnxu9JfFuTXZH/QYjNAcli2yvQ3cc+tXNYw+4tv7WYCwQQgcx5r7vm4RKI6F10q27VWvTdzBolYwSDs7n5U1WwrZA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784837087; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=RLxpDskpUaW2SqFL1paaZz0BMuYJFC5aorXLL2bYB+g=; b=RfleSjQ/EJwgHHnq6KMm2Wx+H7EhCi985CdAlRFtihRNIymFS38tgjTdZHvU2OA4HK0HU27eaJK9YdwWtbDOVkGumuq00fnjeZiZTzdSWPmo/7phBgjFHBSquy4R8i6eTAIK8qN/w/b0SunWjaa7eV4GpFS+w2+s12T+YvIDoEY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784837087481721.9620765632428; Thu, 23 Jul 2026 13:04:47 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmzeN-0007Ql-Ts; Thu, 23 Jul 2026 16:04:12 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmzeH-0007OU-RG; Thu, 23 Jul 2026 16:04:06 -0400 Received: from [115.124.30.100] (helo=out30-100.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmzeA-0005Rk-Pv; Thu, 23 Jul 2026 16:04:05 -0400 Received: from localhost.localdomain(mailfrom:zhiwei_liu@linux.alibaba.com fp:SMTPD_---0X7h4Uu2_1784837018 cluster:ay36) by smtp.aliyun-inc.com; Fri, 24 Jul 2026 04:03:39 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1784837020; h=From:To:Subject:Date:Message-Id:MIME-Version; bh=RLxpDskpUaW2SqFL1paaZz0BMuYJFC5aorXLL2bYB+g=; b=CrCXpWydK7R3o1ZqU95iQVufIsOrswo8l40lXuptQfb+mmyz3voHSz80w1yxHT/b6gWO12SPBz0BWishJgJN+ObFVkHEbfYWz5O4lqekFk5w9z00cAN1rMJU54uja8Okz1oBzxaejxmy8dUCEJbuiODSJLnRQMnLQNJFR81Xifk= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R491e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033045098064; MF=zhiwei_liu@linux.alibaba.com; NM=1; PH=DS; RN=13; SR=0; TI=SMTPD_---0X7h4Uu2_1784837018; From: LIU Zhiwei To: qemu-devel@nongnu.org Cc: palmer@dabbelt.com, alistair.francis@wdc.com, daniel.barboza@oss.qualcomm.com, chao.liu.zevorn@gmail.com, liwei1518@gmail.com, qemu-riscv@nongnu.org, rahul@summations.net, xiangyi.zeng@linux.alibaba.com, cxx194832@alibaba-inc.com, LIU Zhiwei , Huang Tao , TANG Tiancheng Subject: [PATCH v8 01/11] target/riscv: Add basic definitions and CSRs for SMMPT Date: Fri, 24 Jul 2026 04:03:15 +0800 Message-Id: <20260723200325.24969-2-zhiwei_liu@linux.alibaba.com> X-Mailer: git-send-email 2.39.3 (Apple Git-146) In-Reply-To: <20260723200325.24969-1-zhiwei_liu@linux.alibaba.com> References: <20260723200325.24969-1-zhiwei_liu@linux.alibaba.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.100 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.100; envelope-from=zhiwei_liu@linux.alibaba.com; helo=out30-100.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1784837089279158500 Content-Type: text/plain; charset="utf-8" This patch lays the groundwork for the SMMPT (Supervisor Domains Access Protection) extension by introducing its fundamental components. It adds: - New CPU configuration flags, `ext_smmpt` and `ext_smsdid`, to enable the extension. - Bit-field definitions for the `mmpt` CSR in `cpu_bits.h`. - The `mmpt` and `msdcfg` CSR numbers and their read/write handlers in `csr.c`. - New fields in `CPUArchState` to store the state of these new CSRs. - A new translation failure reason `TRANSLATE_MPT_FAIL`. This provides the necessary infrastructure for the core MPT logic and MMU integration that will follow. Co-authored-by: Huang Tao Co-authored-by: TANG Tiancheng Signed-off-by: LIU Zhiwei --- target/riscv/cpu.h | 8 +++ target/riscv/cpu_bits.h | 24 ++++++++ target/riscv/cpu_cfg_fields.h.inc | 2 + target/riscv/riscv_smmpt.h | 21 +++++++ target/riscv/tcg/csr.c | 99 +++++++++++++++++++++++++++++++ 5 files changed, 154 insertions(+) create mode 100644 target/riscv/riscv_smmpt.h diff --git a/target/riscv/cpu.h b/target/riscv/cpu.h index c9dfa7daff..8825e1c186 100644 --- a/target/riscv/cpu.h +++ b/target/riscv/cpu.h @@ -139,6 +139,7 @@ enum { TRANSLATE_PMP_FAIL, TRANSLATE_G_STAGE_FAIL, TRANSLATE_PMA_FAIL, + TRANSLATE_MPT_FAIL }; =20 /* Extension context status */ @@ -184,6 +185,7 @@ extern RISCVCPUImpliedExtsRule *riscv_multi_ext_implied= _rules[]; =20 #if !defined(CONFIG_USER_ONLY) #include "tcg/pmp.h" +#include "riscv_smmpt.h" #endif =20 #define RV_VLEN_MAX 1024 @@ -521,6 +523,12 @@ struct CPUArchState { uint64_t rnmip; uint64_t rnmi_irqvec; uint64_t rnmi_excpvec; + + /* Smsdid */ + uint32_t mptmode; + uint32_t sdid; + uint64_t mptppn; + uint32_t msdcfg; #endif =20 /* Fields from here on are preserved across CPU reset. */ diff --git a/target/riscv/cpu_bits.h b/target/riscv/cpu_bits.h index 3f146a43fe..4ed4843e3d 100644 --- a/target/riscv/cpu_bits.h +++ b/target/riscv/cpu_bits.h @@ -1166,4 +1166,28 @@ typedef enum CTRType { #define MCONTEXT64 0x0000000000001FFFULL #define MCONTEXT32_HCONTEXT 0x0000007F #define MCONTEXT64_HCONTEXT 0x0000000000003FFFULL + +/* Smsdid */ +#define CSR_MMPT 0x382 +#define CSR_MSDCFG 0x74E + +/* + * MMPT register layout for MXLEN=3D32: + * MODE[31:30], 0[29:28], SDID[27:22], PPN[21:0] + */ +#define MMPT_MODE_MASK_32 0xC0000000 +#define MMPT_MODE_SHIFT_32 30 +#define MMPT_SDID_MASK_32 0x0FC00000 +#define MMPT_SDID_SHIFT_32 22 +#define MMPT_PPN_MASK_32 0x003FFFFF + +/* + * MMPT register layout for MXLEN=3D64: + * MODE[63:60], 0[59:58], SDID[57:52], 0[51:44], PPN[43:0] + */ +#define MMPT_MODE_MASK_64 0xF000000000000000ULL +#define MMPT_MODE_SHIFT_64 60 +#define MMPT_SDID_MASK_64 0x03F0000000000000ULL +#define MMPT_SDID_SHIFT_64 52 +#define MMPT_PPN_MASK_64 0x00000FFFFFFFFFFFULL #endif diff --git a/target/riscv/cpu_cfg_fields.h.inc b/target/riscv/cpu_cfg_field= s.h.inc index 9eb47af0a7..6b616388be 100644 --- a/target/riscv/cpu_cfg_fields.h.inc +++ b/target/riscv/cpu_cfg_fields.h.inc @@ -63,6 +63,8 @@ BOOL_FIELD(ext_smpmpmt) BOOL_FIELD(ext_svrsw60t59b) BOOL_FIELD(ext_svvptc) BOOL_FIELD(ext_svukte) +BOOL_FIELD(ext_smmpt) +BOOL_FIELD(ext_smsdid) BOOL_FIELD(ext_zdinx) BOOL_FIELD(ext_zaamo) BOOL_FIELD(ext_zacas) diff --git a/target/riscv/riscv_smmpt.h b/target/riscv/riscv_smmpt.h new file mode 100644 index 0000000000..74dcccf4be --- /dev/null +++ b/target/riscv/riscv_smmpt.h @@ -0,0 +1,21 @@ +/* + * QEMU RISC-V Smmpt (Memory Protection Table) + * + * Copyright (c) 2024 Alibaba Group. All rights reserved. + * + * SPDX-License-Identifier: GPL-2.0-or-later + */ + +#ifndef RISCV_SMMPT_H +#define RISCV_SMMPT_H + +typedef enum { + SMMPTBARE =3D 0, + SMMPT34 =3D 1, + SMMPT43 =3D 2, + SMMPT52 =3D 3, + SMMPT64 =3D 4, + SMMPTMAX +} mpt_mode_t; + +#endif diff --git a/target/riscv/tcg/csr.c b/target/riscv/tcg/csr.c index 36f2004bc5..8ffe85caa9 100644 --- a/target/riscv/tcg/csr.c +++ b/target/riscv/tcg/csr.c @@ -821,6 +821,15 @@ static RISCVException rnmi(CPURISCVState *env, int csr= no) =20 return RISCV_EXCP_ILLEGAL_INST; } + +static RISCVException smsdid(CPURISCVState *env, int csrno) +{ + if (riscv_cpu_cfg(env)->ext_smsdid) { + return RISCV_EXCP_NONE; + } + + return RISCV_EXCP_ILLEGAL_INST; +} #endif =20 static RISCVException seed(CPURISCVState *env, int csrno) @@ -5568,6 +5577,93 @@ static RISCVException write_mnstatus(CPURISCVState *= env, int csrno, return RISCV_EXCP_NONE; } =20 +static RISCVException read_mmpt(CPURISCVState *env, int csrno, + target_ulong *val) +{ + if (riscv_cpu_xlen(env) =3D=3D 32) { + uint32_t value =3D 0; + value |=3D env->mptmode << MMPT_MODE_SHIFT_32; + value |=3D (env->sdid << MMPT_SDID_SHIFT_32) & MMPT_SDID_MASK_32; + value |=3D env->mptppn & MMPT_PPN_MASK_32; + *val =3D value; + } else if (riscv_cpu_xlen(env) =3D=3D 64) { + uint64_t value_64 =3D 0; + uint32_t mode_value =3D env->mptmode; + /* mpt_mode_t convert to mmpt.mode value */ + if (mode_value) { + mode_value -=3D SMMPT43 - SMMPT34; + } + value_64 |=3D (uint64_t)mode_value << MMPT_MODE_SHIFT_64; + value_64 |=3D ((uint64_t)env->sdid << MMPT_SDID_SHIFT_64) + & MMPT_SDID_MASK_64; + value_64 |=3D (uint64_t)env->mptppn & MMPT_PPN_MASK_64; + *val =3D value_64; + } else { + return RISCV_EXCP_ILLEGAL_INST; + } + return RISCV_EXCP_NONE; +} + +static RISCVException write_mmpt(CPURISCVState *env, int csrno, + target_ulong val, uintptr_t ra) +{ + uint32_t mode_value =3D 0; + if (!riscv_cpu_cfg(env)->ext_smmpt) { + goto set_remaining_fields_zero; + } + + if (riscv_cpu_xlen(env) =3D=3D 32) { + mode_value =3D (val & MMPT_MODE_MASK_32) >> MMPT_MODE_SHIFT_32; + /* If mode is bare, the remaining fields in mmpt must be zero */ + if (mode_value =3D=3D SMMPTBARE) { + goto set_remaining_fields_zero; + } else if (mode_value <=3D SMMPT34) { + /* Only write the legal value */ + env->mptmode =3D mode_value; + } + env->sdid =3D (val & MMPT_SDID_MASK_32) >> MMPT_SDID_SHIFT_32; + env->mptppn =3D val & MMPT_PPN_MASK_32; + } else if (riscv_cpu_xlen(env) =3D=3D 64) { + mode_value =3D (val & MMPT_MODE_MASK_64) >> MMPT_MODE_SHIFT_64; + if (mode_value =3D=3D SMMPTBARE) { + goto set_remaining_fields_zero; + } else if (mode_value < SMMPTMAX) { + /* convert to mpt_mode_t */ + mode_value +=3D SMMPT43 - SMMPT34; + env->mptmode =3D mode_value; + } + env->sdid =3D (val & MMPT_SDID_MASK_64) >> MMPT_SDID_SHIFT_64; + env->mptppn =3D val & MMPT_PPN_MASK_64; + /* Smmpt64: root table PPN bits 2:0 must be zero (32KiB alignment)= */ + if (env->mptmode =3D=3D SMMPT64) { + env->mptppn &=3D ~(uint64_t)0x7; + } + } else { + return RISCV_EXCP_ILLEGAL_INST; + } + return RISCV_EXCP_NONE; + +set_remaining_fields_zero: + env->sdid =3D 0; + env->mptmode =3D SMMPTBARE; + env->mptppn =3D 0; + return RISCV_EXCP_NONE; +} + +static RISCVException read_msdcfg(CPURISCVState *env, int csrno, + target_ulong *val) +{ + *val =3D env->msdcfg; + return RISCV_EXCP_NONE; +} + +static RISCVException write_msdcfg(CPURISCVState *env, int csrno, + target_ulong val, uintptr_t ra) +{ + env->msdcfg =3D val; + return RISCV_EXCP_NONE; +} + #endif =20 /* Crypto Extension */ @@ -6769,6 +6865,9 @@ riscv_csr_operations csr_ops[CSR_TABLE_SIZE] =3D { write_mhpmcounterh }, [CSR_SCOUNTOVF] =3D { "scountovf", sscofpmf, read_scountovf, .min_priv_ver =3D PRIV_VERSION_1_12_0 }, + /* Supervisor Domain Identifier and Protection Registers */ + [CSR_MMPT] =3D { "mmpt", smsdid, read_mmpt, write_mmpt }, + [CSR_MSDCFG] =3D { "msdcfg", smsdid, read_msdcfg, write_msdcfg }, =20 #endif /* !CONFIG_USER_ONLY */ }; --=20 2.43.0 From nobody Fri Jul 24 04:55:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1784837155; cv=none; d=zohomail.com; s=zohoarc; b=anU9ZAek+MZqqrDMEmfTCxdhbbqxLXTxc5TXwTnYPbKEZpCEcM+y3jl+KSco2+WFicAqC66b0PGp74hnfVi/ztnomqJ+17YT0KLUiUynJ4JgNzK5ybksARnE3DageU8Lfg0ziG5jn0hN1X+QqvmFuRjM3VpU7f6U4KI2IrfUyV8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784837155; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=HANcIgYWWT+envrnIre/BFVi6a1eYrS8eNzuN21S4Pw=; b=VfDVaNTZnsPhYH8Jejt19jDHo19gY6eiySQaPJcoXc6OZGXxTeZxk0YFwg3gT2Il6k3A2/Aik6BDqSPdN99lXLk0Aieo7zW6Yks9NhU9qMW6Ek7ANe1acJqW9QkWXyi8uiVw5/wvZ7SOpu6lO8Rd1NXtwV8uYBAREOnLiZ7EVb8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784837155786469.0016988333747; Thu, 23 Jul 2026 13:05:55 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmzfH-00085a-D1; Thu, 23 Jul 2026 16:05:07 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmzeE-0007NZ-M4; Thu, 23 Jul 2026 16:04:03 -0400 Received: from [115.124.30.118] (helo=out30-118.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmze8-0005Rl-Sg; Thu, 23 Jul 2026 16:04:01 -0400 Received: from localhost.localdomain(mailfrom:zhiwei_liu@linux.alibaba.com fp:SMTPD_---0X7h4Uu9_1784837019 cluster:ay36) by smtp.aliyun-inc.com; Fri, 24 Jul 2026 04:03:40 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1784837021; h=From:To:Subject:Date:Message-Id:MIME-Version; bh=HANcIgYWWT+envrnIre/BFVi6a1eYrS8eNzuN21S4Pw=; b=BdG79Kf1UNhcz2xcyyrUytRmNEgrdQQAXYh0juaL4FaMDgtMFayZVm/ExB9reSpCaDF5+8+lN4rGvAAUStMl9gBq1zJCvi5W/oFsM8w4bdLKkzgHE9tKRxZlab25PzB7rcnuk6MZj4jskmNj/MGTQPLInD5ejFdnkku44QIys1c= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R211e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033032089153; MF=zhiwei_liu@linux.alibaba.com; NM=1; PH=DS; RN=11; SR=0; TI=SMTPD_---0X7h4Uu9_1784837019; From: LIU Zhiwei To: qemu-devel@nongnu.org Cc: palmer@dabbelt.com, alistair.francis@wdc.com, daniel.barboza@oss.qualcomm.com, chao.liu.zevorn@gmail.com, liwei1518@gmail.com, qemu-riscv@nongnu.org, rahul@summations.net, xiangyi.zeng@linux.alibaba.com, cxx194832@alibaba-inc.com, LIU Zhiwei Subject: [PATCH v8 02/11] target/riscv: Add smmpt-sdidlen property for the mmpt SDID field Date: Fri, 24 Jul 2026 04:03:16 +0800 Message-Id: <20260723200325.24969-3-zhiwei_liu@linux.alibaba.com> X-Mailer: git-send-email 2.39.3 (Apple Git-146) In-Reply-To: <20260723200325.24969-1-zhiwei_liu@linux.alibaba.com> References: <20260723200325.24969-1-zhiwei_liu@linux.alibaba.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.118 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.118; envelope-from=zhiwei_liu@linux.alibaba.com; helo=out30-118.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1784837157276158500 Content-Type: text/plain; charset="utf-8" The number of implemented SDID bits is UNSPECIFIED and may be zero. The number of implemented SDID bits, termed SDIDLEN, may be determined by writing one to every bit position in the SDID field, then reading back the value in mmpt to see which bit positions in the SDID field hold a one. The least-significant bits of SDID are implemented first: that is, if SDIDLEN > 0, SDID[SDIDLEN-1:0] is writable. The maximal value of SDIDLEN, termed SDIDMAX, is 6. Model this by adding a configurable "smmpt-sdidlen" CPU property. The value defaults to SDIDMAX (6) to preserve the current behaviour. The mmpt write handler now keeps only the low SDIDLEN bits of the SDID field, making the SDIDLEN discovery sequence work as specified. Signed-off-by: LIU Zhiwei --- target/riscv/cpu.c | 45 +++++++++++++++++++++++++++++++ target/riscv/cpu_bits.h | 3 +++ target/riscv/cpu_cfg_fields.h.inc | 1 + target/riscv/tcg/csr.c | 11 ++++++-- 4 files changed, 58 insertions(+), 2 deletions(-) diff --git a/target/riscv/cpu.c b/target/riscv/cpu.c index 5a82e6563b..0f96e487fa 100644 --- a/target/riscv/cpu.c +++ b/target/riscv/cpu.c @@ -1434,6 +1434,7 @@ static void riscv_cpu_init(Object *obj) cpu->cfg.pmu_mask =3D MAKE_64BIT_MASK(3, 16); cpu->cfg.vlenb =3D 128 >> 3; cpu->cfg.elen =3D 64; + cpu->cfg.sdidlen =3D MMPT_SDIDLEN_MAX; cpu->cfg.cbom_blocksize =3D 64; cpu->cfg.cbop_blocksize =3D 64; cpu->cfg.cboz_blocksize =3D 64; @@ -1939,6 +1940,48 @@ static const PropertyInfo prop_vlen =3D { .set =3D prop_vlen_set, }; =20 +static void prop_sdidlen_set(Object *obj, Visitor *v, const char *name, + void *opaque, Error **errp) +{ + RISCVCPU *cpu =3D RISCV_CPU(obj); + uint8_t value; + + if (!visit_type_uint8(v, name, &value, errp)) { + return; + } + + if (value > MMPT_SDIDLEN_MAX) { + error_setg(errp, "smmpt-sdidlen must be between 0 and %d", + MMPT_SDIDLEN_MAX); + return; + } + + if (value !=3D cpu->cfg.sdidlen && riscv_cpu_is_vendor(obj)) { + cpu_set_prop_err(cpu, name, errp); + error_append_hint(errp, "Current '%s' val: %u\n", + name, cpu->cfg.sdidlen); + return; + } + + cpu_option_add_user_setting(cpu, name); + cpu->cfg.sdidlen =3D value; +} + +static void prop_sdidlen_get(Object *obj, Visitor *v, const char *name, + void *opaque, Error **errp) +{ + uint8_t value =3D RISCV_CPU(obj)->cfg.sdidlen; + + visit_type_uint8(v, name, &value, errp); +} + +static const PropertyInfo prop_sdidlen =3D { + .type =3D "uint8", + .description =3D "smmpt-sdidlen", + .get =3D prop_sdidlen_get, + .set =3D prop_sdidlen_set, +}; + static void prop_elen_set(Object *obj, Visitor *v, const char *name, void *opaque, Error **errp) { @@ -2853,6 +2896,8 @@ static const Property riscv_cpu_properties[] =3D { {.name =3D "vlen", .info =3D &prop_vlen}, {.name =3D "elen", .info =3D &prop_elen}, =20 + {.name =3D "smmpt-sdidlen", .info =3D &prop_sdidlen}, + {.name =3D "cbom_blocksize", .info =3D &prop_cbom_blksize}, {.name =3D "cbop_blocksize", .info =3D &prop_cbop_blksize}, {.name =3D "cboz_blocksize", .info =3D &prop_cboz_blksize}, diff --git a/target/riscv/cpu_bits.h b/target/riscv/cpu_bits.h index 4ed4843e3d..642edf3369 100644 --- a/target/riscv/cpu_bits.h +++ b/target/riscv/cpu_bits.h @@ -1171,6 +1171,9 @@ typedef enum CTRType { #define CSR_MMPT 0x382 #define CSR_MSDCFG 0x74E =20 +/* Maximal number of implemented SDID bits (SDIDMAX) */ +#define MMPT_SDIDLEN_MAX 6 + /* * MMPT register layout for MXLEN=3D32: * MODE[31:30], 0[29:28], SDID[27:22], PPN[21:0] diff --git a/target/riscv/cpu_cfg_fields.h.inc b/target/riscv/cpu_cfg_field= s.h.inc index 6b616388be..4a8c9b9e21 100644 --- a/target/riscv/cpu_cfg_fields.h.inc +++ b/target/riscv/cpu_cfg_fields.h.inc @@ -174,6 +174,7 @@ TYPED_FIELD(uint64_t, mimpid, 0) TYPED_FIELD(uint32_t, pmu_mask, 0) TYPED_FIELD(uint16_t, vlenb, 0) TYPED_FIELD(uint16_t, elen, 0) +TYPED_FIELD(uint8_t, sdidlen, 0) TYPED_FIELD(uint16_t, cbom_blocksize, 0) TYPED_FIELD(uint16_t, cbop_blocksize, 0) TYPED_FIELD(uint16_t, cboz_blocksize, 0) diff --git a/target/riscv/tcg/csr.c b/target/riscv/tcg/csr.c index 8ffe85caa9..8d38d7a972 100644 --- a/target/riscv/tcg/csr.c +++ b/target/riscv/tcg/csr.c @@ -5608,6 +5608,11 @@ static RISCVException write_mmpt(CPURISCVState *env,= int csrno, target_ulong val, uintptr_t ra) { uint32_t mode_value =3D 0; + /* + * Only the least-significant SDIDLEN bits of the SDID field are + * writable; the remaining bits are WARL and read as zero. + */ + uint64_t sdid_mask =3D MAKE_64BIT_MASK(0, riscv_cpu_cfg(env)->sdidlen); if (!riscv_cpu_cfg(env)->ext_smmpt) { goto set_remaining_fields_zero; } @@ -5621,7 +5626,8 @@ static RISCVException write_mmpt(CPURISCVState *env, = int csrno, /* Only write the legal value */ env->mptmode =3D mode_value; } - env->sdid =3D (val & MMPT_SDID_MASK_32) >> MMPT_SDID_SHIFT_32; + env->sdid =3D ((val & MMPT_SDID_MASK_32) >> MMPT_SDID_SHIFT_32) + & sdid_mask; env->mptppn =3D val & MMPT_PPN_MASK_32; } else if (riscv_cpu_xlen(env) =3D=3D 64) { mode_value =3D (val & MMPT_MODE_MASK_64) >> MMPT_MODE_SHIFT_64; @@ -5632,7 +5638,8 @@ static RISCVException write_mmpt(CPURISCVState *env, = int csrno, mode_value +=3D SMMPT43 - SMMPT34; env->mptmode =3D mode_value; } - env->sdid =3D (val & MMPT_SDID_MASK_64) >> MMPT_SDID_SHIFT_64; + env->sdid =3D (((uint64_t)val & MMPT_SDID_MASK_64) >> MMPT_SDID_SH= IFT_64) + & sdid_mask; env->mptppn =3D val & MMPT_PPN_MASK_64; /* Smmpt64: root table PPN bits 2:0 must be zero (32KiB alignment)= */ if (env->mptmode =3D=3D SMMPT64) { --=20 2.43.0 From nobody Fri Jul 24 04:55:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1784837091; cv=none; d=zohomail.com; s=zohoarc; b=RAZKUTe9m9huMMF7wL5dh4nqHllK1dJ5cCwYvbbAotuT8s+E1PlLPeUPKzGQX7920OJ/cqXqNzHkdUUU6MIFaMnDFPQEySw8c9xvwIFrKql7WJa8JAjdZgjhQeVREKRLPOIX3EbDhB5fjVSLF6Mt8rNZI+9JBVRyl0mTZq25TdA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784837091; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=EZeokRcPmyS1pMC+5nbXh8BHk/bNmq2BQUbViTV7gfk=; b=R9s7vDV0NspV7qwvUUuhUt9TOf/IjX7RPV72nTuEHbYCPBM354vpaBhqG6OKS1RB50wlJsyvjMman4kgFa3MZ9pNg8t8za9hX5dXJOUQGNj5of/6nR4gN2iHhq7nhS5caGn7A+qlcUpdKWFHyR5gY86QTTIBpxnTY1EKCQRlOVA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784837091254786.831450770431; Thu, 23 Jul 2026 13:04:51 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmzeP-0007RD-UN; Thu, 23 Jul 2026 16:04:16 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmzeH-0007OQ-JU; Thu, 23 Jul 2026 16:04:06 -0400 Received: from [115.124.30.100] (helo=out30-100.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmze9-0005Ro-4I; Thu, 23 Jul 2026 16:04:03 -0400 Received: from localhost.localdomain(mailfrom:zhiwei_liu@linux.alibaba.com fp:SMTPD_---0X7h4UuH_1784837020 cluster:ay36) by smtp.aliyun-inc.com; Fri, 24 Jul 2026 04:03:40 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1784837021; h=From:To:Subject:Date:Message-Id:MIME-Version; bh=EZeokRcPmyS1pMC+5nbXh8BHk/bNmq2BQUbViTV7gfk=; b=Gb7xzvaFgIriwiaOR3bnb/mqfGDnWxgKrhoOvAPSU6G2c5tCkk+y/OV+HXHWiIBmOxY5MnPHHQ/nuNe9huIdcAxxal0I7LWrpwWNq+QyRtX+KrZaYxTq1RewCckyLP/2d7aTHV6Q5Z2sV2kfTtmtm9pXmOBwioJMQDBOMjleINo= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R161e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033037009110; MF=zhiwei_liu@linux.alibaba.com; NM=1; PH=DS; RN=13; SR=0; TI=SMTPD_---0X7h4UuH_1784837020; From: LIU Zhiwei To: qemu-devel@nongnu.org Cc: palmer@dabbelt.com, alistair.francis@wdc.com, daniel.barboza@oss.qualcomm.com, chao.liu.zevorn@gmail.com, liwei1518@gmail.com, qemu-riscv@nongnu.org, rahul@summations.net, xiangyi.zeng@linux.alibaba.com, cxx194832@alibaba-inc.com, LIU Zhiwei , Huang Tao , TANG Tiancheng Subject: [PATCH v8 03/11] target/riscv: Implement core SMMPT lookup logic Date: Fri, 24 Jul 2026 04:03:17 +0800 Message-Id: <20260723200325.24969-4-zhiwei_liu@linux.alibaba.com> X-Mailer: git-send-email 2.39.3 (Apple Git-146) In-Reply-To: <20260723200325.24969-1-zhiwei_liu@linux.alibaba.com> References: <20260723200325.24969-1-zhiwei_liu@linux.alibaba.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.100 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.100; envelope-from=zhiwei_liu@linux.alibaba.com; helo=out30-100.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1784837092950158500 Content-Type: text/plain; charset="utf-8" This patch introduces the core implementation for the Memory Protection Tab= le (MPT) walk, which is the central mechanism of the SMMPT extension. A new file, `riscv_smmpt.c`, is added to encapsulate the MPT logic. It implements the `smmpt_lookup()` function, which performs a multi-level page table-like walk starting from the physical address specified in the `mptppn` CSR field. This walk determines the access permissions (read, write, execute) for a given physical address. The implementation supports various SMMPT modes (SMMPT34, SMMPT43, etc.) and correctly handles leaf and non-leaf entries, including reserved bit checks. Both non-NAPOT leaf entries (per-page XWR tuples) and NAPOT leaf entries (a single XWR tuple with a G granularity field) are supported, as defined by the v0.4.9 MPTE format. Helper functions for parsing MPT entries and converting access permissions are included in the new `riscv_smmpt.h` header. Co-authored-by: Huang Tao Co-authored-by: TANG Tiancheng Signed-off-by: LIU Zhiwei --- target/riscv/meson.build | 1 + target/riscv/riscv_smmpt.c | 339 ++++++++++++++++++++++++++++++++++ target/riscv/riscv_smmpt.h | 5 + target/riscv/tcg/cpu_helper.c | 6 +- target/riscv/tcg/pmp.h | 3 + 5 files changed, 351 insertions(+), 3 deletions(-) create mode 100644 target/riscv/riscv_smmpt.c diff --git a/target/riscv/meson.build b/target/riscv/meson.build index 42d0f6d538..51257a8f3a 100644 --- a/target/riscv/meson.build +++ b/target/riscv/meson.build @@ -22,6 +22,7 @@ riscv_ss.add(files( riscv_system_ss =3D ss.source_set() riscv_system_ss.add(files( 'arch_dump.c', + 'riscv_smmpt.c', 'monitor.c', 'machine.c', 'time_helper.c', diff --git a/target/riscv/riscv_smmpt.c b/target/riscv/riscv_smmpt.c new file mode 100644 index 0000000000..5bdc474dbb --- /dev/null +++ b/target/riscv/riscv_smmpt.c @@ -0,0 +1,339 @@ +/* + * QEMU RISC-V Smmpt (Memory Protection Table) + * + * Copyright (c) 2024 Alibaba Group. All rights reserved. + * + * SPDX-License-Identifier: GPL-2.0-or-later + * + * Implements the MPT lookup algorithm per SMMTT specification v0.4.9. + * + * MPTE format (v0.4.9): + * + * 32-bit non-leaf: V[0], L=3D0[1], Reserved[9:2], PPN[31:10] + * 32-bit non-NAPOT leaf: V[0], L=3D1[1], N=3D0[2], Reserved[7:3], XWR[31:= 8] + * 32-bit NAPOT leaf: V[0], L=3D1[1], N=3D1[2], Reserved[7:3], XWR[10:8], = 0[11], + * G[15:12], Reserved[31:16] + * + * 64-bit non-leaf: V[0], L=3D0[1], Reserved[9:2], PPN[53:10], Reserved[6= 3:54] + * 64-bit non-NAPOT leaf: V[0], L=3D1[1], N=3D0[2], Reserved[7:3], XWR[55:= 8], + * Reserved[63:56] + * 64-bit NAPOT leaf: V[0], L=3D1[1], N=3D1[2], Reserved[7:3], XWR[10:8], = 0[11], + * G[15:12], Reserved[63:16] + */ + +#include "qemu/osdep.h" +#include "riscv_smmpt.h" +#include "tcg/pmp.h" +#include "exec/page-protection.h" +#include "system/memory.h" + +typedef uint64_t load_entry_fn(AddressSpace *, hwaddr, + MemTxAttrs, MemTxResult *); + +static uint64_t load_entry_32(AddressSpace *as, hwaddr addr, + MemTxAttrs attrs, MemTxResult *result) +{ + return address_space_ldl_le(as, addr, attrs, result); +} + +static uint64_t load_entry_64(AddressSpace *as, hwaddr addr, + MemTxAttrs attrs, MemTxResult *result) +{ + return address_space_ldq_le(as, addr, attrs, result); +} + +static inline bool mpte_is_valid(uint64_t mpte) +{ + return mpte & 0x1; +} + +static inline bool mpte_is_leaf(uint64_t mpte) +{ + return mpte & 0x2; +} + +static inline bool mpte_get_n(uint64_t mpte) +{ + return (mpte >> 2) & 0x1; +} + +/* + * Get reserved bits from MPTE. Returns non-zero if any reserved bit is se= t. + */ +static uint64_t mpte_get_rsv(CPURISCVState *env, uint64_t mpte) +{ + RISCVMXL mxl =3D riscv_cpu_mxl(env); + bool leaf =3D mpte_is_leaf(mpte); + bool napot =3D mpte_get_n(mpte); + + if (mxl =3D=3D MXL_RV32) { + if (!leaf) { + /* non-leaf32: Reserved =3D bits[9:2] */ + return extract32(mpte, 2, 8); + } + if (!napot) { + /* non-NAPOT leaf32: Reserved =3D bits[7:3] (XWR fills [31:8])= */ + return extract32(mpte, 3, 5); + } + /* NAPOT leaf32: Reserved =3D bits[7:3] | bit[11] (mbz) | bits[31:= 16] */ + return extract32(mpte, 3, 5) | extract32(mpte, 11, 1) | + extract32(mpte, 16, 16); + } + + /* RV64 */ + if (!leaf) { + /* non-leaf64: Reserved =3D bits[9:2] | bits[63:54] */ + return extract64(mpte, 2, 8) | extract64(mpte, 54, 10); + } + if (!napot) { + /* non-NAPOT leaf64: Reserved =3D bits[7:3] | bits[63:56] */ + return extract64(mpte, 3, 5) | extract64(mpte, 56, 8); + } + /* NAPOT leaf64: Reserved =3D bits[7:3] | bit[11] (mbz) | bits[63:16] = */ + return extract64(mpte, 3, 5) | extract64(mpte, 11, 1) | + extract64(mpte, 16, 48); +} + +/* + * Get PPN from a non-leaf MPTE. + * RV32 non-leaf: PPN =3D bits[31:10] (22 bits) + * RV64 non-leaf: PPN =3D bits[53:10] (44 bits) + */ +static uint64_t mpte_get_ppn(CPURISCVState *env, uint64_t mpte) +{ + RISCVMXL mxl =3D riscv_cpu_mxl(env); + + if (mxl =3D=3D MXL_RV32) { + return extract32(mpte, 10, 22); + } + return extract64(mpte, 10, 44); +} + +/* + * Get XWR permission for a specific page index from a non-NAPOT leaf. + * The XWR base bit is 8 for both RV32 and RV64; only the number of + * entries differs (pi in 0..7 for RV32, 0..15 for RV64). + */ +static uint32_t mpte_get_xwr(CPURISCVState *env, uint64_t mpte, int pi) +{ + return extract64(mpte, 8 + pi * 3, 3); +} + +/* + * Get single XWR from a NAPOT leaf. + * The NAPOT XWR base bit is 8 for both RV32 and RV64 (bits[10:8]). + */ +static uint32_t mpte_get_napot_xwr(CPURISCVState *env, uint64_t mpte) +{ + return extract64(mpte, 8, 3); +} + +/* + * Get G field from a NAPOT leaf. + * The G base bit is 12 for both RV32 and RV64 (bits[15:12]). + */ +static uint32_t mpte_get_g(CPURISCVState *env, uint64_t mpte) +{ + return extract64(mpte, 12, 4); +} + +/* + * Validate the G encoding for the given MPT mode. + * Smmpt34: only G=3D6 is valid + * Smmpt43/52/64: only G=3D4 is valid + */ +static bool mpte_validate_g(uint32_t g, mpt_mode_t mode) +{ + switch (mode) { + case SMMPT34: + return g =3D=3D 6; + case SMMPT43: + case SMMPT52: + case SMMPT64: + return g =3D=3D 4; + default: + return false; + } +} + +/* + * Get page number index pn[i] from the supervisor physical address. + * + * Smmpt34 (34-bit SPA): + * SPA layout: range_offset[14:0], pn[0][24:15] (10 bits), + * pn[1][33:25] (9 bits) + * + * Smmpt43/52/64 (RV64 MPT): + * SPA layout: range_offset[15:0], pn[0][24:16] (9 bits), ... + * For Smmpt64, pn[4] (top level) is 12 bits. + */ +static int mpt_get_pn(hwaddr addr, int i, mpt_mode_t mode) +{ + if (mode =3D=3D SMMPT34) { + return i =3D=3D 0 + ? extract64(addr, 15, 10) + : extract64(addr, 25, 9); + } else { + int offset =3D 16 + i * 9; + if ((mode =3D=3D SMMPT64) && (i =3D=3D 4)) { + return extract64(addr, offset, 12); + } else { + return extract64(addr, offset, 9); + } + } +} + +/* + * Get the page index within a leaf MPTE. + * + * Smmpt34: pi =3D SPA[14:12] (3 bits) for level 0, SPA[24:22] for level 1 + * Smmpt43/52/64: pi =3D SPA[offset-4 +: 4] (4 bits) + */ +static int mpt_get_pi(hwaddr addr, int i, mpt_mode_t mode) +{ + if (mode =3D=3D SMMPT34) { + return i =3D=3D 0 + ? extract64(addr, 12, 3) + : extract64(addr, 22, 3); + } else { + int offset =3D 16 + i * 9; + return extract64(addr, offset - 4, 4); + } +} + +/* + * Check XWR permission bits against the access type. + * Returns true if access is allowed. + * + * The 3-bit XWR field uses the same bit order as RISC-V PTE permissions + * (bit0 =3D R, bit1 =3D W, bit2 =3D X), matching QEMU's PAGE_READ / PAGE_= WRITE / + * PAGE_EXEC. As with PTEs, writable-but-not-readable encodings are reserv= ed. + * + * XWR encoding (bit2=3DX, bit1=3DW, bit0=3DR): + * 000 =3D No access + * 001 =3D Read only + * 010 =3D Reserved (fault) + * 011 =3D Read + Write + * 100 =3D Execute only + * 101 =3D Read + Execute + * 110 =3D Reserved (fault) + * 111 =3D Read + Write + Execute + */ +static bool mpt_check_xwr(uint32_t xwr, int *prot, MMUAccessType access_ty= pe) +{ + switch (xwr) { + case 0: /* No access */ + return false; + case PAGE_EXEC: /* 100: Execute only */ + *prot =3D PAGE_EXEC; + return access_type =3D=3D MMU_INST_FETCH; + case PAGE_READ | PAGE_EXEC: /* 101: Read + Execute */ + *prot =3D PAGE_READ | PAGE_EXEC; + return (access_type =3D=3D MMU_DATA_LOAD || + access_type =3D=3D MMU_INST_FETCH); + case PAGE_READ: /* 001: Read only */ + *prot =3D PAGE_READ; + return access_type =3D=3D MMU_DATA_LOAD; + case PAGE_READ | PAGE_WRITE: /* 011: Read + Write */ + *prot =3D PAGE_READ | PAGE_WRITE; + return (access_type =3D=3D MMU_DATA_LOAD || + access_type =3D=3D MMU_DATA_STORE); + case PAGE_READ | PAGE_WRITE | PAGE_EXEC: /* 111: R+W+X */ + *prot =3D PAGE_READ | PAGE_WRITE | PAGE_EXEC; + return true; + default: /* 010, 110: Reserved - fault */ + return false; + } +} + +static bool smmpt_lookup(CPURISCVState *env, hwaddr addr, mpt_mode_t mode, + int *prot, MMUAccessType access_type) +{ + MemTxResult res; + MemTxAttrs attrs =3D MEMTXATTRS_UNSPECIFIED; + CPUState *cs =3D env_cpu(env); + hwaddr mpte_addr, base =3D (hwaddr)env->mptppn << PGSHIFT; + load_entry_fn *load_entry; + uint32_t mptesize, levels, xwr, g; + int pn, pi, pmp_prot, pmp_ret; + uint64_t mpte; + + switch (mode) { + case SMMPT34: + load_entry =3D &load_entry_32; levels =3D 2; mptesize =3D 4; break; + case SMMPT43: + load_entry =3D &load_entry_64; levels =3D 3; mptesize =3D 8; break; + case SMMPT52: + load_entry =3D &load_entry_64; levels =3D 4; mptesize =3D 8; break; + case SMMPT64: + load_entry =3D &load_entry_64; levels =3D 5; mptesize =3D 8; break; + case SMMPTBARE: + *prot =3D PAGE_READ | PAGE_WRITE | PAGE_EXEC; + return true; + default: + g_assert_not_reached(); + break; + } + + for (int i =3D levels - 1; i >=3D 0; i--) { + /* Step 1: Get pn[i] as the MPT index */ + pn =3D mpt_get_pn(addr, i, mode); + + /* Step 2: Load MPTE from memory */ + mpte_addr =3D base + pn * mptesize; + pmp_ret =3D get_physical_address_pmp(env, &pmp_prot, mpte_addr, + mptesize, MMU_DATA_LOAD, PRV_M); + if (pmp_ret !=3D TRANSLATE_SUCCESS) { + return false; + } + mpte =3D load_entry(cs->as, mpte_addr, attrs, &res); + if (res !=3D MEMTX_OK) { + return false; + } + + /* Step 3: Check valid bit and reserved bits */ + if (!mpte_is_valid(mpte) || mpte_get_rsv(env, mpte)) { + return false; + } + + /* Step 3 (cont): non-leaf with N=3D1 is a fault */ + if (!mpte_is_leaf(mpte) && mpte_get_n(mpte)) { + return false; + } + + /* Step 4: Process non-leaf node */ + if (!mpte_is_leaf(mpte)) { + if (i =3D=3D 0) { + return false; + } + base =3D mpte_get_ppn(env, mpte) << PGSHIFT; + continue; + } + + /* Step 5 & 6: Process leaf node */ + if (!mpte_get_n(mpte)) { + /* Step 5: Non-NAPOT leaf - get XWR[pi] */ + pi =3D mpt_get_pi(addr, i, mode); + xwr =3D mpte_get_xwr(env, mpte, pi); + } else { + /* Step 6: NAPOT leaf - validate G, get single XWR */ + g =3D mpte_get_g(env, mpte); + if (!mpte_validate_g(g, mode)) { + return false; + } + xwr =3D mpte_get_napot_xwr(env, mpte); + } + + /* Step 7: Check permission */ + return mpt_check_xwr(xwr, prot, access_type); + } + return false; +} + +bool smmpt_check_access(CPURISCVState *env, hwaddr addr, + int *prot, MMUAccessType access_type) +{ + mpt_mode_t mode =3D env->mptmode; + + return smmpt_lookup(env, addr, mode, prot, access_type); +} diff --git a/target/riscv/riscv_smmpt.h b/target/riscv/riscv_smmpt.h index 74dcccf4be..c15637036e 100644 --- a/target/riscv/riscv_smmpt.h +++ b/target/riscv/riscv_smmpt.h @@ -9,6 +9,9 @@ #ifndef RISCV_SMMPT_H #define RISCV_SMMPT_H =20 +#include "cpu.h" +#include "exec/mmu-access-type.h" + typedef enum { SMMPTBARE =3D 0, SMMPT34 =3D 1, @@ -18,4 +21,6 @@ typedef enum { SMMPTMAX } mpt_mode_t; =20 +bool smmpt_check_access(CPURISCVState *env, hwaddr addr, + int *prot, MMUAccessType access_type); #endif diff --git a/target/riscv/tcg/cpu_helper.c b/target/riscv/tcg/cpu_helper.c index 07d9222652..354506c565 100644 --- a/target/riscv/tcg/cpu_helper.c +++ b/target/riscv/tcg/cpu_helper.c @@ -903,9 +903,9 @@ void riscv_cpu_set_mode(CPURISCVState *env, privilege_m= ode_t newpriv, * @access_type: The type of MMU access * @mode: Indicates current privilege level. */ -static int get_physical_address_pmp(CPURISCVState *env, int *prot, hwaddr = addr, - int size, MMUAccessType access_type, - privilege_mode_t mode) +int get_physical_address_pmp(CPURISCVState *env, int *prot, hwaddr addr, + int size, MMUAccessType access_type, + privilege_mode_t mode) { pmp_priv_t pmp_priv; bool pmp_has_privs; diff --git a/target/riscv/tcg/pmp.h b/target/riscv/tcg/pmp.h index 4c95c2767a..16c0db93c6 100644 --- a/target/riscv/tcg/pmp.h +++ b/target/riscv/tcg/pmp.h @@ -80,6 +80,9 @@ void pmp_update_rule_nums(CPURISCVState *env); uint32_t pmp_get_num_rules(CPURISCVState *env); int pmp_priv_to_page_prot(pmp_priv_t pmp_priv); void pmp_unlock_entries(CPURISCVState *env); +int get_physical_address_pmp(CPURISCVState *env, int *prot, hwaddr addr, + int size, MMUAccessType access_type, + privilege_mode_t mode); =20 #define MSECCFG_MML_ISSET(env) get_field(env->mseccfg, MSECCFG_MML) #define MSECCFG_MMWP_ISSET(env) get_field(env->mseccfg, MSECCFG_MMWP) --=20 2.43.0 From nobody Fri Jul 24 04:55:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1784837103; cv=none; d=zohomail.com; s=zohoarc; b=W5wUh9JXjQ76W0xzzJzYjFF9KhJCKZiJuXOc2JO3JST+nAwmWpJdBjRQjCMae3Vmxw8G+T5noPgQU/QxuuEppDGSci0E4PbvX1Op64r+gneuztPm9tvl0Oy+a5jGyQvC29WE6uLB/nkTPmTPcgLki53uZ01GYjYIlGFHe3oetf4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784837103; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=M07UVfnU/2nidLWov/BOD//BB/HPNCPhrhQsGIpMnPg=; b=niiVBA80Dkmoju3+NUfqZPi1nkTsyNG5wX23PuQuRxuNutrnc0UdPdpPt8QtN/isXW003Py4yLGSlVQYinTs3gx5VvkNJhG5KRYHLI64sg8tpEblXr2coQUqRzVjHkbj9/CmUGxBApqzbBFrioI3NizFocGloaJk99f6+a/LiE8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784837103523299.70771994754784; Thu, 23 Jul 2026 13:05:03 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmzf4-0007ib-BE; Thu, 23 Jul 2026 16:04:54 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmzeI-0007Oe-IC; Thu, 23 Jul 2026 16:04:06 -0400 Received: from [115.124.30.111] (helo=out30-111.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmzeA-0005Rt-P7; Thu, 23 Jul 2026 16:04:06 -0400 Received: from localhost.localdomain(mailfrom:zhiwei_liu@linux.alibaba.com fp:SMTPD_---0X7h4UuO_1784837021 cluster:ay36) by smtp.aliyun-inc.com; Fri, 24 Jul 2026 04:03:41 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1784837022; h=From:To:Subject:Date:Message-Id:MIME-Version; bh=M07UVfnU/2nidLWov/BOD//BB/HPNCPhrhQsGIpMnPg=; b=RoZ6H5qhWrQXc1ePvUyTeyT/LTbLYzT3vm+XeIU1XdBDykxE98RfUoTXin8MXdDjg18Dgqo++d+0+/OlYoYWRDnkFVcFodD/wVrrYlZ3B9gxawZwcEgSYccG+paMl+RKnKzLdlgFghBIeowWO/8swbclHIzwcyvODkMRTJYd0Nw= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R141e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033045133197; MF=zhiwei_liu@linux.alibaba.com; NM=1; PH=DS; RN=14; SR=0; TI=SMTPD_---0X7h4UuO_1784837021; From: LIU Zhiwei To: qemu-devel@nongnu.org Cc: palmer@dabbelt.com, alistair.francis@wdc.com, daniel.barboza@oss.qualcomm.com, chao.liu.zevorn@gmail.com, liwei1518@gmail.com, qemu-riscv@nongnu.org, rahul@summations.net, xiangyi.zeng@linux.alibaba.com, cxx194832@alibaba-inc.com, LIU Zhiwei , Huang Tao , TANG Tiancheng , Daniel Henrique Barboza Subject: [PATCH v8 04/11] target/riscv: Integrate SMMPT checks into MMU and TLB fill Date: Fri, 24 Jul 2026 04:03:18 +0800 Message-Id: <20260723200325.24969-5-zhiwei_liu@linux.alibaba.com> X-Mailer: git-send-email 2.39.3 (Apple Git-146) In-Reply-To: <20260723200325.24969-1-zhiwei_liu@linux.alibaba.com> References: <20260723200325.24969-1-zhiwei_liu@linux.alibaba.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.111 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.111; envelope-from=zhiwei_liu@linux.alibaba.com; helo=out30-111.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1784837105188158500 Content-Type: text/plain; charset="utf-8" With the core MPT lookup logic in place, this patch integrates the permission checks into QEMU's main MMU processing functions. A new helper, `get_physical_address_mpt`, is introduced to check the permissions for a given physical address against the MPT. This helper is then called at two critical points: 1. During page table walks (`get_physical_address`): The physical address of the Page Table Entry (PTE) itself is checked to ensure the supervisor has permission to read it. 2. After successful address translation (`riscv_cpu_tlb_fill`): The final guest-physical address is checked against the MPT before the access is allowed to proceed. This ensures that SMMPT protection is enforced for both the translation process and the final memory access, as required by the specification. Co-authored-by: Huang Tao Co-authored-by: TANG Tiancheng Signed-off-by: LIU Zhiwei Reviewed-by: Daniel Henrique Barboza Reviewed-by: Chao Liu --- target/riscv/tcg/cpu_helper.c | 113 ++++++++++++++++++++++++++++++---- 1 file changed, 100 insertions(+), 13 deletions(-) diff --git a/target/riscv/tcg/cpu_helper.c b/target/riscv/tcg/cpu_helper.c index 354506c565..e3aac26931 100644 --- a/target/riscv/tcg/cpu_helper.c +++ b/target/riscv/tcg/cpu_helper.c @@ -976,6 +976,53 @@ static bool check_svukte_addr(CPURISCVState *env, vadd= r addr) return !high_bit; } =20 +/* + * get_physical_address_mpt - check mpt permission for this physical addre= ss + * + * Lookup the Memory Protection Table and check permission for this + * physical address. Returns 0 if the permission checking was successful + * + * @env: CPURISCVState + * @prot: The returned protection attributes + * @addr: The physical address to be checked permission + * @access_type: The type of MMU access + * @mode: Indicates current privilege level. + */ +static int get_physical_address_mpt(CPURISCVState *env, int *prot, hwaddr = addr, + MMUAccessType access_type, int mode) +{ + /* + * If the extension is not supported or the mmpt.mode is Bare, + * there is no protection, return success. + */ + if (!riscv_cpu_cfg(env)->ext_smmpt || env->mptmode =3D=3D SMMPTBARE) { + *prot =3D PAGE_READ | PAGE_WRITE | PAGE_EXEC; + return TRANSLATE_SUCCESS; + } + + /* + * MPT is checked for all accesses to physical memory, unless the + * effective privilege mode is M. + * + * Data accesses in M-mode when the MPRV bit in mstatus is set and + * the MPP field in mstatus contains S or U are subject to MPT checks. + * + * In riscv_env_mmu_index, The MPRV and MPP bits are already checked a= nd + * encoded to mmu_idx, So we do not need to check it here. + */ + if (mode =3D=3D PRV_M) { + *prot =3D PAGE_READ | PAGE_WRITE | PAGE_EXEC; + return TRANSLATE_SUCCESS; + } + + if (!smmpt_check_access(env, addr, prot, access_type)) { + *prot =3D 0; + return TRANSLATE_MPT_FAIL; + } + + return TRANSLATE_SUCCESS; +} + /* * get_physical_address - get the physical address for this virtual address * @@ -1174,6 +1221,13 @@ static int get_physical_address(CPURISCVState *env, = hwaddr *physical, pte_addr =3D base + idx * ptesize; } =20 + int mpt_prot; + int mpt_ret =3D get_physical_address_mpt(env, &mpt_prot, pte_addr, + MMU_DATA_LOAD, PRV_S); + if (mpt_ret !=3D TRANSLATE_SUCCESS) { + return mpt_ret; + } + int pmp_prot; int pmp_ret =3D get_physical_address_pmp(env, &pmp_prot, pte_addr, sxlen_bytes, @@ -1657,7 +1711,7 @@ bool riscv_cpu_tlb_fill(CPUState *cs, vaddr address, = int size, CPURISCVState *env =3D &cpu->env; vaddr im_address; hwaddr pa =3D 0; - int prot, prot2, prot_pmp; + int prot, prot2, prot_pmp, mpt_prot; bool pmp_pma_violation =3D false; bool first_stage_error =3D true; bool two_stage_lookup =3D mmuidx_2stage(mmu_idx); @@ -1710,26 +1764,42 @@ bool riscv_cpu_tlb_fill(CPUState *cs, vaddr address= , int size, prot &=3D prot2; =20 if (ret =3D=3D TRANSLATE_SUCCESS) { - ret =3D get_physical_address_pmp(env, &prot_pmp, pa, - size, access_type, mode); - tlb_size =3D pmp_get_tlb_size(env, pa); + ret =3D get_physical_address_mpt(env, &mpt_prot, pa, + access_type, mode); + if (riscv_cpu_cfg(env)->ext_smmpt) { + qemu_log_mask(CPU_LOG_MMU, + "%s MPT address=3D" HWADDR_FMT_plx " ret= %d" + " prot %d\n", + __func__, pa, ret, mpt_prot); + } + prot &=3D mpt_prot; =20 - qemu_log_mask(CPU_LOG_MMU, - "%s PMP address=3D" HWADDR_FMT_plx " ret %d = prot" - " %d tlb_size %" HWADDR_PRIu "\n", - __func__, pa, ret, prot_pmp, tlb_size); + if (ret =3D=3D TRANSLATE_SUCCESS) { + ret =3D get_physical_address_pmp(env, &prot_pmp, pa, + size, access_type, mode= ); + tlb_size =3D pmp_get_tlb_size(env, pa); + + qemu_log_mask(CPU_LOG_MMU, + "%s PMP address=3D" HWADDR_FMT_plx + " ret %d prot %d tlb_size %" + HWADDR_PRIu "\n", + __func__, pa, ret, prot_pmp, + tlb_size); =20 - prot &=3D prot_pmp; + prot &=3D prot_pmp; + } } else { /* * Guest physical address translation failed, this is a HS * level exception */ first_stage_error =3D false; - if (ret !=3D TRANSLATE_PMP_FAIL) { + if (ret !=3D TRANSLATE_PMP_FAIL && + ret !=3D TRANSLATE_MPT_FAIL) { env->guest_phys_fault_addr =3D (im_address | (address & - (TARGET_PAGE_SIZE - 1))= ) >> 2; + (TARGET_PAGE_SIZE - 1))) + >> 2; } } } @@ -1744,6 +1814,18 @@ bool riscv_cpu_tlb_fill(CPUState *cs, vaddr address,= int size, HWADDR_FMT_plx " prot %d\n", __func__, address, ret, pa, prot); =20 + if (ret =3D=3D TRANSLATE_SUCCESS) { + ret =3D get_physical_address_mpt(env, &mpt_prot, pa, + access_type, mode); + if (riscv_cpu_cfg(env)->ext_smmpt) { + qemu_log_mask(CPU_LOG_MMU, + "%s MPT address=3D" HWADDR_FMT_plx " ret %d" + " prot %d\n", + __func__, pa, ret, mpt_prot); + } + prot &=3D mpt_prot; + } + if (ret =3D=3D TRANSLATE_SUCCESS) { ret =3D get_physical_address_pmp(env, &prot_pmp, pa, size, access_type, mode); @@ -1757,8 +1839,13 @@ bool riscv_cpu_tlb_fill(CPUState *cs, vaddr address,= int size, prot &=3D prot_pmp; } } - - if (ret =3D=3D TRANSLATE_PMP_FAIL || ret =3D=3D TRANSLATE_PMA_FAIL) { + /* + * Both MPT (Machine-level Memory Protection Table, Smmpt extension) a= nd + * PMP (Physical Memory Protection) follow the same exception reporting + * rule when an access violation is detected + */ + if (ret =3D=3D TRANSLATE_PMP_FAIL || ret =3D=3D TRANSLATE_PMA_FAIL || + ret =3D=3D TRANSLATE_MPT_FAIL) { pmp_pma_violation =3D true; } =20 --=20 2.43.0 From nobody Fri Jul 24 04:55:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1784837202; cv=none; d=zohomail.com; s=zohoarc; b=B/GAK3QzGXAfbPLufE0dcWEJ5X/6sRNjVWpNKS4olmeQ63sCnVacy2NyXH/SAucDLHPd7U6L/vPnDoXbeb+T7BCkrYyvzB7fHvMowru/vBOzJb+3NyFA3YkYK7XL8TyR8XhZTizbzXbobrxVG69EhhMECZSdmszUcsqPJOvXCz4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784837202; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=o9Tsn3g5F5bgE5q/yvCjG/dBWMS6cVPED04c2iL2CMg=; b=CRNTkF60l6JJf0EixQlPqhySJfl5RRx6Vdct9z29ko6mkmztju/brpJbUTlZTFWbDGvk9vRVDFs2vU7vk0kQMPiBc/yDTpk75gQBFm5//Vo9fmtj122I+VD3stAuPpwnPI6C4M+pRnFCHn8lNbuCBXe/0P56TuO11CEzlcVM4bc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784837202386927.1803682511999; Thu, 23 Jul 2026 13:06:42 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmzfF-00081E-TI; Thu, 23 Jul 2026 16:05:05 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmzeI-0007Pb-T5; Thu, 23 Jul 2026 16:04:07 -0400 Received: from [115.124.30.133] (helo=out30-133.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmzeA-0005Ru-Pd; Thu, 23 Jul 2026 16:04:06 -0400 Received: from localhost.localdomain(mailfrom:zhiwei_liu@linux.alibaba.com fp:SMTPD_---0X7h4UuV_1784837022 cluster:ay36) by smtp.aliyun-inc.com; Fri, 24 Jul 2026 04:03:42 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1784837023; h=From:To:Subject:Date:Message-Id:MIME-Version; bh=o9Tsn3g5F5bgE5q/yvCjG/dBWMS6cVPED04c2iL2CMg=; b=tKVyFowZ5d5BDs8mpuof51t5dQ4/f/IvfAY2jTQZq8dV50SnbsfBcKUPmU4b+rG3iP1EamIq0sLdPVJDAeJZUvFFQ4vZIZtthxoRLQdzWXGbo6g+R/JywR3que7mKdCLfn5poRZrUBxuxCSDRWXFMO8weJt0YPHcTNMpP3iHJMU= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R791e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033037033178; MF=zhiwei_liu@linux.alibaba.com; NM=1; PH=DS; RN=13; SR=0; TI=SMTPD_---0X7h4UuV_1784837022; From: LIU Zhiwei To: qemu-devel@nongnu.org Cc: palmer@dabbelt.com, alistair.francis@wdc.com, daniel.barboza@oss.qualcomm.com, chao.liu.zevorn@gmail.com, liwei1518@gmail.com, qemu-riscv@nongnu.org, rahul@summations.net, xiangyi.zeng@linux.alibaba.com, cxx194832@alibaba-inc.com, LIU Zhiwei , Huang Tao , TANG Tiancheng Subject: [PATCH v8 05/11] target/riscv: Implement SMMPT fence instructions Date: Fri, 24 Jul 2026 04:03:19 +0800 Message-Id: <20260723200325.24969-6-zhiwei_liu@linux.alibaba.com> X-Mailer: git-send-email 2.39.3 (Apple Git-146) In-Reply-To: <20260723200325.24969-1-zhiwei_liu@linux.alibaba.com> References: <20260723200325.24969-1-zhiwei_liu@linux.alibaba.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.133 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.133; envelope-from=zhiwei_liu@linux.alibaba.com; helo=out30-133.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1784837203609158500 Content-Type: text/plain; charset="utf-8" This patch completes the SMMPT implementation by adding support for the new fence instructions: `mfence.pa` and `minval.pa`. According to the specification, these instructions act as memory ordering fences for MPT updates. In QEMU's TCG model, this is conservatively implemented by flushing the entire TLB, which ensures that any subsequent memory accesses will re-evaluate permissions and see the effects of any pri= or MPT modifications. The instructions are privileged and will cause an illegal instruction exception if executed outside of M-mode. Co-authored-by: Huang Tao Co-authored-by: TANG Tiancheng Signed-off-by: LIU Zhiwei --- target/riscv/insn32.decode | 2 ++ .../tcg/insn_trans/trans_privileged.c.inc | 30 +++++++++++++++++++ 2 files changed, 32 insertions(+) diff --git a/target/riscv/insn32.decode b/target/riscv/insn32.decode index 21272fdb50..f0917b7696 100644 --- a/target/riscv/insn32.decode +++ b/target/riscv/insn32.decode @@ -120,6 +120,8 @@ sret 0001000 00010 00000 000 00000 1110011 mret 0011000 00010 00000 000 00000 1110011 wfi 0001000 00101 00000 000 00000 1110011 sfence_vma 0001001 ..... ..... 000 00000 1110011 @sfence_vma +mfence_pa 0011001 ..... ..... 000 00000 1110011 @sfence_vma +minval_pa 0011011 ..... ..... 000 00000 1110011 @sfence_vma =20 # *** NMI *** mnret 0111000 00010 00000 000 00000 1110011 diff --git a/target/riscv/tcg/insn_trans/trans_privileged.c.inc b/target/ri= scv/tcg/insn_trans/trans_privileged.c.inc index a8eaccef67..67f2e56034 100644 --- a/target/riscv/tcg/insn_trans/trans_privileged.c.inc +++ b/target/riscv/tcg/insn_trans/trans_privileged.c.inc @@ -160,3 +160,33 @@ static bool trans_sfence_vma(DisasContext *ctx, arg_sf= ence_vma *a) #endif return false; } + +#define REQUIRE_SMSDID(ctx) do { \ + if (!ctx->cfg_ptr->ext_smsdid) { \ + return false; \ + } \ +} while (0) + +static bool do_mfence_pa(DisasContext *ctx) +{ +#ifndef CONFIG_USER_ONLY + REQUIRE_SMSDID(ctx); + if (ctx->priv !=3D PRV_M) { + return false; + } + decode_save_opc(ctx, 0); + gen_helper_tlb_flush_all(tcg_env); + return true; +#endif + return false; +} + +static bool trans_mfence_pa(DisasContext *ctx, arg_mfence_pa *a) +{ + return do_mfence_pa(ctx); +} + +static bool trans_minval_pa(DisasContext *ctx, arg_minval_pa *a) +{ + return do_mfence_pa(ctx); +} --=20 2.43.0 From nobody Fri Jul 24 04:55:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1784837234; cv=none; d=zohomail.com; s=zohoarc; b=fDStVysqQ5kijv3z75BOE4SF6cPFdQWhl2QTM+khDu50cIw/qu83PKvUmb1EpWASGfqRxyQirJn/qPVmUVslVNM9u5ucNjS59ZRQw2w0g0GWOR6KQW315xjUPWHvjsSOHZVT1Liml2KFDsxOArlOSiJh5EF4KpEDC8MHzj/II5c= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784837234; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=nyh9B34myKsqusGo6Xsw3p8tQRU7+kZFJbdmy6yn90A=; b=mlmGGRgafH+SAaLbl4XsuHftItc7Ai4IIyiqopp5hltUSHPOsKRsSz30iBm17u42uJa3KNKzZIFC+X2vrsbF7exjTkJZ1z8U9dKlb1q9JMQa3xkKlfeo7nnmc7VOIC/2pTEBcmTYjIZVF6dkRAUmPVwg6sEyXVXarlKqg7fllOI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784837234674554.8986769216481; Thu, 23 Jul 2026 13:07:14 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmzfE-0007oL-9O; Thu, 23 Jul 2026 16:05:04 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmzeH-0007OT-Jj; Thu, 23 Jul 2026 16:04:06 -0400 Received: from [115.124.30.112] (helo=out30-112.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmzeA-0005Rx-Ln; Thu, 23 Jul 2026 16:04:03 -0400 Received: from localhost.localdomain(mailfrom:zhiwei_liu@linux.alibaba.com fp:SMTPD_---0X7h4Uuk_1784837022 cluster:ay36) by smtp.aliyun-inc.com; Fri, 24 Jul 2026 04:03:43 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1784837024; h=From:To:Subject:Date:Message-Id:MIME-Version; bh=nyh9B34myKsqusGo6Xsw3p8tQRU7+kZFJbdmy6yn90A=; b=oSuCaH3GyaZomv1ud9Ay+1q8HQm4H4FlT4ACPcpAAMsPvTswKygS7r97XGrk+CD2SQPGLMSkFOeo7e/ZzPHV7M9Fy3jEaPjIWUuLLCvjJMlTXPW90UPA9lkZRRClV4cYRQ+0gxeKkrLgUq5TtmP1M0k9+aTWDZKOyDUYXCCAKvo= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R101e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033037026112; MF=zhiwei_liu@linux.alibaba.com; NM=1; PH=DS; RN=13; SR=0; TI=SMTPD_---0X7h4Uuk_1784837022; From: LIU Zhiwei To: qemu-devel@nongnu.org Cc: palmer@dabbelt.com, alistair.francis@wdc.com, daniel.barboza@oss.qualcomm.com, chao.liu.zevorn@gmail.com, liwei1518@gmail.com, qemu-riscv@nongnu.org, rahul@summations.net, xiangyi.zeng@linux.alibaba.com, cxx194832@alibaba-inc.com, LIU Zhiwei , Daniel Henrique Barboza , Frank Chang Subject: [PATCH v8 06/11] target/riscv: Fix smrnmi isa alphabetical order Date: Fri, 24 Jul 2026 04:03:20 +0800 Message-Id: <20260723200325.24969-7-zhiwei_liu@linux.alibaba.com> X-Mailer: git-send-email 2.39.3 (Apple Git-146) In-Reply-To: <20260723200325.24969-1-zhiwei_liu@linux.alibaba.com> References: <20260723200325.24969-1-zhiwei_liu@linux.alibaba.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.112 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.112; envelope-from=zhiwei_liu@linux.alibaba.com; helo=out30-112.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1784837235643158500 Content-Type: text/plain; charset="utf-8" Signed-off-by: LIU Zhiwei Suggested-by: Daniel Henrique Barboza Reviewed-by: Daniel Henrique Barboza Reviewed-by: Alistair Francis Reviewed-by: Frank Chang Reviewed-by: Chao Liu --- target/riscv/cpu.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/target/riscv/cpu.c b/target/riscv/cpu.c index 0f96e487fa..727b2924a6 100644 --- a/target/riscv/cpu.c +++ b/target/riscv/cpu.c @@ -264,9 +264,9 @@ const RISCVIsaExtData isa_edata_arr[] =3D { ISA_EXT_DATA_ENTRY(smdbltrp, PRIV_VERSION_1_13_0, ext_smdbltrp), ISA_EXT_DATA_ENTRY(smepmp, PRIV_VERSION_1_12_0, ext_smepmp), ISA_EXT_DATA_ENTRY(smpmpmt, PRIV_VERSION_1_12_0, ext_smpmpmt), - ISA_EXT_DATA_ENTRY(smrnmi, PRIV_VERSION_1_12_0, ext_smrnmi), ISA_EXT_DATA_ENTRY(smmpm, PRIV_VERSION_1_13_0, ext_smmpm), ISA_EXT_DATA_ENTRY(smnpm, PRIV_VERSION_1_13_0, ext_smnpm), + ISA_EXT_DATA_ENTRY(smrnmi, PRIV_VERSION_1_12_0, ext_smrnmi), ISA_EXT_DATA_ENTRY(smstateen, PRIV_VERSION_1_12_0, ext_smstateen), ISA_EXT_DATA_ENTRY(ssaia, PRIV_VERSION_1_12_0, ext_ssaia), ISA_EXT_DATA_ENTRY(ssccfg, PRIV_VERSION_1_13_0, ext_ssccfg), --=20 2.43.0 From nobody Fri Jul 24 04:55:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1784837154; cv=none; d=zohomail.com; s=zohoarc; b=VEhvUvvfuIiZJnuncuNvunHYs5+xCeLjVkCm30CSmNpPc6Itj1Gg9DAKGMmervYfSpSsUZrYGmeu2gzeODk8AKkxANdnP6+b9YKTGf0YQYc6jaHYqYL8usIFaLY/cMH9EyUQECvlSTXw2bjzrPwiIO/WOA/Zhr7H2AwNNoRMLNM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784837154; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Z7ScyqJhyuMD43cubZw/XBiC8G2Ld3c8D9YYFkOZP9k=; b=EqlZod+OSBahUoWHRZ0SA+Z6sfbV5y9xze5dIE67QY1xiNj83CmeDgePPRIGcjSbFmuEZI7cT2G3OsCjLtcNWhIvBwMUHY9j2diJZEaPWQm+Zfyy95WndQNyI/vrv7MgXxORd9BsUXWFcREJDfJsWZeCWpsAiWSN4+6pEraO38k= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784837154795655.5207015889844; Thu, 23 Jul 2026 13:05:54 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmzeu-0007WL-NG; Thu, 23 Jul 2026 16:04:46 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmzeH-0007OV-TT; Thu, 23 Jul 2026 16:04:06 -0400 Received: from [115.124.30.119] (helo=out30-119.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmzeA-0005Ry-PX; Thu, 23 Jul 2026 16:04:05 -0400 Received: from localhost.localdomain(mailfrom:zhiwei_liu@linux.alibaba.com fp:SMTPD_---0X7h4UvA_1784837023 cluster:ay36) by smtp.aliyun-inc.com; Fri, 24 Jul 2026 04:03:44 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1784837024; h=From:To:Subject:Date:Message-Id:MIME-Version; bh=Z7ScyqJhyuMD43cubZw/XBiC8G2Ld3c8D9YYFkOZP9k=; b=I2jKDW7bzJM9Vy4KhZzuNGPcNiJ1pdwshYPio5+jjXfyHzUVHKnP/4KY/VD6ciqQKWTI7Of7eDk4x1srCCISElPresgdm+EPOakr2752viqySHZ9Mn9s+MTA+0nmlemJAow0AL+oCmrPtkg1zQFYCtf4e0n49zahU/veqtVxHxY= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R411e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033037009110; MF=zhiwei_liu@linux.alibaba.com; NM=1; PH=DS; RN=11; SR=0; TI=SMTPD_---0X7h4UvA_1784837023; From: LIU Zhiwei To: qemu-devel@nongnu.org Cc: palmer@dabbelt.com, alistair.francis@wdc.com, daniel.barboza@oss.qualcomm.com, chao.liu.zevorn@gmail.com, liwei1518@gmail.com, qemu-riscv@nongnu.org, rahul@summations.net, xiangyi.zeng@linux.alibaba.com, cxx194832@alibaba-inc.com, LIU Zhiwei Subject: [PATCH v8 07/11] target/riscv: Add disassembly for Smmpt instructions and CSRs Date: Fri, 24 Jul 2026 04:03:21 +0800 Message-Id: <20260723200325.24969-8-zhiwei_liu@linux.alibaba.com> X-Mailer: git-send-email 2.39.3 (Apple Git-146) In-Reply-To: <20260723200325.24969-1-zhiwei_liu@linux.alibaba.com> References: <20260723200325.24969-1-zhiwei_liu@linux.alibaba.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.119 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.119; envelope-from=zhiwei_liu@linux.alibaba.com; helo=out30-119.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1784837155280158500 Content-Type: text/plain; charset="utf-8" Add disassembly support to the RISC-V disassembler for the machine CSRs and fence instructions introduced by the Smmpt/Smsdid series: - CSRs: mmpt (0x382), msdcfg (0x74e) - Instructions: mfence.pa, minval.pa Note that CSR 0x382 was previously mapped to the obsolete "mibase" register from the removed base-and-bound draft; it is now reused by Smmpt for mmpt. Signed-off-by: LIU Zhiwei --- disas/riscv.c | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/disas/riscv.c b/disas/riscv.c index 7f1b262773..8fdae54449 100644 --- a/disas/riscv.c +++ b/disas/riscv.c @@ -990,6 +990,8 @@ typedef enum { rv_op_cbo_flush =3D 958, rv_op_cbo_zero =3D 959, rv_op_mnret =3D 960, + rv_op_mfence_pa =3D 961, + rv_op_minval_pa =3D 962, } rv_op; =20 /* register names */ @@ -2265,6 +2267,8 @@ const rv_opcode_data rvi_opcode_data[] =3D { { "cbo.flush", rv_codec_r, rv_fmt_rs1, NULL, 0, 0, 0 }, { "cbo.zero", rv_codec_r, rv_fmt_rs1, NULL, 0, 0, 0 }, { "mnret", rv_codec_none, rv_fmt_none, NULL, 0, 0, 0 }, + { "mfence.pa", rv_codec_r, rv_fmt_rs1_rs2, NULL, 0, 0, 0 }, + { "minval.pa", rv_codec_r, rv_fmt_rs1_rs2, NULL, 0, 0, 0 }, }; =20 /* CSR names */ @@ -2356,7 +2360,7 @@ static const char *csr_name(int csrno) case 0x0344: return "mip"; case 0x0380: return "mbase"; case 0x0381: return "mbound"; - case 0x0382: return "mibase"; + case 0x0382: return "mmpt"; case 0x0383: return "mibound"; case 0x0384: return "mdbase"; case 0x0385: return "mdbound"; @@ -2440,6 +2444,7 @@ static const char *csr_name(int csrno) case 0x03ed: return "pmpaddr61"; case 0x03ee: return "pmpaddr62"; case 0x03ef: return "pmpaddr63"; + case 0x074e: return "msdcfg"; case 0x0780: return "mtohost"; case 0x0781: return "mfromhost"; case 0x0782: return "mreset"; @@ -4079,6 +4084,8 @@ static void decode_inst_opcode(rv_decode *dec, rv_isa= isa) case 64: op =3D rv_op_mret; break; } break; + case 800: op =3D rv_op_mfence_pa; break; + case 864: op =3D rv_op_minval_pa; break; case 1792: switch ((inst >> 15) & 0b1111111111) { case 64: op =3D rv_op_mnret; break; --=20 2.43.0 From nobody Fri Jul 24 04:55:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1784837177; cv=none; d=zohomail.com; s=zohoarc; b=FwQF6wqHPEQ/cCMKuCmVWrUPklGxHkz2YGEZLHNSRO1rvZfoPAssWAYQYcm5c+W4JROrJfxYPhLSN46qc2tFT5eh6GXHF7szRmdT/hNrlcv9+wwkgjN7ugwqrS93dW8h56H0dT6kr/UuiQAVDXGfr+euuqN4qD6cbYxQWTsgBY4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784837177; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=kBj5yGMNBRtpEDFstFG2ij4l26e7v+8t99VjblvjH+I=; b=LyWGVoJCpFWet4BIjjuTK/+lNSWBOF6EmaJasQQfNxAVFMkCQdNlR/Bx2Tq8Txlb3a5nqQlZS1Jw1FitPkzEqoldkiugUHs5cWB/svGY3/cXPV9CM2yPP97Rt56Oa3EyEbGM3FtBCpFnAbj4WLV77wuCsEhKmr62C05kXzrh9I8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784837177037657.3185599659583; Thu, 23 Jul 2026 13:06:17 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmzfE-0007w4-CG; Thu, 23 Jul 2026 16:05:04 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmzeI-0007Ol-PA; Thu, 23 Jul 2026 16:04:07 -0400 Received: from [115.124.30.124] (helo=out30-124.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmzeA-0005S4-P0; Thu, 23 Jul 2026 16:04:06 -0400 Received: from localhost.localdomain(mailfrom:zhiwei_liu@linux.alibaba.com fp:SMTPD_---0X7h4Uvj_1784837024 cluster:ay36) by smtp.aliyun-inc.com; Fri, 24 Jul 2026 04:03:44 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1784837026; h=From:To:Subject:Date:Message-Id:MIME-Version; bh=kBj5yGMNBRtpEDFstFG2ij4l26e7v+8t99VjblvjH+I=; b=sTx63gZ4hxGfKKjQvOTEvP5RL9BhXhpWNe7bJAkHSk3ZYSDogOXZItZllsQAleMYF0QeqKuKo+6k8pUEoBuw6nKcxONo+P/IKP/8WOs9K84VGS9xfm/jN4qnmRO3Y5vxL9bC7jXj3euGT0gLnuL/ZJunlzcYl9iilD9NZecsobY= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R901e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033037033178; MF=zhiwei_liu@linux.alibaba.com; NM=1; PH=DS; RN=15; SR=0; TI=SMTPD_---0X7h4Uvj_1784837024; From: LIU Zhiwei To: qemu-devel@nongnu.org Cc: palmer@dabbelt.com, alistair.francis@wdc.com, daniel.barboza@oss.qualcomm.com, chao.liu.zevorn@gmail.com, liwei1518@gmail.com, qemu-riscv@nongnu.org, rahul@summations.net, xiangyi.zeng@linux.alibaba.com, cxx194832@alibaba-inc.com, LIU Zhiwei , Huang Tao , TANG Tiancheng , Daniel Henrique Barboza , Frank Chang Subject: [PATCH v8 08/11] target/riscv: Enable SMMPT extension Date: Fri, 24 Jul 2026 04:03:22 +0800 Message-Id: <20260723200325.24969-9-zhiwei_liu@linux.alibaba.com> X-Mailer: git-send-email 2.39.3 (Apple Git-146) In-Reply-To: <20260723200325.24969-1-zhiwei_liu@linux.alibaba.com> References: <20260723200325.24969-1-zhiwei_liu@linux.alibaba.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.124 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.124; envelope-from=zhiwei_liu@linux.alibaba.com; helo=out30-124.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1784837177412158500 Content-Type: text/plain; charset="utf-8" This patch implements v0.4.9 SMMPT specification(https://github.com/riscv/riscv-smmtt/releases/tag/v0.4.9). Co-authored-by: Huang Tao Co-authored-by: TANG Tiancheng Signed-off-by: LIU Zhiwei Reviewed-by: Daniel Henrique Barboza Reviewed-by: Chao Liu Reviewed-by: Frank Chang --- target/riscv/cpu.c | 13 ++++++++++++- 1 file changed, 12 insertions(+), 1 deletion(-) diff --git a/target/riscv/cpu.c b/target/riscv/cpu.c index 727b2924a6..5f8455dae2 100644 --- a/target/riscv/cpu.c +++ b/target/riscv/cpu.c @@ -265,8 +265,10 @@ const RISCVIsaExtData isa_edata_arr[] =3D { ISA_EXT_DATA_ENTRY(smepmp, PRIV_VERSION_1_12_0, ext_smepmp), ISA_EXT_DATA_ENTRY(smpmpmt, PRIV_VERSION_1_12_0, ext_smpmpmt), ISA_EXT_DATA_ENTRY(smmpm, PRIV_VERSION_1_13_0, ext_smmpm), + ISA_EXPERIMENTAL_EXT_DATA_ENTRY(smmpt, PRIV_VERSION_1_13_0, ext_smmpt), ISA_EXT_DATA_ENTRY(smnpm, PRIV_VERSION_1_13_0, ext_smnpm), ISA_EXT_DATA_ENTRY(smrnmi, PRIV_VERSION_1_12_0, ext_smrnmi), + ISA_EXPERIMENTAL_EXT_DATA_ENTRY(smsdid, PRIV_VERSION_1_13_0, ext_smsdi= d), ISA_EXT_DATA_ENTRY(smstateen, PRIV_VERSION_1_12_0, ext_smstateen), ISA_EXT_DATA_ENTRY(ssaia, PRIV_VERSION_1_12_0, ext_ssaia), ISA_EXT_DATA_ENTRY(ssccfg, PRIV_VERSION_1_13_0, ext_ssccfg), @@ -2852,6 +2854,15 @@ static RISCVCPUImpliedExtsRule ZVFBFA_IMPLIED =3D { }, }; =20 +static RISCVCPUImpliedExtsRule SMMPT_IMPLIED =3D { + .ext =3D CPU_CFG_OFFSET(ext_smmpt), + .implied_multi_exts =3D { + CPU_CFG_OFFSET(ext_smsdid), + + RISCV_IMPLIED_EXTS_RULE_END + }, +}; + RISCVCPUImpliedExtsRule *riscv_misa_ext_implied_rules[] =3D { &RVA_IMPLIED, &RVD_IMPLIED, &RVF_IMPLIED, &RVM_IMPLIED, &RVV_IMPLIED, &RVG_IMPLIED, @@ -2873,7 +2884,7 @@ RISCVCPUImpliedExtsRule *riscv_multi_ext_implied_rule= s[] =3D { &ZVKS_IMPLIED, &ZVKSC_IMPLIED, &ZVKSG_IMPLIED, &SHA_IMPLIED, &SSCFG_IMPLIED, &SUPM_IMPLIED, &SSPM_IMPLIED, &SMCTR_IMPLIED, &SSCTR_IMPLIED, &SSSTATEEN_IMPLIED, - NULL + &SMMPT_IMPLIED, NULL }; =20 static const Property riscv_cpu_properties[] =3D { --=20 2.43.0 From nobody Fri Jul 24 04:55:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1784837089; cv=none; d=zohomail.com; s=zohoarc; b=N75IwzAJrScTSW2phAfgSS+AgMASVXbwfl8dxPN6QfH3gAkB4UCxDsMVFShUQgdO0ipBOXh+rxSsVSbNk28CVZ6s6xLAgRs4DtpTeKj9x1ZXzeM7aic2ojkyma4yVG4wBdxnVBEEejxloet9+2dzncCBBH+BP8O4CKgmhDrEg7Q= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784837089; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=YZeWaiS6fuLwx9Xkrp3dK8yuipuHKK+sT+MR5ZcDcT4=; b=J9PdAqkeQhm1KdLs5HHKLyg8RoPUF1TJfrzkBrdGvd+7Fb5mPYUtCiPKZajYT7673uwJxE3kdzXGkdM9qag1YZWEVEjb3KOCuq33rB7Mlwj8BAdMxeo3gtIMuR4z54HdgCq7ENAwN3m2Dxv7YXSAV9Fp0UtT9GmxKzDfw70XZXY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784837089655858.4944387297941; Thu, 23 Jul 2026 13:04:49 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmzeP-0007Rl-VD; Thu, 23 Jul 2026 16:04:16 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmzeH-0007OR-JY; Thu, 23 Jul 2026 16:04:06 -0400 Received: from [115.124.30.98] (helo=out30-98.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmzeA-0005SD-Lx; Thu, 23 Jul 2026 16:04:04 -0400 Received: from localhost.localdomain(mailfrom:zhiwei_liu@linux.alibaba.com fp:SMTPD_---0X7h4Uw9_1784837025 cluster:ay36) by smtp.aliyun-inc.com; Fri, 24 Jul 2026 04:03:45 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1784837027; h=From:To:Subject:Date:Message-Id:MIME-Version; bh=YZeWaiS6fuLwx9Xkrp3dK8yuipuHKK+sT+MR5ZcDcT4=; b=f3LQL3wHNA4bzM8h2fW4i0K2ILSfY03+x0+pYpVaJj91s+K6nDPjWk8BSAyUMXx6qkql2hdYNHCWS7g/RU6y0CnG2vZQ9aKXqARDufsz/5giGVfTv4i/IODQq47ilZFUzPx90IeE3HdIXDti2Ypfw/1H5bccStIPTDk+uI79y1I= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R161e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033037026112; MF=zhiwei_liu@linux.alibaba.com; NM=1; PH=DS; RN=11; SR=0; TI=SMTPD_---0X7h4Uw9_1784837025; From: LIU Zhiwei To: qemu-devel@nongnu.org Cc: palmer@dabbelt.com, alistair.francis@wdc.com, daniel.barboza@oss.qualcomm.com, chao.liu.zevorn@gmail.com, liwei1518@gmail.com, qemu-riscv@nongnu.org, rahul@summations.net, xiangyi.zeng@linux.alibaba.com, cxx194832@alibaba-inc.com, LIU Zhiwei Subject: [PATCH v8 09/11] target/riscv: Add system test for SMMPT extension Date: Fri, 24 Jul 2026 04:03:23 +0800 Message-Id: <20260723200325.24969-10-zhiwei_liu@linux.alibaba.com> X-Mailer: git-send-email 2.39.3 (Apple Git-146) In-Reply-To: <20260723200325.24969-1-zhiwei_liu@linux.alibaba.com> References: <20260723200325.24969-1-zhiwei_liu@linux.alibaba.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.98 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.98; envelope-from=zhiwei_liu@linux.alibaba.com; helo=out30-98.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1784837091089158500 Content-Type: text/plain; charset="utf-8" Add a bare-metal M-mode assembly test (test-smmpt.S) that validates the Smmpt43 MPT lookup and permission enforcement against SMMTT v0.4.9. The test builds a 3-level Smmpt43 MPT in RAM and uses the MPRV trick (mstatus.MPRV=3D1, MPP=3DS, satp=3DBare) so that data accesses are subject = to MPT checks while instruction fetches remain in M-mode (which bypasses the MPT). PMP is configured to grant all permissions so that only the MPT gates the accesses. Coverage: mfence.pa in M-mode; every XWR encoding (RW, no-access, R-only, R+X, RWX, the reserved 010/110 encodings and X-only) checked for both load and store, verifying the correct exception cause (load access fault =3D 5, store/AMO access fault =3D 7); an invalid (V=3D0) leaf; a leaf with a reserved bit set; and NAPOT leaves with a valid and a reserved G field. The mode-independent harness (MPRV helpers, per-access check/verify subroutines, the M-mode trap handler and the semihosting exit) lives in a shared smmpt-common.S so the Smmpt52/Smmpt64/Smmpt34 tests can reuse it. Signed-off-by: LIU Zhiwei --- tests/tcg/riscv64/Makefile.softmmu-target | 4 + tests/tcg/riscv64/smmpt-common.S | 257 ++++++++++++++++++++++ tests/tcg/riscv64/test-smmpt.S | 85 +++++++ 3 files changed, 346 insertions(+) create mode 100644 tests/tcg/riscv64/smmpt-common.S create mode 100644 tests/tcg/riscv64/test-smmpt.S diff --git a/tests/tcg/riscv64/Makefile.softmmu-target b/tests/tcg/riscv64/= Makefile.softmmu-target index 82be8a2c91..18da9c6299 100644 --- a/tests/tcg/riscv64/Makefile.softmmu-target +++ b/tests/tcg/riscv64/Makefile.softmmu-target @@ -41,5 +41,9 @@ comma:=3D , run-test-crc32: test-crc32 $(call run-test, $<, $(QEMU) -cpu rv64$(comma)xlrbr=3Dtrue $(QEMU_OPTS)$<) =20 +EXTRA_RUNS +=3D run-test-smmpt +run-test-smmpt: test-smmpt + $(call run-test, $<, $(QEMU) -cpu rv64$(comma)x-smmpt=3Dtrue $(QEMU_OPTS)= $<) + # We don't currently support the multiarch system tests undefine MULTIARCH_TESTS diff --git a/tests/tcg/riscv64/smmpt-common.S b/tests/tcg/riscv64/smmpt-com= mon.S new file mode 100644 index 0000000000..3a3b10ed53 --- /dev/null +++ b/tests/tcg/riscv64/smmpt-common.S @@ -0,0 +1,257 @@ +/* + * SPDX-License-Identifier: GPL-2.0-or-later + * + * Shared harness for the Smmpt (Supervisor Memory Protection Table) system + * tests, per SMMTT specification v0.4.9. + * + * This header is meant to be #included by the per-mode Smmpt test programs + * (Smmpt34 on RV32, Smmpt43/52/64 on RV64). All the mode-independent log= ic + * lives here so each test only has to build its mode-specific MPT and inv= oke + * RUN_LEAF_CHECKS. + * + * The tests run in M-mode and use the MPRV trick (mstatus.MPRV=3D1, + * mstatus.MPP=3DS, satp=3DBare so PA=3D=3DVA) to subject explicit data ac= cesses to + * MPT checks while the instruction stream keeps running in M-mode (M-mode + * fetches bypass the MPT). The data-access width is irrelevant to the MPT + * check, so the harness uses lw/sw and works unmodified on RV32 and RV64. + * + * The MPT XWR field uses the standard bit order R=3Dbit0, W=3Dbit1, X=3Db= it2 + * (matching QEMU PAGE_READ/PAGE_WRITE/PAGE_EXEC), so Read+Write is 0b011= =3D3. + * Per the spec the exception is reported for the original access type: a = load + * violation raises "load access fault" (cause 5) and a store violation ra= ises + * "store/AMO access fault" (cause 7). + * + * Execute permission is not exercised: the MPRV trick only redirects data + * accesses, while instruction fetch stays in M-mode and bypasses the MPT. + * X-bearing encodings are therefore checked only for their load/store + * behaviour (e.g. X-only denies loads, R+X denies stores). + * + * The tests expect an MPT laid out so that these supervisor physical + * addresses resolve as follows (identical across all modes): + * + * 0x8050_0000..0x8050_7000 non-NAPOT leaf, XWR[pi] tuples (LEAF_ALL_XW= R): + * pi0 011 (RW) pi1 000 (no access) + * pi2 001 (R) pi3 101 (R+X) + * pi4 111 (RWX) pi5 010 (reserved) + * pi6 110 (rsvd) pi7 100 (X only) + * 0x8051_0000 invalid leaf (V=3D0) + * 0x8052_0000 leaf with a reserved bit set + * 0x8060_0000 NAPOT leaf with a valid G + * 0x8080_0000 NAPOT leaf with a reserved G + * + * On any mismatch the test exits (via semihosting) with a non-zero code t= hat + * identifies the failing check; a successful run exits with 0. + */ + + /* mstatus bits (same positions on RV32 and RV64) */ + .equ MSTATUS_MPP_S, (1 << 11) /* MPP =3D 01 (Supervisor) */ + .equ MSTATUS_MPP_M, (3 << 11) /* MPP mask */ + .equ MSTATUS_MPRV, (1 << 17) + + /* Expected fault causes */ + .equ CAUSE_LOAD_ACCESS_FAULT, 5 + .equ CAUSE_STORE_ACCESS_FAULT, 7 + + .equ EXPECT_OK, 0 + .equ EXPECT_FAULT, 1 + + /* + * Non-NAPOT leaf value carrying all eight XWR encodings in pi0..pi7: + * V|L | pi0=3D011 pi1=3D000 pi2=3D001 pi3=3D101 + * pi4=3D111 pi5=3D010 pi6=3D110 pi7=3D100 + * The XWR tuples occupy bits [31:8], valid for both the 4-byte (RV32) + * and 8-byte (RV64) leaf formats. + */ + .equ LEAF_ALL_XWR, 0x997A4303 + + /* + * Switch the effective privilege of data accesses to S-mode so that + * they are subject to MPT checks (MPP=3DS, MPRV=3D1). Uses t0 only. + */ + .macro ENTER_MPRV + li t0, MSTATUS_MPP_M + csrc mstatus, t0 /* clear MPP */ + li t0, MSTATUS_MPP_S + csrs mstatus, t0 /* MPP =3D S */ + li t0, MSTATUS_MPRV + csrs mstatus, t0 /* enable MPRV */ + .endm + + .macro EXIT_MPRV + li t0, MSTATUS_MPRV + csrc mstatus, t0 /* disable MPRV */ + .endm + + /* + * Perform an MPT-checked load/store from \addr and verify the outcome. + * \eflt : EXPECT_OK or EXPECT_FAULT + * \ecause : expected mcause when a fault is expected + * \code : exit code reported if the check fails + */ + .macro TEST_LOAD addr, eflt, ecause, code + li a3, \addr + jal do_load + li a4, \eflt + li a5, \ecause + li a6, \code + jal check + .endm + + .macro TEST_STORE addr, eflt, ecause, code + li a3, \addr + li t3, 0x1234 + jal do_store + li a4, \eflt + li a5, \ecause + li a6, \code + jal check + .endm + + /* + * MFENCE.PA (funct7=3D0b0011001) must not fault in M-mode. Reuses the + * generic check subroutine (expects no fault). + */ + .macro TEST_MFENCE_PA code + li s0, 0 + .insn r 0x73, 0, 0x19, x0, x0, x0 + li a4, EXPECT_OK + li a6, \code + jal check + .endm + + /* + * Run the full set of MPT permission and structural checks against the + * shared address layout described above. + */ + .macro RUN_LEAF_CHECKS + /* pi0 RW: load and store both allowed */ + TEST_LOAD 0x80500000, EXPECT_OK, 0, 2 + TEST_STORE 0x80500000, EXPECT_OK, 0, 3 + /* pi1 no-access: load faults (cause 5), store faults (cause 7) */ + TEST_LOAD 0x80501000, EXPECT_FAULT, CAUSE_LOAD_ACCESS_FAULT, 4 + TEST_STORE 0x80501000, EXPECT_FAULT, CAUSE_STORE_ACCESS_FAULT, 5 + /* pi2 R-only: load allowed, store faults */ + TEST_LOAD 0x80502000, EXPECT_OK, 0, 6 + TEST_STORE 0x80502000, EXPECT_FAULT, CAUSE_STORE_ACCESS_FAULT, 7 + /* pi3 R+X: load allowed, store faults */ + TEST_LOAD 0x80503000, EXPECT_OK, 0, 8 + TEST_STORE 0x80503000, EXPECT_FAULT, CAUSE_STORE_ACCESS_FAULT, 9 + /* pi4 RWX: load and store both allowed */ + TEST_LOAD 0x80504000, EXPECT_OK, 0, 10 + TEST_STORE 0x80504000, EXPECT_OK, 0, 11 + /* pi5/pi6 reserved encodings (010/110): load faults (cause 5) */ + TEST_LOAD 0x80505000, EXPECT_FAULT, CAUSE_LOAD_ACCESS_FAULT, 12 + TEST_LOAD 0x80506000, EXPECT_FAULT, CAUSE_LOAD_ACCESS_FAULT, 13 + /* pi7 X-only: load faults (cause 5) */ + TEST_LOAD 0x80507000, EXPECT_FAULT, CAUSE_LOAD_ACCESS_FAULT, 14 + /* invalid leaf (V=3D0): load faults (cause 5) */ + TEST_LOAD 0x80510000, EXPECT_FAULT, CAUSE_LOAD_ACCESS_FAULT, 15 + /* leaf with a reserved bit set: load faults (cause 5) */ + TEST_LOAD 0x80520000, EXPECT_FAULT, CAUSE_LOAD_ACCESS_FAULT, 16 + /* NAPOT leaf, valid G, RW: load and store both allowed */ + TEST_LOAD 0x80600000, EXPECT_OK, 0, 17 + TEST_STORE 0x80600000, EXPECT_OK, 0, 18 + /* NAPOT leaf with a reserved G: load faults (cause 5) */ + TEST_LOAD 0x80800000, EXPECT_FAULT, CAUSE_LOAD_ACCESS_FAULT, 19 + .endm + + /* + * Emit the shared subroutines, trap handler, semihosting exit and data. + * Invoke once, after the test's _start code. + */ + .macro SMMPT_HARNESS + /* + * do_load / do_store: perform one MPT-checked access from a3. + * On return, s0 =3D 1 if the access faulted (else 0) and s1 =3D mcause. + * do_store uses the value in t3. lw/sw keep these width-agnostic. + */ + .balign 4 +do_load: + li s0, 0 + li s1, 0 + ENTER_MPRV + lw t4, 0(a3) /* MPT-checked load */ + EXIT_MPRV + ret + +do_store: + li s0, 0 + li s1, 0 + ENTER_MPRV + sw t3, 0(a3) /* MPT-checked store */ + EXIT_MPRV + ret + + /* + * check: verify the outcome of the last access. + * a4 =3D expected fault (0/1), a5 =3D expected cause, a6 =3D fail code. + * Returns on success; exits with a6 on mismatch. + */ + .balign 4 +check: + beqz a4, 1f + beqz s0, 2f /* expected a fault but none occurred */ + bne s1, a5, 2f /* faulted with the wrong cause */ + ret +1: + bnez s0, 2f /* unexpected fault */ + ret +2: + mv a0, a6 + j _exit + + /* + * M-mode trap handler. Records that a fault occurred (s0=3D1) and the + * mcause (s1), skips the faulting 4-byte instruction, disables MPRV + * and returns. Only clobbers t5/t6 besides s0/s1. + */ + .balign 4 +mtrap: + csrr t5, mcause + li s0, 1 + mv s1, t5 + csrr t6, mepc + addi t6, t6, 4 /* skip the faulting instruction */ + csrw mepc, t6 + li t5, MSTATUS_MPRV + csrc mstatus, t5 /* ensure MPRV is off on return */ + mret + + /* Exit via semihosting (ADP_Stopped_ApplicationExit) */ +_exit: +#if __riscv_xlen =3D=3D 32 + /* + * On RV32 the SYS_EXIT_EXTENDED parameter block cannot be used: when + * this test runs on qemu-system-riscv64 with a 32-bit CPU the block + * pointer is sign-extended (0xffffffff_8xxx_xxxx) and the semihosting + * argument read faults. Use the plain SYS_EXIT, which takes the exit + * reason directly in a1: a successful run (a0=3D=3D0) reports + * ADP_Stopped_ApplicationExit and any failure reports a non-zero + * reason (reported by QEMU as exit status 1). + */ + li a1, 0x20026 /* ADP_Stopped_ApplicationExit */ + beqz a0, 1f + mv a1, a0 /* non-zero reason -> exit status 1 */ +1: + li a0, 0x18 /* TARGET_SYS_EXIT */ +#else + lla a1, semiargs + li t0, 0x20026 + sd t0, 0(a1) + sd a0, 8(a1) + li a0, 0x20 /* TARGET_SYS_EXIT_EXTENDED */ +#endif + + .balign 16 + slli zero, zero, 0x1f + ebreak + srai zero, zero, 0x7 + j . + +#if __riscv_xlen !=3D 32 + .data + .balign 8 +semiargs: + .space 16 +#endif + .endm diff --git a/tests/tcg/riscv64/test-smmpt.S b/tests/tcg/riscv64/test-smmpt.S new file mode 100644 index 0000000000..f8da362629 --- /dev/null +++ b/tests/tcg/riscv64/test-smmpt.S @@ -0,0 +1,85 @@ +/* + * SPDX-License-Identifier: GPL-2.0-or-later + * + * Test for the Smmpt43 (Supervisor Memory Protection Table) extension, + * per SMMTT specification v0.4.9. + * + * The test runs in M-mode and builds a 3-level Smmpt43 MPT, then drives t= he + * mode-independent checks in smmpt-common.S. See that harness for the MP= RV + * trick, the shared address layout and the exit-code convention. + * + * MPT layout (Smmpt43, 3 levels, 8-byte entries, 16 pages per leaf, + * pi =3D SPA[15:12], pn[i] 9 bits at SPA[16 + i*9 +: 9]): + * + * L2 (root) @ 0x8040_0000 : entry[0] -> non-leaf, PPN(L1)=3D0x80410 + * L1 @ 0x8041_0000 : entry[64] -> non-leaf, PPN(L0)=3D0x80420 + * L0 @ 0x8042_0000 : + * entry[80] -> non-NAPOT leaf (LEAF_ALL_XWR) covering 0x8050_0000+ + * entry[81] -> V=3D0 (invalid) covering 0x8051_0000 + * entry[82] -> leaf with a reserved bit set covering 0x8052_0000 + * entry[96] -> NAPOT leaf, G=3D4, XWR=3DRW covering 0x8060_0= 000 + * entry[128] -> NAPOT leaf, reserved G=3D5 covering 0x8080_0000 + * + * mmpt =3D MODE(1=3DSmmpt43)<<60 | PPN(0x80400) + */ + +#include "smmpt-common.S" + + .option norvc + + .text + .global _start +_start: + /* Install the M-mode trap handler */ + lla t0, mtrap + csrw mtvec, t0 + csrw medeleg, zero + + /* PMP entry 0: NAPOT covering the whole space, RWX, so S-mode + * accesses pass PMP and the MPT is the only gate. */ + li t0, -1 + csrw pmpaddr0, t0 + li t0, 0x1f /* A=3DNAPOT(0x18) | R | W | X */ + csrw pmpcfg0, t0 + + /* Build the MPT tables (M-mode stores bypass the MPT). */ + /* L2[0] =3D non-leaf -> L1 (PPN 0x80410): (0x80410 << 10) | V */ + li t0, 0x80400000 + li t1, 0x20104001 + sd t1, 0(t0) + /* L1[64] =3D non-leaf -> L0 (PPN 0x80420): (0x80420 << 10) | V */ + li t0, 0x80410000 + li t1, 0x20108001 + sd t1, 0x200(t0) /* 64 * 8 =3D 0x200 */ + + li t0, 0x80420000 + /* L0[80] =3D non-NAPOT leaf carrying all XWR encodings (pi0..pi7) */ + li t1, LEAF_ALL_XWR + sd t1, 0x280(t0) /* 80 * 8 =3D 0x280 */ + /* L0[81] =3D 0: invalid entry (V=3D0) */ + sd x0, 0x288(t0) /* 81 * 8 =3D 0x288 */ + /* L0[82] =3D leaf with reserved bit 3 set (V|L|rsv|XWR[pi0]=3DRW) */ + li t1, 0x30B + sd t1, 0x290(t0) /* 82 * 8 =3D 0x290 */ + /* L0[96] =3D NAPOT leaf: V|L|N | XWR=3DRW(0x300) | G=3D4(0x4000) */ + li t1, 0x4307 + sd t1, 0x300(t0) /* 96 * 8 =3D 0x300 */ + /* L0[128] =3D NAPOT leaf, reserved G=3D5 (0x5000): V|L|N | XWR=3DRW */ + li t1, 0x5307 + sd t1, 0x400(t0) /* 128 * 8 =3D 0x400 */ + + /* Program mmpt: MODE=3D1 (Smmpt43), PPN =3D 0x80400 */ + li t0, 0x1000000000080400 + csrw 0x382, t0 /* CSR_MMPT */ + + /* mfence.pa must not fault in M-mode */ + TEST_MFENCE_PA 1 + + /* Run the shared permission and structural checks */ + RUN_LEAF_CHECKS + + /* All tests passed */ + li a0, 0 + j _exit + + SMMPT_HARNESS --=20 2.43.0 From nobody Fri Jul 24 04:55:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1784837209; cv=none; d=zohomail.com; s=zohoarc; b=YOechYK1n1gd6+b18j1JXvQFZrqrxa8hK7hrXg+m+d49evymsLW5sINrc4x3VV0ACRb2KR/MUDsTCXSZ/VHkd5HIM0kCsS1lFWmpLVN6aN5wYKyAUckkVX7Ns/BPTYMvH9b0rJTsu7YnwGU4+STD04x9kUSHxTnJH7hmyYf33bQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784837209; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=LbeloWnfmme1Ol6QCO52wmwJAeYMXLpwV3PnXwunugw=; b=K1Zur5JjbSsmLsBk0zR4qzR70T2TKdwUfxvkfjyGAjhr6DtfWCONFn6VGblbJiah3NzDfC2MB+xFTDi1GTzQtdLhBLqw+LuMAOESQ5I5f/IHasltJGR991aKis4XVK3Zv04zlUCR7lAV9CtWZB/XUihcqkuTF6lE1vebYQYSNBg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784837209427816.4534749663634; Thu, 23 Jul 2026 13:06:49 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmzfF-0007zg-Kt; Thu, 23 Jul 2026 16:05:05 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmzeJ-0007Py-Ff; Thu, 23 Jul 2026 16:04:07 -0400 Received: from [115.124.30.119] (helo=out30-119.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmzeB-0005SM-MZ; Thu, 23 Jul 2026 16:04:07 -0400 Received: from localhost.localdomain(mailfrom:zhiwei_liu@linux.alibaba.com fp:SMTPD_---0X7h4UwQ_1784837026 cluster:ay36) by smtp.aliyun-inc.com; Fri, 24 Jul 2026 04:03:46 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1784837028; h=From:To:Subject:Date:Message-Id:MIME-Version; bh=LbeloWnfmme1Ol6QCO52wmwJAeYMXLpwV3PnXwunugw=; b=svOHpmHnLBdv63Lge0DhNaEAi2N0isQ/f0wYf5yvHF5J+4dn+ZpkqMiOTKccsBz5Ya8p0gyuOor7/baK+F+VCtIZVQyyBicjy1jVmHlhYY6YuybSvaFgJ33c16hvmdi9xRV0M/SJxVt0td95+MtmkEEoWY6NRzzmFN2KQUXsOmQ= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R401e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033037033178; MF=zhiwei_liu@linux.alibaba.com; NM=1; PH=DS; RN=11; SR=0; TI=SMTPD_---0X7h4UwQ_1784837026; From: LIU Zhiwei To: qemu-devel@nongnu.org Cc: palmer@dabbelt.com, alistair.francis@wdc.com, daniel.barboza@oss.qualcomm.com, chao.liu.zevorn@gmail.com, liwei1518@gmail.com, qemu-riscv@nongnu.org, rahul@summations.net, xiangyi.zeng@linux.alibaba.com, cxx194832@alibaba-inc.com, LIU Zhiwei Subject: [PATCH v8 10/11] target/riscv: Add system tests for Smmpt52 and Smmpt64 Date: Fri, 24 Jul 2026 04:03:24 +0800 Message-Id: <20260723200325.24969-11-zhiwei_liu@linux.alibaba.com> X-Mailer: git-send-email 2.39.3 (Apple Git-146) In-Reply-To: <20260723200325.24969-1-zhiwei_liu@linux.alibaba.com> References: <20260723200325.24969-1-zhiwei_liu@linux.alibaba.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.119 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.119; envelope-from=zhiwei_liu@linux.alibaba.com; helo=out30-119.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1784837211480158500 Content-Type: text/plain; charset="utf-8" Extend the SMMPT system-test coverage to the two larger RV64 memory protection schemes: Smmpt52 (4-level MPT, 52-bit SPA) and Smmpt64 (5-level MPT, 64-bit SPA with a 32 KiB / 32 KiB-aligned root table). Both tests reuse the mode-independent harness in smmpt-common.S and only differ in the number of radix levels and, for Smmpt64, the root-table size and alignment. They exercise the same permission and structural checks (all XWR encodings for load and store, V=3D0 and reserved-bit leaves, and NAPOT leaves with a valid and a reserved G field) and are wired into the Makefile as run-test-smmpt52 and run-test-smmpt64. Signed-off-by: LIU Zhiwei --- tests/tcg/riscv64/Makefile.softmmu-target | 8 ++ tests/tcg/riscv64/test-smmpt52.S | 91 +++++++++++++++++++++ tests/tcg/riscv64/test-smmpt64.S | 98 +++++++++++++++++++++++ 3 files changed, 197 insertions(+) create mode 100644 tests/tcg/riscv64/test-smmpt52.S create mode 100644 tests/tcg/riscv64/test-smmpt64.S diff --git a/tests/tcg/riscv64/Makefile.softmmu-target b/tests/tcg/riscv64/= Makefile.softmmu-target index 18da9c6299..6bbec02ed2 100644 --- a/tests/tcg/riscv64/Makefile.softmmu-target +++ b/tests/tcg/riscv64/Makefile.softmmu-target @@ -45,5 +45,13 @@ EXTRA_RUNS +=3D run-test-smmpt run-test-smmpt: test-smmpt $(call run-test, $<, $(QEMU) -cpu rv64$(comma)x-smmpt=3Dtrue $(QEMU_OPTS)= $<) =20 +EXTRA_RUNS +=3D run-test-smmpt52 +run-test-smmpt52: test-smmpt52 + $(call run-test, $<, $(QEMU) -cpu rv64$(comma)x-smmpt=3Dtrue $(QEMU_OPTS)= $<) + +EXTRA_RUNS +=3D run-test-smmpt64 +run-test-smmpt64: test-smmpt64 + $(call run-test, $<, $(QEMU) -cpu rv64$(comma)x-smmpt=3Dtrue $(QEMU_OPTS)= $<) + # We don't currently support the multiarch system tests undefine MULTIARCH_TESTS diff --git a/tests/tcg/riscv64/test-smmpt52.S b/tests/tcg/riscv64/test-smmp= t52.S new file mode 100644 index 0000000000..445ba50d22 --- /dev/null +++ b/tests/tcg/riscv64/test-smmpt52.S @@ -0,0 +1,91 @@ +/* + * SPDX-License-Identifier: GPL-2.0-or-later + * + * Test for the Smmpt52 (Supervisor Memory Protection Table) extension, + * per SMMTT specification v0.4.9. + * + * Smmpt52 uses a 4-level MPT with 8-byte entries (16 pages per leaf, + * pi =3D SPA[15:12], pn[i] 9 bits at SPA[16 + i*9 +: 9]). It shares the = MPTE + * formats and the permission-lookup algorithm with Smmpt43, only adding o= ne + * more radix level. See smmpt-common.S for the MPRV trick, the shared + * address layout and the exit-code convention. + * + * For the low (< 4 GiB) addresses exercised here pn[3] and pn[2] are 0, so + * the upper levels are single-entry chains: + * + * L3 (root) @ 0x8040_0000 : entry[0] -> non-leaf, PPN(L2)=3D0x80410 + * L2 @ 0x8041_0000 : entry[0] -> non-leaf, PPN(L1)=3D0x80420 + * L1 @ 0x8042_0000 : entry[64] -> non-leaf, PPN(L0)=3D0x80430 + * L0 @ 0x8043_0000 : + * entry[80] -> non-NAPOT leaf (LEAF_ALL_XWR) covering 0x8050_0000+ + * entry[81] -> V=3D0 (invalid) covering 0x8051_0000 + * entry[82] -> leaf with a reserved bit set covering 0x8052_0000 + * entry[96] -> NAPOT leaf, G=3D4, XWR=3DRW covering 0x8060_0= 000 + * entry[128] -> NAPOT leaf, reserved G=3D5 covering 0x8080_0000 + * + * mmpt =3D MODE(2=3DSmmpt52)<<60 | PPN(0x80400) + */ + +#include "smmpt-common.S" + + .option norvc + + .text + .global _start +_start: + /* Install the M-mode trap handler */ + lla t0, mtrap + csrw mtvec, t0 + csrw medeleg, zero + + /* PMP entry 0: NAPOT covering the whole space, RWX. */ + li t0, -1 + csrw pmpaddr0, t0 + li t0, 0x1f + csrw pmpcfg0, t0 + + /* Build the MPT tables (M-mode stores bypass the MPT). */ + /* L3[0] =3D non-leaf -> L2 (PPN 0x80410) */ + li t0, 0x80400000 + li t1, 0x20104001 + sd t1, 0(t0) + /* L2[0] =3D non-leaf -> L1 (PPN 0x80420) */ + li t0, 0x80410000 + li t1, 0x20108001 + sd t1, 0(t0) + /* L1[64] =3D non-leaf -> L0 (PPN 0x80430) */ + li t0, 0x80420000 + li t1, 0x2010C001 + sd t1, 0x200(t0) /* 64 * 8 =3D 0x200 */ + + li t0, 0x80430000 + /* L0[80] =3D non-NAPOT leaf carrying all XWR encodings (pi0..pi7) */ + li t1, LEAF_ALL_XWR + sd t1, 0x280(t0) /* 80 * 8 =3D 0x280 */ + /* L0[81] =3D 0: invalid entry (V=3D0) */ + sd x0, 0x288(t0) /* 81 * 8 =3D 0x288 */ + /* L0[82] =3D leaf with reserved bit 3 set */ + li t1, 0x30B + sd t1, 0x290(t0) /* 82 * 8 =3D 0x290 */ + /* L0[96] =3D NAPOT leaf: V|L|N | XWR=3DRW | G=3D4 */ + li t1, 0x4307 + sd t1, 0x300(t0) /* 96 * 8 =3D 0x300 */ + /* L0[128] =3D NAPOT leaf with reserved G=3D5 */ + li t1, 0x5307 + sd t1, 0x400(t0) /* 128 * 8 =3D 0x400 */ + + /* Program mmpt: MODE=3D2 (Smmpt52), PPN =3D 0x80400 */ + li t0, 0x2000000000080400 + csrw 0x382, t0 /* CSR_MMPT */ + + /* mfence.pa must not fault in M-mode */ + TEST_MFENCE_PA 1 + + /* Run the shared permission and structural checks */ + RUN_LEAF_CHECKS + + /* All tests passed */ + li a0, 0 + j _exit + + SMMPT_HARNESS diff --git a/tests/tcg/riscv64/test-smmpt64.S b/tests/tcg/riscv64/test-smmp= t64.S new file mode 100644 index 0000000000..d67035aabb --- /dev/null +++ b/tests/tcg/riscv64/test-smmpt64.S @@ -0,0 +1,98 @@ +/* + * SPDX-License-Identifier: GPL-2.0-or-later + * + * Test for the Smmpt64 (Supervisor Memory Protection Table) extension, + * per SMMTT specification v0.4.9. + * + * Smmpt64 uses a 5-level MPT with 8-byte entries. Unlike the other RV64 + * modes its root table is 32 KiB (2^12 entries, pn[4] =3D SPA[63:52], 12 = bits) + * and must be aligned to a 32 KiB boundary; the non-root levels are the u= sual + * 4 KiB / 9-bit tables (16 pages per leaf, pi =3D SPA[15:12]). See + * smmpt-common.S for the MPRV trick, the shared address layout and the + * exit-code convention. + * + * For the low (< 4 GiB) addresses exercised here pn[4], pn[3] and pn[2] a= re + * 0, so the upper levels are single-entry chains: + * + * L4 (root) @ 0x8040_0000 : entry[0] -> non-leaf, PPN(L3)=3D0x80410 + * (32 KiB / 32 KiB-aligned) + * L3 @ 0x8041_0000 : entry[0] -> non-leaf, PPN(L2)=3D0x80420 + * L2 @ 0x8042_0000 : entry[0] -> non-leaf, PPN(L1)=3D0x80430 + * L1 @ 0x8043_0000 : entry[64] -> non-leaf, PPN(L0)=3D0x80440 + * L0 @ 0x8044_0000 : + * entry[80] -> non-NAPOT leaf (LEAF_ALL_XWR) covering 0x8050_0000+ + * entry[81] -> V=3D0 (invalid) covering 0x8051_0000 + * entry[82] -> leaf with a reserved bit set covering 0x8052_0000 + * entry[96] -> NAPOT leaf, G=3D4, XWR=3DRW covering 0x8060_0= 000 + * entry[128] -> NAPOT leaf, reserved G=3D5 covering 0x8080_0000 + * + * mmpt =3D MODE(3=3DSmmpt64)<<60 | PPN(0x80400) (PPN[2:0] must be 0) + */ + +#include "smmpt-common.S" + + .option norvc + + .text + .global _start +_start: + /* Install the M-mode trap handler */ + lla t0, mtrap + csrw mtvec, t0 + csrw medeleg, zero + + /* PMP entry 0: NAPOT covering the whole space, RWX. */ + li t0, -1 + csrw pmpaddr0, t0 + li t0, 0x1f + csrw pmpcfg0, t0 + + /* Build the MPT tables (M-mode stores bypass the MPT). */ + /* L4[0] =3D non-leaf -> L3 (PPN 0x80410); root is 32 KiB aligned */ + li t0, 0x80400000 + li t1, 0x20104001 + sd t1, 0(t0) + /* L3[0] =3D non-leaf -> L2 (PPN 0x80420) */ + li t0, 0x80410000 + li t1, 0x20108001 + sd t1, 0(t0) + /* L2[0] =3D non-leaf -> L1 (PPN 0x80430) */ + li t0, 0x80420000 + li t1, 0x2010C001 + sd t1, 0(t0) + /* L1[64] =3D non-leaf -> L0 (PPN 0x80440) */ + li t0, 0x80430000 + li t1, 0x20110001 + sd t1, 0x200(t0) /* 64 * 8 =3D 0x200 */ + + li t0, 0x80440000 + /* L0[80] =3D non-NAPOT leaf carrying all XWR encodings (pi0..pi7) */ + li t1, LEAF_ALL_XWR + sd t1, 0x280(t0) /* 80 * 8 =3D 0x280 */ + /* L0[81] =3D 0: invalid entry (V=3D0) */ + sd x0, 0x288(t0) /* 81 * 8 =3D 0x288 */ + /* L0[82] =3D leaf with reserved bit 3 set */ + li t1, 0x30B + sd t1, 0x290(t0) /* 82 * 8 =3D 0x290 */ + /* L0[96] =3D NAPOT leaf: V|L|N | XWR=3DRW | G=3D4 */ + li t1, 0x4307 + sd t1, 0x300(t0) /* 96 * 8 =3D 0x300 */ + /* L0[128] =3D NAPOT leaf with reserved G=3D5 */ + li t1, 0x5307 + sd t1, 0x400(t0) /* 128 * 8 =3D 0x400 */ + + /* Program mmpt: MODE=3D3 (Smmpt64), PPN =3D 0x80400 */ + li t0, 0x3000000000080400 + csrw 0x382, t0 /* CSR_MMPT */ + + /* mfence.pa must not fault in M-mode */ + TEST_MFENCE_PA 1 + + /* Run the shared permission and structural checks */ + RUN_LEAF_CHECKS + + /* All tests passed */ + li a0, 0 + j _exit + + SMMPT_HARNESS --=20 2.43.0 From nobody Fri Jul 24 04:55:09 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1784837116; cv=none; d=zohomail.com; s=zohoarc; b=eEA8NpQv/ePO1AOCdEbhe35aBfEjWxv9FiUmKagRgHRQIZX2+r5uhLi5eH7EKYsaV1wI2wSTOamcKPIt06NtJhrx45nRhWkDCza+wcjwdkfzY2em52NZb4i3z235vHrGdE7ySEV4EvtESW6dCs/8s+ucfPE1aWUuVVpRjrLaoF4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784837116; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Jt1V96ny+CA0zx6XNKmOp9XsUUuethWx7bcnXoNBbgo=; b=lEZ8MBoajgFWUe0J+mJ/q0v27FpHnJkjL8Qxm6LQP8O1dWOuUqsNEivx5pOg2HqFzt6MueQpLHvFA5a+9P3VE0r6V9MIzus3BT7Ip5KfTgjBoZuvaIqQVEgAiRc5vlZHE6SgEc2Co+uPBWV1WR3qs+lBEHE4mt/503AOUYxRaes= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784837116341321.9804468492539; Thu, 23 Jul 2026 13:05:16 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmzey-0007XG-Dt; Thu, 23 Jul 2026 16:04:48 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmzeH-0007OP-Iv; Thu, 23 Jul 2026 16:04:06 -0400 Received: from [115.124.30.132] (helo=out30-132.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmzeA-0005SI-Po; Thu, 23 Jul 2026 16:04:04 -0400 Received: from localhost.localdomain(mailfrom:zhiwei_liu@linux.alibaba.com fp:SMTPD_---0X7h4Uwk_1784837026 cluster:ay36) by smtp.aliyun-inc.com; Fri, 24 Jul 2026 04:03:47 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1784837027; h=From:To:Subject:Date:Message-Id:MIME-Version; bh=Jt1V96ny+CA0zx6XNKmOp9XsUUuethWx7bcnXoNBbgo=; b=fV4Q5cwRRKHmiQzxyZspsAspJvJykhh/hLjv/teohcX7sJZ4rFnpXMX6r4CHCdH3QPVxCKIOJBVGdPnImggh1TYq68my3vxk9ynikPNXA77UTjVnFaNMlyG/RJaYuZiPyQSbTxucqBgoIIOheJR10ZsCiQ0S/ci4HutXEGEi190= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R461e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033045133197; MF=zhiwei_liu@linux.alibaba.com; NM=1; PH=DS; RN=11; SR=0; TI=SMTPD_---0X7h4Uwk_1784837026; From: LIU Zhiwei To: qemu-devel@nongnu.org Cc: palmer@dabbelt.com, alistair.francis@wdc.com, daniel.barboza@oss.qualcomm.com, chao.liu.zevorn@gmail.com, liwei1518@gmail.com, qemu-riscv@nongnu.org, rahul@summations.net, xiangyi.zeng@linux.alibaba.com, cxx194832@alibaba-inc.com, LIU Zhiwei Subject: [PATCH v8 11/11] target/riscv: Add system test for Smmpt34 Date: Fri, 24 Jul 2026 04:03:25 +0800 Message-Id: <20260723200325.24969-12-zhiwei_liu@linux.alibaba.com> X-Mailer: git-send-email 2.39.3 (Apple Git-146) In-Reply-To: <20260723200325.24969-1-zhiwei_liu@linux.alibaba.com> References: <20260723200325.24969-1-zhiwei_liu@linux.alibaba.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.132 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.132; envelope-from=zhiwei_liu@linux.alibaba.com; helo=out30-132.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1784837117420158500 Content-Type: text/plain; charset="utf-8" Add SMMPT system-test coverage for Smmpt34, the RV32-only memory protection scheme (2-level MPT with 4-byte entries). Smmpt34 requires a 32-bit CPU, but qemu-system-riscv64 can run a 32-bit CPU (-cpu rv32), so the test lives in tests/tcg/riscv64 alongside the RV64 Smmpt tests and shares the same harness (smmpt-common.S). It only differs in the table geometry: 4-byte MPTEs, two radix levels, a 10-bit level-0 index and the RV32 mmpt CSR layout (MODE in bits[31:30]). It exercises the same permission and structural checks as the RV64 tests (all XWR encodings for load and store, V=3D0 and reserved-bit leaves, and NAPOT leaves with a valid and a reserved G field), using the same access addresses. It is built for RV32 and run on qemu-system-riscv64 with -cpu rv32. Signed-off-by: LIU Zhiwei --- tests/tcg/riscv64/test-smmpt34.S | 97 ++++++++++++++++++++++++++++++++ 1 file changed, 97 insertions(+) create mode 100644 tests/tcg/riscv64/test-smmpt34.S diff --git a/tests/tcg/riscv64/test-smmpt34.S b/tests/tcg/riscv64/test-smmp= t34.S new file mode 100644 index 0000000000..92c8320999 --- /dev/null +++ b/tests/tcg/riscv64/test-smmpt34.S @@ -0,0 +1,97 @@ +/* + * SPDX-License-Identifier: GPL-2.0-or-later + * + * Test for the Smmpt34 (Supervisor Memory Protection Table) extension, + * per SMMTT specification v0.4.9. Smmpt34 is the RV32-only scheme. + * + * Although Smmpt34 requires a 32-bit CPU, the program is run on + * qemu-system-riscv64 with a 32-bit CPU (-cpu rv32), which lives in the + * same target as the RV64 Smmpt tests. It is therefore kept here in + * tests/tcg/riscv64 alongside the other Smmpt tests and shares the same + * harness (smmpt-common.S). Build it for RV32 and run it as: + * + * $CC -march=3Drv32ima_zicsr -mabi=3Dilp32 -I tests/tcg/riscv64 \ + * tests/tcg/riscv64/test-smmpt34.S -Wa,--noexecstack -c -o smmpt34.o + * $LD -m elf32lriscv -T tests/tcg/riscv64/semihost.ld smmpt34.o -o smmp= t34 + * qemu-system-riscv64 -cpu rv32,x-smmpt=3Dtrue -M virt -display none \ + * -semihosting -device loader,file=3Dsmmpt34 + * + * Smmpt34 uses a 2-level MPT with 4-byte entries (8 pages per leaf, + * pi =3D SPA[14:12]). The supervisor physical address is partitioned as + * pn[1] =3D SPA[33:25] (9-bit root index), pn[0] =3D SPA[24:15] (10-bit l= evel-0 + * index) and range offset SPA[14:0]. For the RAM addresses used here + * (0x8xxx_xxxx, < 4 GiB) pn[1] resolves to 64. See smmpt-common.S for the + * MPRV trick, the shared address layout and the exit-code convention. + * + * This test reuses the same shared harness and the same access addresses = as + * the RV64 tests; only the table geometry (4-byte entries, 2 levels, 10-b= it + * level-0 index) and the RV32 mmpt layout differ. + * + * MPT layout (Smmpt34, 2 levels, 4-byte entries): + * + * L1 (root) @ 0x8040_0000 : entry[64] -> non-leaf, PPN(L0)=3D0x80410 + * L0 @ 0x8041_0000 : + * entry[160] -> non-NAPOT leaf (LEAF_ALL_XWR) covering 0x8050_0000+ + * entry[162] -> V=3D0 (invalid) covering 0x8051_0000 + * entry[164] -> leaf with a reserved bit set covering 0x8052_0000 + * entry[192] -> NAPOT leaf, G=3D6, XWR=3DRW covering 0x8060_0= 000 + * entry[256] -> NAPOT leaf, reserved G=3D0 covering 0x8080_0000 + * + * mmpt =3D MODE(1=3DSmmpt34)<<30 | PPN(0x80400) + */ + +#include "smmpt-common.S" + + .option norvc + + .text + .global _start +_start: + /* Install the M-mode trap handler */ + lla t0, mtrap + csrw mtvec, t0 + csrw medeleg, zero + + /* PMP entry 0: NAPOT covering the whole space, RWX. */ + li t0, -1 + csrw pmpaddr0, t0 + li t0, 0x1f + csrw pmpcfg0, t0 + + /* Build the MPT tables (M-mode stores bypass the MPT). */ + /* L1[64] =3D non-leaf -> L0 (PPN 0x80410): (0x80410 << 10) | V */ + li t0, 0x80400000 + li t1, 0x20104001 + sw t1, 0x100(t0) /* 64 * 4 =3D 0x100 */ + + li t0, 0x80410000 + /* L0[160] =3D non-NAPOT leaf carrying all XWR encodings (pi0..pi7) */ + li t1, LEAF_ALL_XWR + sw t1, 0x280(t0) /* 160 * 4 =3D 0x280 */ + /* L0[162] =3D 0: invalid entry (V=3D0) */ + sw x0, 0x288(t0) /* 162 * 4 =3D 0x288 */ + /* L0[164] =3D leaf with reserved bit 3 set (V|L|rsv|XWR[pi0]=3DRW) */ + li t1, 0x30B + sw t1, 0x290(t0) /* 164 * 4 =3D 0x290 */ + /* L0[192] =3D NAPOT leaf: V|L|N | XWR=3DRW(0x300) | G=3D6(0x6000) */ + li t1, 0x6307 + sw t1, 0x300(t0) /* 192 * 4 =3D 0x300 */ + /* L0[256] =3D NAPOT leaf with reserved G=3D0: V|L|N | XWR=3DRW | G=3D0 */ + li t1, 0x307 + sw t1, 0x400(t0) /* 256 * 4 =3D 0x400 */ + + /* Program mmpt: MODE=3D1 (Smmpt34) at bits[31:30], PPN =3D 0x80400 */ + li t0, 0x40080400 + csrw 0x382, t0 /* CSR_MMPT */ + + /* mfence.pa must not fault in M-mode */ + TEST_MFENCE_PA 1 + + /* Run the shared permission and structural checks */ + RUN_LEAF_CHECKS + + /* All tests passed */ + li a0, 0 + j _exit + + SMMPT_HARNESS --=20 2.43.0